The Kingslayer EvLog Supply Chain Attack

Updated 5 Oct 2026 · Incident date 9 Apr 2015 · vendor binary

PackageAltair Technologies EvLog (EventID.net) -> trojanized signed build served 9-25 April 2015
Filethe signed EVlog .msi installer package served from the...

From 9 to 25 April 2015, attackers served a trojanized version of EvLog, a Windows event log tool from Altair Technologies and the EventID.net site. RSA named the operation Kingslayer. Krebs reports that the vendor told the public about it in a short notice in June 2016, and that the story reached wide notice in February 2017.

The tool was popular with Windows administrators. A tool that administrators run is a path to the systems they manage.

What happened

Attackers replaced a legitimate administrator tool with a backdoored build. Krebs reports that they compromised both the software download page and the update server. Existing installs then downloaded the bad version at their next update check, and new installs got it too.

Krebs reports that the malicious software was distributed from 9 to 25 April 2015. The vendor, Altair Technologies of Mississauga, Ontario, posted a short breach notice in June 2016 without a direct notice to customers. The vendor told SecurityWeek that it had no way to identify who downloaded or updated EvLog, because downloads needed no registration.

RSA confirmed at least one system administrator at a defense contractor as infected. SecurityWeek reports that the defense contractor was targeted about 11 weeks after the first breach. RSA took control of the command server domain, oraclesoft[dot]net, in April 2016. SecurityWeek reports a link to Chinese APT groups known as Shell Crew and Codoso.

The users of the EventID.net portal included, according to Krebs, five major defense contractors, four major telecom providers, more than ten western military organizations and more than 24 Fortune 500 companies, with banks and universities. Not all of these users ran the bad build. Krebs lists related products from the same owner, EventReader and Firegen, as possibly affected.

Vigilance compares the version you trust with the new one. A vendor build that adds new network code is the kind of change it reports. See the scan block below.

Affected versions

The sources do not give a build number for the trojanized file. The fetched Krebs and SecurityWeek reports give no version, so this page lists none.

Indicators of compromise

The RSA and Krebs sources that this page uses give no file hashes. Ask RSA or the vendor for the full RSA report for more.

How to check

Search DNS and proxy logs for the command domain, starting with the logs of April 2015 onward. If you have archived DNS logs:

zgrep -il "oraclesoft.net" /var/log/dns/* 2>/dev/null

Replace the path with your own log folder. Also check your software inventory for EvLog and ask administrators when they installed or updated it.

What to do now

  1. Find every machine where EvLog ran, and the dates of install and update.
  2. If it ran between 9 and 25 April 2015, treat that machine as compromised. Rebuild it.
  3. Reset the credentials that the administrator used on that machine. These credentials open many systems.
  4. Remove EvLog if you no longer use it.
  5. Record the version and source of every administrator tool, and check the vendor for a clean build.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old Altair-prev --new Altair-current
files scanned: 80

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    Altair.exe
           It now downloads from the internet, reads saved passwords and access keys and runs other programs. It did not before.

Frequently asked questions

What was the Kingslayer supply chain attack?

Kingslayer is RSA's name for the attack on Altair Technologies. Attackers distributed a trojanized EvLog build from 9 to 25 April 2015.

How can I check if EvLog was compromised on my network?

Search DNS and proxy logs for oraclesoft.net. Then list every EvLog install and its install or update date, and look for dates between 9 and 25 April 2015.

Sources

  1. krebsonsecurity.com/2017/02/how-to-bury-a-major-breach-notification/
  2. securityweek.com/serious-breach-linked-chinese-apts-comes-light/

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free