The M.E.Doc Update Supply Chain Attack

Updated 5 Oct 2026 · Incident date 14 Apr 2017 · vendor binary

PackageM.E.Doc 10.01.174 -> 10.01.175/176 (also 10.01.180/181 and 10.01.188/189)
FileZvitPublishedObjects.dll

In 2017, the Ukrainian accounting software M.E.Doc shipped three sets of backdoored updates: 10.01.175 and 10.01.176 (14 April), 10.01.180 and 10.01.181 (15 May), and 10.01.188 and 10.01.189 (22 June). The backdoor sat in the module ZvitPublishedObjects.dll.

The same update path delivered the NotPetya outbreak of 27 June 2017. ESET reports that the last bad update came five days before it.

Major incident. Microsoft observed infections in Ukraine and another 64 countries. This entry covers the same outbreak as the other M.E.Doc record. Impact source

What happened

Attackers took over the update server and added a backdoor to a program module that most Ukrainian companies already trusted. According to ESET, the .NET module ZvitPublishedObjects.dll held a backdoor class named MeCom. A method in the update checker, IsNewUpdate, called it each time the software checked for updates.

The clean updates of 17 May to 21 June had no backdoor. The bad sets came before two attack waves. ESET notes that the 15 May set preceded the Filecoder.AESNI.C ransomware by three days, and that the 22 June set preceded the DiskCoder.C (NotPetya) outbreak by five days.

Talos explains how the server was used. Attackers used stolen M.E.Doc administrator credentials, changed the NGINX configuration on the update server upd.me-doc.com.ua, and sent update traffic to a server they controlled. BleepingComputer reports that the server had not been updated since 2013, according to Ukrainian officials, and that a PHP web shell named medoc_online.php was found.

The backdoor collected company registration numbers (EDRPOU), proxy settings and credentials, and email account user names and passwords. It had six commands, including running shell commands, dropping and running files, and loading a DLL through rundll32.exe. ESET found that the last command matched how DiskCoder.C was first deployed. ESET reports that data left in cookies on requests to the update server. Talos describes queries to command servers every two minutes. Ukrainian police raided the vendor on 4 July 2017 and seized its servers.

Vigilance compares the version you trust with the new one. These updates changed a program module so that it fetches and runs outside code. Vigilance reports the file that gained that capability. See the scan block below.

Affected versions

ESET states that updates between 17 May and 21 June 2017 were clean. Check the exact build against the vendor's current release.

Indicators of compromise

How to check

Check the registry key that the backdoor used, and hash the module. In PowerShell:

Get-ItemProperty "HKCU:\SOFTWARE\WC" -ErrorAction SilentlyContinue; Get-ChildItem C:\ -Recurse -Filter ZvitPublishedObjects.dll -ErrorAction SilentlyContinue | Get-FileHash -Algorithm SHA256

A WC key with Cred or Prx values shows that the backdoor ran. Compare each hash with the list above.

What to do now

  1. Update M.E.Doc to a current release from the vendor.
  2. Change proxy and email passwords for all users of the software. ESET gives this advice because the backdoor stole them.
  3. Delete the WC registry key after you record it for evidence.
  4. Segment the network. Limit what an accounting host can reach.
  5. Block the addresses above and review logs for outbound connections from the software.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old M.E.Doc-10.01.174 --new M.E.Doc-10.01.175
files scanned: 57

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    ZvitPublishedObjects.dll
           It now downloads from the internet, reads saved passwords and access keys and runs other programs. It did not before.

Frequently asked questions

Which M.E.Doc versions contained the backdoor?

Versions 10.01.175 and 10.01.176, 10.01.180 and 10.01.181, and 10.01.188 and 10.01.189 contained the backdoor.

How did attackers deliver NotPetya through M.E.Doc?

They took control of the M.E.Doc update server and added a backdoor to a module. The backdoor was able to run any code on client machines, which started the NotPetya outbreak on 27 June 2017.

Sources

  1. welivesecurity.com/2017/07/04/analysis-of-telebots-cunning-backdoor/
  2. blog.talosintelligence.com/the-medoc-connection/
  3. bleepingcomputer.com/news/security/m-e-doc-software-was-backdoored-3-times-servers-left-without-updates-since-2013/

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free