MIT TRACE

MIT CTL Logo
Back to Main Dashboard

MonPass CA compromised; installer backdoored and multiple webshells found

Avast reported that Mongolian CA MonPass’ public web server was repeatedly breached and its official certificate client installer was backdoored with a Cobalt Strike-based RAT. The trojanized installer was available from February 8 to March 3, 2021, and investigators found eight webshells/backdoors on the compromised server.

60

Estimated severity

60 / 100

90

Source reliability

90 / 100

Approximate Date

03/03/2021

Targeted Company

MONPASS

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

No information

Geographic Impact

Country Targeted Company

Mongolia

MNG

Other Affected Countries

No other affected countries reported

Target country

Mongolia

Affected countries

Mongolia

Impacted regions

Asia · Mongolia

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.