Avast has published the results of an investigation into the compromise of the Mongolian certification authority MonPass, which led to the insertion of a backdoor in the application offered for installation to clients. The analysis revealed that the infrastructure was compromised through a breach of one of MonPass's public web servers based on the Windows platform. The specified server showed traces of eight different hacks, resulting in the installation of eight webshells and backdoors for remote access.
Malicious changes were also made to the official client software, which was supplied with a backdoor from February 8 to March 3. The story began when, in response to a client complaint, Avast confirmed the presence of malicious changes in the installer distributed via the official MonPass website. After being notified of the issue, MonPass staff provided Avast access to a copy of the disk image of the compromised system. server to investigate the incident.
Source: opennet.ru
