MonPass, one of Mongolia’s largest certificate authorities, was breached and used to distribute a trojanized version of its official certificate installer containing a Cobalt Strike-based payload. Avast reported that the malicious installer was available from February 8 to March 3, 2021, giving attackers a trusted software distribution channel to infect selected victims through software they were likely to regard as legitimate.
Investigators found signs that a public MonPass web server had been compromised as many as eight times and hosted multiple webshells and backdoors. Avast worked with CERT Mongolia and MonPass on the investigation and said the intrusion showed traits consistent with a targeted cyber-espionage operation, though it did not definitively attribute the activity to a specific threat actor; the campaign was assessed against a backdrop of prior Chinese-linked operations targeting Mongolia and the surrounding region, and the backdoor appeared to be removed after the intended victims were reached.

Trace attribution and downstream blast radius.
5 events from the most recent confirmed update back to the earliest known activity.
Beginning in April 2021, Avast analyzed a cloned image of a MonPass server provided during the investigation. The analysis indicated that a public MonPass web server had likely been breached as many as eight separate times and contained multiple webshells and backdoors.
The malicious MonPass client installer stopped being distributed on March 3, 2021. Avast assessed that the attackers likely removed the backdoor themselves after reaching their intended targets.
From March to June 2021, Avast worked with CERT Mongolia and MonPass to investigate the breach and its impact. During this period, MonPass also cleaned up the compromised server and notified customers who had downloaded the backdoored client earlier in 2021.
In late March 2021, Avast found the backdoored MonPass installer and identified the associated backdoor on one of its customers' systems. This discovery triggered the subsequent investigation into MonPass's infrastructure.
MonPass's official certificate installer was distributed with a malicious Cobalt Strike-based payload, turning the CA's trusted software channel into a malware delivery mechanism. The compromised installer was available between February 8 and March 3, 2021.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.