Mystery criminals backdoor courtroom recording software
Summary
Examining the installer, Ipek Solak, the detection and response analyst at Rapid7 who discovered the issue, spotted a binary called fffmpeg.exe that was quickly outed as one that provided remote access via a command and control (C2) server. fffmpeg.exe has previously been linked with the known GateDoor/Rustdoor malware family first discovered by S2W earlier this year, and running its SHA1 hash through VirusTotal reveals multiple vendors flagging it as a malicious dropper. It allowed attackers to run obfuscated PowerShell scripts, which were revealed to bypass anti-malware protections, disable Event Tracing for Windows, and download an additional payload. The first eyes on JAVS came in early April after a threat intelligence researcher at S2W Xeeted about malware being hosted on the vendors downloads page, but it didnt get much attention at the time. We couldnt get a hold of JAVS for its side of the story, but it did provide a statement to the researchers, saying it worked with authorities to understand what was happening, and now believes its downloads page is safe and free from malware.