The JAVS Viewer Supply Chain Attack
Updated 5 Oct 2026 · Incident date 5 Mar 2024 · vendor binary
JAVS Viewer Setup 8.3.7.250-1.exe (JAVS Suite 8); fixed in 8.3.8fffmpeg.exeThe installer JAVS.Viewer8.Setup_8.3.7.250-1.exe for JAVS Viewer 8.3.7, a courtroom recording tool, held a backdoor. It came from the official Justice AV Solutions website. The CVE is CVE-2024-4978, and the fixed version is 8.3.8.
Rapid7 found the problem in May 2024 when it investigated an infection that began with a download on 5 March 2024.
What happened
A trojanized installer on the vendor's own website installed a backdoor next to the real software. Rapid7 traced an infection to the download of the installer on 5 March 2024. Help Net Security reports that the bad file was served from the official site since at least 2 April 2024, and that the discovery was made public on 23 May 2024.
The backdoor was a file named fffmpeg.exe, with three letters f. The real tool, ffmpeg.exe, has two. Rapid7 reports that both this file and the installer were signed with a certificate issued to "Vanguard Tech Limited", not to Justice AV Solutions.
After it started, fffmpeg.exe sent the host name, operating system, processor type, working folder and user name to a command server. It ran two obfuscated PowerShell scripts to turn off Event Tracing for Windows and bypass the Anti-Malware Scan Interface. It then downloaded more malware that dropped Python scripts to steal passwords stored in web browsers. Help Net Security describes the loader as part of the GateDoor and Rustdoor family.
The vendor states that it removed all 8.3.7 versions, reset passwords, audited its systems and checked that current downloads are clean. It states that no source code, certificates or systems were compromised, according to Help Net Security.
Vigilance compares the version you trust with the new one. This installer added a new program that the clean build did not have. Vigilance reports the file that gained a new capability. See the scan block below.
Affected versions
- JAVS Viewer 8.3.7, installer
JAVS.Viewer8.Setup_8.3.7.250-1.exe. - Fixed in 8.3.8. Rapid7 and Help Net Security advise 8.3.8 or later.
The report concerns JAVS Suite 8 installs of this one installer. Other installers are not named.
Indicators of compromise
- File:
fffmpeg.exe(three f letters). Size about 1.4 MB. - SHA-256:
a5e24c10d595969858af422c6dff6bed5f9c6c49dc9622d694327323d8a57d72. - SHA-1:
e41ec15f2bac76914b4a86cade3a0f4619167f52. - Code-signing name on the installer and the file: "Vanguard Tech Limited".
- Extra payloads that Rapid7 saw on the attacker's server on port 8000:
chrome_installer.exe,firefox_updater.exe,OneDriveStandaloneUpdater.exe. The attacker later replaced the last one withChromeDiscovery.exe.
The sources do not give the server address in a form this page can verify, so none is listed.
How to check
Search the machine for the three-f file and for the hash. Run this in PowerShell.
Get-ChildItem C:\ -Recurse -Filter fffmpeg.exe -ErrorAction SilentlyContinue | Get-FileHash -Algorithm SHA256
Any hit means the machine ran the backdoor. Also check the signer of the installed JAVS files in file properties. The name must be Justice AV Solutions, not Vanguard Tech Limited.
What to do now
- Upgrade to JAVS Viewer 8.3.8 or later from the vendor.
- If
fffmpeg.exeexists, re-image the machine. Rapid7 and Help Net Security give this advice. - Reset the credentials and browser sessions of every user who signed in on that machine.
- Check the digital signature of any installer before you run it.
- CISA added CVE-2024-4978 to its Known Exploited Vulnerabilities list, so treat any open install as urgent.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 48 (1 Added) HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. NEW FILE fffmpeg.exe It downloads from the internet and runs other programs.
Frequently asked questions
Which JAVS Viewer version contained the backdoor?
JAVS Viewer 8.3.7, installer JAVS.Viewer8.Setup_8.3.7.250-1.exe, held the backdoor. Version 8.3.8 is the fixed release.
How can I tell if a machine ran the JAVS Viewer backdoor?
Look for a file named fffmpeg.exe, with three f letters. Compare its SHA-256 hash with a5e24c10d595969858af422c6dff6bed5f9c6c49dc9622d694327323d8a57d72.
Sources
More supply chain attacks
- JDownloader official site installer swap 6 May 2026
- CPUID CPU-Z / HWMonitor download compromise 9 Apr 2026
- DAEMON Tools trojanized installers 8 Apr 2026
- eScan antivirus update server compromise (2026) 20 Jan 2026
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.