The MonPass Certificate Authority Client Backdoor

Updated 5 Oct 2026 · Incident date 8 Feb 2021 · vendor binary

PackageMonPass client installer served from the MonPass website, 8 February to 3 March 2021
Filethe MonPass client installer executable itself - an uns...

The MonPass client installer, served from the website of the Mongolian certificate authority, carried a backdoor from 8 February to 3 March 2021. The backdoor loaded a Cobalt Strike beacon hidden inside an image file.

Avast found the backdoor on 24 March 2021 and published its report on 1 July 2021. MonPass confirmed on 29 June 2021 that it had fixed the issues and told affected customers.

What happened

Attackers broke into the public web server of MonPass and replaced the client installer with a backdoored build. The Avast report found eight different webshells and backdoors on the server. This points to repeated intrusions.

The poisoned installer downloaded a bitmap image from an attacker server. The code took every fourth byte of the image data, starting from the third byte, and turned the resulting hex text into binary. It then decrypted the result with the XOR key miat_mg and ran a Cobalt Strike beacon. The malware also checked processor count, memory, and disk size, and stopped if the values looked like an analysis machine.

Avast could not attribute the attack with confidence. It reports circumstantial evidence of a China-based espionage group, based on similar campaigns against government bodies and certificate authorities in Asia. The Record also covered it.

The timeline from the Avast report: first contact with MonPass through MN CERT/CC on 8 April 2021, a forensic image of the server shared on 20 April, and findings sent on 22 April.

Affected versions

MonPass did not publish version numbers in the sources used here. The affected file is the MonPass client installer that visitors could download from the MonPass website between 8 February and 3 March 2021. Anyone who downloaded the client in that period is affected. A clean installer had been on the same page before.

Indicators of compromise

The full list is at github.com/avast/ioc.

How to check

Hash the installer you saved and compare it with the Avast list. On macOS or Linux:

shasum -a 256 MonPass-installer.exe

On Windows, use Get-FileHash in PowerShell. Search proxy and DNS logs for the listed domains.

Get-FileHash .\MonPass-installer.exe -Algorithm SHA256

What to do now

  1. Find every machine that installed the MonPass client between 8 February and 3 March 2021.
  2. Compare hashes and logs with the Avast indicators.
  3. If a match exists, treat the machine as compromised. A Cobalt Strike beacon gives the operator remote control.
  4. Reinstall the client from the current MonPass site and reset credentials used on the machine.
  5. Contact MonPass or MN CERT/CC if you were a customer. MonPass reports that it notified affected customers.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old MonPass-prev --new MonPass-current
files scanned: 76

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    MonPass.exe
           It now downloads from the internet, reads saved passwords and access keys and runs other programs. It did not before.

Frequently asked questions

When was the MonPass client backdoored?

The backdoored client was available from 8 February to 3 March 2021, according to Avast.

What malware did the MonPass installer load?

It downloaded an image, extracted a hidden payload from it, and ran a Cobalt Strike beacon.

Who was behind the MonPass backdoor?

Avast could not attribute the attack with confidence. It reports circumstantial evidence of a China-based espionage group.

Sources

  1. decoded.avast.io/luigicamastra/backdoored-client-from-mongolian-ca-monpass/
  2. gendigital.com/blog/insights/research/backdoored-client-from-mongolian-ca-monpass
  3. therecord.media/mongolian-certificate-authority-hacked-eight-times-compromised-with-malware

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free