The Havex Trojanized ICS Vendor Installers

Updated 5 Oct 2026 · Incident date 16 Apr 2014 · vendor binary

PackageInstallers from three European ICS/SCADA vendors, including the mbCHECK camera utility, trojanized on the vendors' own websites
Filethe vendors' own signed installer executables - mbCHECK.exe and setup_1.0.1.exe

The Dragonfly group trojanized installers on the websites of three European industrial control system vendors. The vendors are MESA Imaging, eWON and MB Connect Line. The installers carried the Havex remote access tool, and the attacks ran in 2013 and 2014.

Netresec published the full list of trojanized files in October 2014.

What happened

Netresec reports that all of the listed files were infected with the Havex RAT. The group is also called Energetic Bear and Crouching Yeti. The vendors' own download pages served the infected installers.

Netresec lists these incidents:

The mbCHECK installer affected Europe only. The US and Canada version was clean. The sources I fetched do not explain what the Havex OPC scanning module does in detail, so this page does not describe it. The record for this attack says the dropped DLL has outbound command and OPC scanning ability.

Affected versions

Each vendor had shipped clean installers before. A download from outside those windows is not covered by this list.

Indicators of compromise

How to check

Find any of the installers that you still hold and hash them.

Get-ChildItem -Path C:\ -Recurse -Include SwissrangerSetup*.exe,eCatcherSetup.exe,egrabitsetup.exe,mbCHECK*.exe -ErrorAction SilentlyContinue | Get-FileHash -Algorithm MD5

Compare each result with the hashes above and with the Netresec list. A match means the machine that ran the installer needs investigation.

What to do now

  1. Find where each of these installers was run in your plant or office.
  2. Isolate any machine that ran a matching file and treat it as compromised.
  3. Check connections from that machine to your control network.
  4. Download vendor installers again from the vendor and check their hashes against the vendor's value.
  5. Keep engineering workstations apart from control devices.

Vigilance compares the version you trust with a new one and reports the file that gained a new capability. See all attacks.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old Installers-prev --new Installers-current
files scanned: 38 (1 Added)

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

NEW FILE   mbCHECK.exe
           It downloads from the internet and runs other programs.

Frequently asked questions

Which vendors had Havex trojanized installers?

MESA Imaging, eWON and MB Connect Line, according to Netresec. The attacks ran from 2013 to April 2014.

How do I check for Havex trojanized installers?

Hash any Swiss Ranger, eCatcher, eGrabIt or mbCHECK installer you hold and compare it with the hashes published by Netresec.

Sources

  1. netresec.com/?page=Blog&month=2014-10&post=Full-Disclosure-of-Havex-Trojans

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free