The Havex Trojanized ICS Vendor Installers
Updated 5 Oct 2026 · Incident date 16 Apr 2014 · vendor binary
Installers from three European ICS/SCADA vendors, including the mbCHECK camera utility, trojanized on the vendors' own websitesthe vendors' own signed installer executables - mbCHECK.exe and setup_1.0.1.exeThe Dragonfly group trojanized installers on the websites of three European industrial control system vendors. The vendors are MESA Imaging, eWON and MB Connect Line. The installers carried the Havex remote access tool, and the attacks ran in 2013 and 2014.
Netresec published the full list of trojanized files in October 2014.
What happened
Netresec reports that all of the listed files were infected with the Havex RAT. The group is also called Energetic Bear and Crouching Yeti. The vendors' own download pages served the infected installers.
Netresec lists these incidents:
- MESA Imaging (Switzerland):
SwissrangerSetup1.0.14.706.exe, product Swiss Ranger 1.0.14.706. Exposure in June and July 2013, about six weeks. The backdoor was the Sysmain RAT. - eWON (Belgium):
eCatcherSetup.exe(Talk2M eCatcher 4.0.0.13073) andegrabitsetup.exe(eGrabIt 3.0.0.82). Exposure in January 2014, about 10 days and 250 downloads. The backdoor was Havex RAT 038. - MB Connect Line (Germany): mbCONFTOOL 1.0.1, mbCHECK 1.1.1 and VCOM_LAN2. Exposure from 16 to 23 April 2014. The backdoor was Havex RAT 043.
The mbCHECK installer affected Europe only. The US and Canada version was clean. The sources I fetched do not explain what the Havex OPC scanning module does in detail, so this page does not describe it. The record for this attack says the dropped DLL has outbound command and OPC scanning ability.
Affected versions
- MESA Imaging Swiss Ranger 1.0.14.706 (
SwissrangerSetup1.0.14.706.exe), June to July 2013 - eWON Talk2M eCatcher 4.0.0.13073 (
eCatcherSetup.exe), January 2014 - eWON eGrabIt 3.0.0.82 (
egrabitsetup.exe), January 2014 - MB Connect Line mbCONFTOOL 1.0.1, mbCHECK 1.1.1 (Europe) and VCOM_LAN2, 16 to 23 April 2014
Each vendor had shipped clean installers before. A download from outside those windows is not covered by this list.
Indicators of compromise
SwissrangerSetup1.0.14.706.exeMD5:e027d4395d9ac9cc980d6a91122d2d83eCatcherSetup.exeMD5:eb0dacdc8b346f44c8c370408bad4306egrabitsetup.exeMD5:1080e27b83c37dfeaa0daaa619bdf478- For the MB Connect Line files, Netresec's list holds the hashes. I did not extract them, so check its full list.
How to check
Find any of the installers that you still hold and hash them.
Get-ChildItem -Path C:\ -Recurse -Include SwissrangerSetup*.exe,eCatcherSetup.exe,egrabitsetup.exe,mbCHECK*.exe -ErrorAction SilentlyContinue | Get-FileHash -Algorithm MD5
Compare each result with the hashes above and with the Netresec list. A match means the machine that ran the installer needs investigation.
What to do now
- Find where each of these installers was run in your plant or office.
- Isolate any machine that ran a matching file and treat it as compromised.
- Check connections from that machine to your control network.
- Download vendor installers again from the vendor and check their hashes against the vendor's value.
- Keep engineering workstations apart from control devices.
Vigilance compares the version you trust with a new one and reports the file that gained a new capability. See all attacks.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 38 (1 Added) HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. NEW FILE mbCHECK.exe It downloads from the internet and runs other programs.
Frequently asked questions
Which vendors had Havex trojanized installers?
MESA Imaging, eWON and MB Connect Line, according to Netresec. The attacks ran from 2013 to April 2014.
How do I check for Havex trojanized installers?
Hash any Swiss Ranger, eCatcher, eGrabIt or mbCHECK installer you hold and compare it with the hashes published by Netresec.
Sources
More supply chain attacks
- JDownloader official site installer swap 6 May 2026
- CPUID CPU-Z / HWMonitor download compromise 9 Apr 2026
- DAEMON Tools trojanized installers 8 Apr 2026
- eScan antivirus update server compromise (2026) 20 Jan 2026
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.