Attackers have compromised the installer of widely used courtroom video recording software Justice AV Solutions (JAVS) with malware, allowing them to launch attacks on compromised systems.
See also: Abuse of cloud services in SMS phishing attacks

The company behind this software, also known as JAVS, says that the digital recording tool currently has more than 10,000 installations in many courtrooms, law offices, correctional institutions, and government agencies around the world.
JAVS has since removed the compromised version from its official website, saying that the trojanized software containing a malicious fffmpeg.exe binary “ does not originate from JAVS or any third party associated with JAVS. ”
The company also conducted a full audit of all JAVS systems and is resetting all passwords to ensure that in the event of theft, they could not be used in future attacks.
" Through continued monitoring and cooperation with cyber authorities, we have identified attempts to replace the Viewer 8.3.7 software with a compromised file ," the company said
“We have confirmed that all files currently available on the JAVS.com website are genuine and free of malware. We have further verified that no source code, certificates, systems or other versions of JAVS software were compromised in this incident.“
See also: Jumbo Group fell victim to ransomware attack
Cybersecurity firm Rapid7 investigated this supply chain incident (now tracked as CVE-2024-4978) and found that the S2W Talon first spotted the trojanized JAVS installer in early April and linked it to Rustdoor/GateDoor.

While analyzing an incident linked to CVE-2024-4978 on May 10, Rapid7 found that the malware sends system information to the server after it installs and boots. It then runs two obscure PowerShell scripts that will attempt to disable Event Tracking for Windows (ETW) and bypass the Anti-Malware Scanning Interface (AMSI).
Then, an additional malicious payload downloaded from the C2 server drops Python, which will start collecting credentials stored in web browsers on the system.
According to Rapid7, the backdoored installer (JAVS.Viewer8.Setup_8.3.7.250-1.exe)—classified by many security vendors as a malware dropper and used in attacks—was downloaded from the official JAVS website.
See also: Trego County hospital hit by ransomware attack
What are the basic techniques for protecting against cyberattacks?
- Regularly updating software and systems is critical for security.
- Using antivirus and anti-malware software can detect and prevent many threats.
- User education on recognizing and avoiding phishing is essential.
- Using VPN (Virtual Private Network) networks can protect online communications, especially when using public or unsecured Wi-Fi.
- Implementing access control policies, such as the principle of least privilege.
- Creating and maintaining backups of data is vital. attackers.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
