The MonPass Certificate Authority Client Backdoor
Updated 5 Oct 2026 · Incident date 8 Feb 2021 · vendor binary
MonPass client installer served from the MonPass website, 8 February to 3 March 2021the MonPass client installer executable itself - an uns...The MonPass client installer, served from the website of the Mongolian certificate authority, carried a backdoor from 8 February to 3 March 2021. The backdoor loaded a Cobalt Strike beacon hidden inside an image file.
Avast found the backdoor on 24 March 2021 and published its report on 1 July 2021. MonPass confirmed on 29 June 2021 that it had fixed the issues and told affected customers.
What happened
Attackers broke into the public web server of MonPass and replaced the client installer with a backdoored build. The Avast report found eight different webshells and backdoors on the server. This points to repeated intrusions.
The poisoned installer downloaded a bitmap image from an attacker server. The code took every fourth byte of the image data, starting from the third byte, and turned the resulting hex text into binary. It then decrypted the result with the XOR key miat_mg and ran a Cobalt Strike beacon. The malware also checked processor count, memory, and disk size, and stopped if the values looked like an analysis machine.
Avast could not attribute the attack with confidence. It reports circumstantial evidence of a China-based espionage group, based on similar campaigns against government bodies and certificate authorities in Asia. The Record also covered it.
The timeline from the Avast report: first contact with MonPass through MN CERT/CC on 8 April 2021, a forensic image of the server shared on 20 April, and findings sent on 22 April.
Affected versions
MonPass did not publish version numbers in the sources used here. The affected file is the MonPass client installer that visitors could download from the MonPass website between 8 February and 3 March 2021. Anyone who downloaded the client in that period is affected. A clean installer had been on the same page before.
Indicators of compromise
- SHA-256 hashes listed by Avast:
e2596f015378234d9308549f08bcdca8eadbf69e488355cddc9c2425f77b7535,f21a9c69bfca6f0633ba1e669e5cf86bd8fc55b2529cd9b064ff9e2e129525e8,4a43fa8a3305c2a17f6a383fb68f02515f589ba112c6e95f570ce421cc690910, and others in the Avast IoC repository. - Files named
DNS.exe,Browser_plugin.exe, andSilverlight_ins.exe. - Payload URLs on
download.google-images.ml:8880,micsoftin.us:2086,37.61.205.212:8880, andjquery-code.ml. - The PDB path
C:\Users\test\Desktop\fishmaster\x64\Release\fishmaster.pdband the stringBidenhappyhappyhappyin the samples.
The full list is at github.com/avast/ioc.
How to check
Hash the installer you saved and compare it with the Avast list. On macOS or Linux:
shasum -a 256 MonPass-installer.exe
On Windows, use Get-FileHash in PowerShell. Search proxy and DNS logs for the listed domains.
Get-FileHash .\MonPass-installer.exe -Algorithm SHA256
What to do now
- Find every machine that installed the MonPass client between 8 February and 3 March 2021.
- Compare hashes and logs with the Avast indicators.
- If a match exists, treat the machine as compromised. A Cobalt Strike beacon gives the operator remote control.
- Reinstall the client from the current MonPass site and reset credentials used on the machine.
- Contact MonPass or MN CERT/CC if you were a customer. MonPass reports that it notified affected customers.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 76 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED MonPass.exe It now downloads from the internet, reads saved passwords and access keys and runs other programs. It did not before.
Frequently asked questions
When was the MonPass client backdoored?
The backdoored client was available from 8 February to 3 March 2021, according to Avast.
What malware did the MonPass installer load?
It downloaded an image, extracted a hidden payload from it, and ran a Cobalt Strike beacon.
Who was behind the MonPass backdoor?
Avast could not attribute the attack with confidence. It reports circumstantial evidence of a China-based espionage group.
Sources
More supply chain attacks
- JDownloader official site installer swap 6 May 2026
- CPUID CPU-Z / HWMonitor download compromise 9 Apr 2026
- DAEMON Tools trojanized installers 8 Apr 2026
- eScan antivirus update server compromise (2026) 20 Jan 2026
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.