The NoxPlayer Supply Chain Attack

Updated 5 Oct 2026 · Incident date 1 Sept 2020 · vendor binary

PackageBigNox NoxPlayer 6.6.0.0 through 7.0.2.0 - malicious updates delivered September 2020 to January 2021
Filemalicious update packages dropping ieproxysocket.dll /...

Attackers abused the update system of BigNox NoxPlayer, an Android emulator, between September 2020 and January 2021. ESET named the operation NightScout and published its findings on 1 February 2021.

The attackers did not hit every user. ESET confirmed five victims in Taiwan, Hong Kong, and Sri Lanka. NoxPlayer has over 150 million users.

What happened

Attackers compromised two BigNox servers and used the official updater to deliver malware. ESET found the activity on 25 January 2021.

The two servers were the API server (api.bignox.com) and the file hosting server (res06.bignox.com). Securityaffairs reports that the attackers changed the download URL of NoxPlayer updates on the API server. Some updates came from BigNox's own host. Others came from attacker domains such as cdn.cloudfronter[.]com and cdn.cloudfronte[.]com.

ESET found three malware variants. Each one targeted only a few chosen machines.

ESET saw only surveillance functions and no sign of financial motive. On 3 February 2021, BigNox moved updates to HTTPS only. It also added MD5 file checks, signature checks, and file verification at start up.

Affected versions

The attack record for this page lists NoxPlayer 6.6.0.0 through 7.0.2.0 as the versions that received malicious updates. The delivery period ran from September 2020 to 25 January 2021.

Most users received clean updates. The poisoned update went to selected machines only.

Indicators of compromise

ESET lists file paths, hashes, addresses, and domains.

How to check

Test for the dropped files first. Run this in PowerShell.

'C:\Program Files\Internet Explorer\ieproxysocket.dll','C:\Program Files\Internet Explorer\ieproxysocket64.dll','C:\ProgramData\Sandboxie\SbieDll.dll','C:\ProgramData\LoGiTech\LBTServ.dll' | ForEach-Object { "$_ " + (Test-Path $_) }

Then check the updater file for a signature.

Get-AuthenticodeSignature "$env:LOCALAPPDATA\Nox\update\UpdatePackageSilence.exe"

Search proxy and DNS logs for the domains and addresses above. A genuine Sandboxie or Logitech folder can exist on a machine for other reasons. Compare the file with the hashes before you act.

What to do now

  1. If any dropped file exists, treat the machine as compromised.
  2. Reinstall the system from clean media. ESET recommends this step.
  3. Block the command servers and domains at the firewall.
  4. Check for open connections to the listed servers.
  5. If you are not affected, avoid NoxPlayer updates until BigNox fixes the threat. ESET gives this advice. BigNox announced fixes on 3 February 2021.

Vigilance compares the version you trust with the new one. NoxPlayer had a long clean update history. The poisoned update added a new executable component with remote-access capability. That addition shows in the comparison with the clean update.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old BigNox-prev --new BigNox-current
files scanned: 64 (1 Added)

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

NEW FILE   ieproxysocket.dll
           It downloads from the internet.

Frequently asked questions

What was Operation NightScout?

It was a supply chain attack on BigNox NoxPlayer found by ESET. Attackers used the product's own update system to send malware to a few chosen victims from September 2020 to January 2021.

How many people did the NoxPlayer attack hit?

ESET confirmed five victims in Taiwan, Hong Kong, and Sri Lanka. NoxPlayer has over 150 million users.

Sources

  1. welivesecurity.com/2021/02/01/operation-nightscout-supply-chain-attack-online-gaming-asia/
  2. securityaffairs.com/114090/hacking/noxplayer-supply-chain-attack.html

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free