The MediaGet Poisoned Update and Dofoil Outbreak

Updated 5 Oct 2026 · Incident date 12 Feb 2018 · vendor binary

PackageMediaGet BitTorrent client - poisoned update replaced mediaget.exe; outbreak hit 400,000 PCs on 6 March 2018
Filemediaget.exe

In February 2018, a poisoned update for the MediaGet BitTorrent client delivered a trojanized mediaget.exe. On 6 March 2018 it started the Dofoil coin miner outbreak.

Microsoft reported the campaign on 7 March 2018. BleepingComputer reports that more than 400,000 users were targeted in 12 hours, mostly in Russia and Turkey.

What happened

A signed MediaGet program fetched an update that was a trojanized copy of itself. Microsoft describes MediaGet as a potentially unwanted application, a BitTorrent client used to download programs and media. Microsoft's analysis gives this chain.

  1. The signed MediaGet executable downloaded update.exe, an InnoSetup self-extracting file.
  2. It contained a trojanized mediaget.exe that was 98 percent similar to the real file but added command-and-control functions.
  3. The trojan contacted .bit domains (NameCoin) and used 71 embedded DNS servers.
  4. A RUN command downloaded Dofoil as my.dat and ran it.
  5. Dofoil installed a coin miner.

BleepingComputer reports that attackers breached MediaGet infrastructure in mid-February and replaced the installer between 12 and 19 February. It also reports that they used a stolen certificate to sign the update. The company did not comment to BleepingComputer. The outbreak waited about two weeks between the first change and the main attack. Microsoft says Windows Defender detected the attack within milliseconds, and cloud protection reached users within 15 minutes. Windows 10 S was not affected.

Read Microsoft's analysis, BleepingComputer and The Hacker News.

The installed program changed into a copy that downloads and runs code. A comparison of the old and new mediaget.exe shows that gain.

Affected versions

The sources do not give MediaGet version numbers. They identify the bad files by hash.

Any MediaGet copy whose mediaget.exe matches the trojanized hash below is affected.

Indicators of compromise

FileSHA-1Microsoft detection
mediaget.exe (official)1038d32974969a1cc7a79c3fc7b7a5ab8d14fd3ePUA:Win32/MediaGet
update.exe (trojanized)513a1624b47a4bca15f2f32457153482bedda640Trojan:Win32/Modimer.A
mediaget.exe (trojanized)3e0ccd9fa0a5c40c2abb40ed6730556e3d36af3cTrojan:Win32/Modimer.A
my.dat (Dofoil)d84d6ec10694f76c56f6b7367ab56ea1f743d284TrojanDownloader:Win32/Dofoil.AB

Other indicators: a file named update.exe next to MediaGet, and DNS lookups for .bit domains.

How to check

Hash the MediaGet executable and compare it with the table. Run this in the MediaGet install folder.

certutil -hashfile mediaget.exe SHA1

A match with 3e0ccd9f... means the trojan is present. Also search the machine for my.dat and update.exe with the hashes above.

What to do now

  1. Hash mediaget.exe on each Windows machine and compare it with the table.
  2. Uninstall MediaGet. Microsoft classes it as a potentially unwanted application.
  3. If you find the trojan hash, scan and clean the machine with an up-to-date antivirus, or rebuild it.
  4. Check DNS logs for .bit domain lookups.
  5. Do not accept an update to a signed program only because it is signed. Compare the new file with the old one.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old MediaGet-prev --new MediaGet-current
files scanned: 68

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    mediaget.exe
           It now downloads from the internet. It did not before.

Frequently asked questions

What was the MediaGet poisoned update?

A trojanized mediaget.exe delivered through MediaGet's update in February 2018. It downloaded Dofoil, which installed a coin miner.

How many computers did the Dofoil outbreak hit?

BleepingComputer reports that more than 400,000 users were targeted within 12 hours on 6 March 2018. Microsoft says hundreds of thousands of computers.

How do I check if I have the trojanized mediaget.exe?

Run certutil -hashfile mediaget.exe SHA1 and compare the result with 3e0ccd9fa0a5c40c2abb40ed6730556e3d36af3c.

Sources

  1. microsoft.com/en-us/security/blog/2018/03/13/poisoned-peer-to-peer-app-kicked-off-dofoil-coin-miner-outbreak/
  2. bleepingcomputer.com/news/security/400k-malware-outbreak-caused-by-backdoored-russian-torrenting-client/
  3. thehackernews.com/2018/03/windows-malware-hacking.html

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free