The M.E.Doc Update Supply Chain Attack
Updated 5 Oct 2026 · Incident date 14 Apr 2017 · vendor binary
M.E.Doc 10.01.174 -> 10.01.175/176 (also 10.01.180/181 and 10.01.188/189)ZvitPublishedObjects.dllIn 2017, the Ukrainian accounting software M.E.Doc shipped three sets of backdoored updates: 10.01.175 and 10.01.176 (14 April), 10.01.180 and 10.01.181 (15 May), and 10.01.188 and 10.01.189 (22 June). The backdoor sat in the module ZvitPublishedObjects.dll.
The same update path delivered the NotPetya outbreak of 27 June 2017. ESET reports that the last bad update came five days before it.
Major incident. Microsoft observed infections in Ukraine and another 64 countries. This entry covers the same outbreak as the other M.E.Doc record. Impact source
What happened
Attackers took over the update server and added a backdoor to a program module that most Ukrainian companies already trusted. According to ESET, the .NET module ZvitPublishedObjects.dll held a backdoor class named MeCom. A method in the update checker, IsNewUpdate, called it each time the software checked for updates.
The clean updates of 17 May to 21 June had no backdoor. The bad sets came before two attack waves. ESET notes that the 15 May set preceded the Filecoder.AESNI.C ransomware by three days, and that the 22 June set preceded the DiskCoder.C (NotPetya) outbreak by five days.
Talos explains how the server was used. Attackers used stolen M.E.Doc administrator credentials, changed the NGINX configuration on the update server upd.me-doc.com.ua, and sent update traffic to a server they controlled. BleepingComputer reports that the server had not been updated since 2013, according to Ukrainian officials, and that a PHP web shell named medoc_online.php was found.
The backdoor collected company registration numbers (EDRPOU), proxy settings and credentials, and email account user names and passwords. It had six commands, including running shell commands, dropping and running files, and loading a DLL through rundll32.exe. ESET found that the last command matched how DiskCoder.C was first deployed. ESET reports that data left in cookies on requests to the update server. Talos describes queries to command servers every two minutes. Ukrainian police raided the vendor on 4 July 2017 and seized its servers.
Vigilance compares the version you trust with the new one. These updates changed a program module so that it fetches and runs outside code. Vigilance reports the file that gained that capability. See the scan block below.
Affected versions
- M.E.Doc 10.01.175 and 10.01.176, released 14 April 2017.
- 10.01.180 and 10.01.181, released 15 May 2017.
- 10.01.188 and 10.01.189, released 22 June 2017.
ESET states that updates between 17 May and 21 June 2017 were clean. Check the exact build against the vendor's current release.
Indicators of compromise
- Module:
ZvitPublishedObjects.dll(about 5 MB, .NET) with a class namedMeCom. - Registry:
HKEY_CURRENT_USER\SOFTWARE\WCwith the valuesCredandPrx. - ESET detection name: MSIL/TeleDoor.A.
- SHA-256 of bad DLL builds (Talos):
f9d6fe8bd8aca6528dec7eaa9f1aafbecde15fd61668182f2ba8a7fc2b9a6740,d462966166450416d6addd3bfdf48590f8440dd80fc571a389023b7c860ca3ac. - SHA-1 values (ESET):
7B051E7E7A82F07873FA360958ACC6492E4385DD,7F3B1C56C180369AE7891483675BEC61F3182F27,3567434E2E49358E8210674641A20B147E0BD23C. - Addresses (Talos):
176.31.182[.]167and159.148.186[.]214. Update host:upd.me-doc.com.ua.
How to check
Check the registry key that the backdoor used, and hash the module. In PowerShell:
Get-ItemProperty "HKCU:\SOFTWARE\WC" -ErrorAction SilentlyContinue; Get-ChildItem C:\ -Recurse -Filter ZvitPublishedObjects.dll -ErrorAction SilentlyContinue | Get-FileHash -Algorithm SHA256
A WC key with Cred or Prx values shows that the backdoor ran. Compare each hash with the list above.
What to do now
- Update M.E.Doc to a current release from the vendor.
- Change proxy and email passwords for all users of the software. ESET gives this advice because the backdoor stole them.
- Delete the
WCregistry key after you record it for evidence. - Segment the network. Limit what an accounting host can reach.
- Block the addresses above and review logs for outbound connections from the software.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 57 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED ZvitPublishedObjects.dll It now downloads from the internet, reads saved passwords and access keys and runs other programs. It did not before.
Frequently asked questions
Which M.E.Doc versions contained the backdoor?
Versions 10.01.175 and 10.01.176, 10.01.180 and 10.01.181, and 10.01.188 and 10.01.189 contained the backdoor.
How did attackers deliver NotPetya through M.E.Doc?
They took control of the M.E.Doc update server and added a backdoor to a module. The backdoor was able to run any code on client machines, which started the NotPetya outbreak on 27 June 2017.
Sources
More supply chain attacks
- JDownloader official site installer swap 6 May 2026
- CPUID CPU-Z / HWMonitor download compromise 9 Apr 2026
- DAEMON Tools trojanized installers 8 Apr 2026
- eScan antivirus update server compromise (2026) 20 Jan 2026
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.