The Able Desktop Supply Chain Attack
Updated 5 Oct 2026 · Incident date 1 May 2018 · vendor binary
Able Desktop (Able Soft, Mongolia): trojanized installers from at least May 2018; update system compromised from June 2020pcalocalresloader.dllAble Desktop is a chat application in a business management suite used by 430 Mongolian government agencies. ESET named the attack Operation StealthyTrident. Trojanized installers appeared from May 2018, and the update system was compromised by June 2020.
The attackers used side-loaded DLLs to run the HyperBro, Korplug and Tmanger backdoors.
What happened
ESET reports that two trojanized installers and a compromised update system spread the malware. ESET dates the first trojanized installer to December 2017 in its timeline, and later installers to May 2018 onward. It dates the update system compromise to June 2020 or earlier, and a shift to the Tmanger backdoor to July 2020. ESET published its report on 10 December 2020.
The update mechanism downloaded executables over HTTPS to %USERPROFILE%\Documents\Able\Able Desktop.exe.
The attackers used DLL side-loading. They ran legitimate signed programs from security vendors, and those programs loaded the malicious DLLs:
IntgStat.exe(Symantec) loadedpcalocalresloader.dllSiteadv.exe(McAfee) loadedsiteadv.dllThinprobe.exe(Symantec) loadedthinprobe.dll
These DLLs decoded an XOR-encoded payload stored in thumb.db or thumbs.db. The payloads were the HyperBro backdoor, associated with LuckyMouse, the Korplug (PlugX) remote access tool, and the Tmanger remote access tool, associated with TA428. ESET says the links between these groups suggest shared access, shared tools or organizational ties.
Affected versions
ESET names no version numbers. The affected items are the trojanized Able Desktop installers from 2018 and the updates delivered by the compromised update system.
- Trojanized installers: December 2017 and May 2018 onward
- Compromised update system: June 2020 or earlier
Indicators of compromise
ESET lists these in its public IOC repository.
- Trojanized Able Desktop SHA-1:
0B0CF4ADA30797B0488857F9A3B1429F44335FB6andB51835A5D8DA77A49E3266494A8AE96764C4C152 - Payload loader SHA-1:
23A227DD9B77913D15735A25EFB0882420B1DE81 - HyperBro SHA-1:
8FFF5C6EB4DAEE2052B3578B73789EB15711FEEEand6477783B302F4D893271F5522110650EB2C50BD1 - Korplug SHA-1:
5D066113534A9E31F49BEFDA560CF8F8890496D0 - Tmanger SHA-1:
ED6CECFDAAEB7F41A824757862640C874EF3F7AE - Domain:
developer.firefoxapi.com - IP addresses:
45.77.173.124,45.77.55.145,139.180.208.225 - Files:
pcalocalresloader.dll,siteadv.dll,thinprobe.dll,thumb.dbandthumbs.dbin an Able Desktop folder
How to check
Look for the side-loaded DLLs next to Able Desktop files, and hash them.
Get-ChildItem -Path C:\ -Recurse -Include pcalocalresloader.dll,siteadv.dll,thinprobe.dll -ErrorAction SilentlyContinue | Get-FileHash -Algorithm SHA1
Compare the output with the SHA-1 values above. Search network logs for developer.firefoxapi.com and the three IP addresses.
What to do now
- Isolate any machine with a match and treat it as compromised.
- Remove the DLL and the encoded
thumb.dbfiles, and rebuild the machine. - Block the domain and IP addresses.
- Rotate credentials that the machine used.
- Do not accept updates from Able Desktop until the vendor confirms a clean update channel.
Vigilance compares the version you trust with a new one and reports the file that gained a new capability. Here new side-loading DLLs and encoded payload files appeared inside the package. See all attacks.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 59 (1 Added) HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. NEW FILE pcalocalresloader.dll It runs other programs and runs a hidden, encoded command.
Frequently asked questions
What is Operation StealthyTrident?
It is ESET's name for an attack on Able Desktop, in which trojanized installers and a compromised update system delivered the HyperBro, Korplug and Tmanger backdoors to Mongolian government users.
How do I check for Able Desktop compromise?
Search for pcalocalresloader.dll, siteadv.dll and thinprobe.dll and compare their SHA-1 hashes with ESET's published list. Search network logs for developer.firefoxapi.com.
Sources
More supply chain attacks
- JDownloader official site installer swap 6 May 2026
- CPUID CPU-Z / HWMonitor download compromise 9 Apr 2026
- DAEMON Tools trojanized installers 8 Apr 2026
- eScan antivirus update server compromise (2026) 20 Jan 2026
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.