Signed software abused to deploy antivirus-killing scripts
2026-04-15T19:23:28Z•81bdda596d62e4c00a2fb90416664963aabce03818ce40a91127352b9b2c28cd
.rdp hardeningBitLockerCISA advisoryChrome Web StoreKB5082052KB5082063KB5082200KB5083769Kraken extortion','fake-mac-apps','crypto-theft'],OAuth token theftRDP protectionsSalesforce misconfigurationWindows Server 2019/2022/2025Windows Task Hostadwareantivirus disablingcode-signing abusedata-breachextortionmalicious-browser-extensionspatch-tuesdayprivilege escalationsigned-softwaresupply-chainzero-day
What happened
A range of high-impact incidents and Microsoft security developments: a digitally signed adware tool deployed SYSTEM‑level payloads that disabled antivirus protections on thousands of endpoints across education, utilities, government and healthcare; CISA warned of a Windows Task Host privilege‑escalation being exploited to gain SYSTEM; Microsoft issued April 2026 Patch Tuesday fixes for 167 flaws (including two zero‑days) and multiple KB updates for Windows 10/11/Server though some updates (KB5082063) caused BitLocker recovery prompts. Other notable items: over 100 malicious Chrome extensions—
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 81bdda596d62e4c00a2fb90416664963aabce03818ce40a91127352b9b2c28cd
- Enrichment time
- 2026-04-15T19:23:28Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.