United States
USA
Attackers placed trojanized JAVS Viewer 8.3.7 installers on Justice AV Solutions' official distribution infrastructure. Rapid7 traced a real customer infection to an installer downloaded from the official JAVS site and later found another malicious installer still being served there. Execution installed a persistent backdoor capable of remote command execution and credential theft, making this a confirmed compromise of a legitimate software distribution channel affecting downstream JAVS customers.
Estimated severity
72 / 100
Source reliability
92 / 100
Approximate Date
13/05/2024
Targeted Company
JUSTICE AV SOLUTIONS
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
No information
United States
USA
No other affected countries reported
Target country
United States
Affected countries
Impacted regions
No information
Duration
No information
Financial impact (USD M)
No information
Impact types
Affected sectors
Affected departments
Attack types
Attributed threat actors
No information
Incident Sources
Please rotate your phone