Executive brief
Justice AV Solutions (JAVS) Viewer installer version 8.3.7.250-1 contains a malicious version of ffmpeg.exe (named fffmpeg.exe) that functions as a backdoor. When executed, the binary establishes a connection to a malicious command-and-control (C2) server, allowing for unauthorized PowerShell command execution.
Affected products
- Justice AV Solutions (JAVS) Viewer Setup 8.3.7.250-1
Timeline
- 2024-05-23: disclosed: Rapid7 published a blog post regarding the backdoored software.
- 2024-05-29: kev added: Added to CISA's Known Exploited Vulnerabilities (KEV) Catalog.
- 2024-05-29: exploited: Reported as exploited in the wild.