MIT TRACE

MIT CTL Logo
Back to Main Dashboard

Compromised JAVS Viewer installer distributes backdoor through official software channel

Attackers placed trojanized JAVS Viewer 8.3.7 installers on Justice AV Solutions' official distribution infrastructure. Rapid7 traced a real customer infection to an installer downloaded from the official JAVS site and later found another malicious installer still being served there. Execution installed a persistent backdoor capable of remote command execution and credential theft, making this a confirmed compromise of a legitimate software distribution channel affecting downstream JAVS customers.

72

Estimated severity

72 / 100

92

Source reliability

92 / 100

Approximate Date

13/05/2024

Targeted Company

JUSTICE AV SOLUTIONS

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

No information

Geographic Impact

Country Targeted Company

United States

USA

Other Affected Countries

No other affected countries reported

Target country

United States

Affected countries

United States

Impacted regions

No information

Operational Impact

Duration

No information

Financial impact (USD M)

No information

Impact types

Supply chain data integrity impactDownstream customer disruption

Affected sectors

Technology & IT Services

Affected departments

Information Technology

Attack Profile

Attack types

Software supply chain compromiseMalwareBackdoor

Attributed threat actors

No information

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.