The NoxPlayer Supply Chain Attack
Updated 5 Oct 2026 · Incident date 1 Sept 2020 · vendor binary
BigNox NoxPlayer 6.6.0.0 through 7.0.2.0 - malicious updates delivered September 2020 to January 2021malicious update packages dropping ieproxysocket.dll /...Attackers abused the update system of BigNox NoxPlayer, an Android emulator, between September 2020 and January 2021. ESET named the operation NightScout and published its findings on 1 February 2021.
The attackers did not hit every user. ESET confirmed five victims in Taiwan, Hong Kong, and Sri Lanka. NoxPlayer has over 150 million users.
What happened
Attackers compromised two BigNox servers and used the official updater to deliver malware. ESET found the activity on 25 January 2021.
The two servers were the API server (api.bignox.com) and the file hosting server (res06.bignox.com). Securityaffairs reports that the attackers changed the download URL of NoxPlayer updates on the API server. Some updates came from BigNox's own host. Others came from attacker domains such as cdn.cloudfronter[.]com and cdn.cloudfronte[.]com.
ESET found three malware variants. Each one targeted only a few chosen machines.
- Variant 1 dropped
ieproxysocket.dllandieproxysocket64.dllinC:\Program Files\Internet Explorer\. It can manage files, run commands, and upload and download files. - Variant 2 used files that looked like Sandboxie components in
C:\ProgramData\Sandboxie\. Its final payload was Gh0st RAT, which includes a keylogger. - Variant 3 used files that looked like Logitech components in
C:\ProgramData\LoGiTech\. Its final payload was PoisonIvy RAT.
ESET saw only surveillance functions and no sign of financial motive. On 3 February 2021, BigNox moved updates to HTTPS only. It also added MD5 file checks, signature checks, and file verification at start up.
Affected versions
The attack record for this page lists NoxPlayer 6.6.0.0 through 7.0.2.0 as the versions that received malicious updates. The delivery period ran from September 2020 to 25 January 2021.
- Product: BigNox NoxPlayer
- Updater file:
%LOCALAPPDATA%\Nox\update\UpdatePackageSilence.exe, unsigned in the bad cases - Delivery period: September 2020 to 25 January 2021
Most users received clean updates. The poisoned update went to selected machines only.
Indicators of compromise
ESET lists file paths, hashes, addresses, and domains.
C:\Program Files\Internet Explorer\ieproxysocket.dllC:\Program Files\Internet Explorer\ieproxysocket64.dllC:\ProgramData\Sandboxie\SbieIni.datC:\ProgramData\Sandboxie\SbieDll.dllC:\ProgramData\LoGiTech\LBTServ.dll- Variant 1 SHA-1:
CA4276033A7CBDCCDE26105DEC911B215A1CE5CF - Variant 2 SHA-1:
E45A5D9B03CFBE7EB2E90181756FDF0DD690C00C - Variant 3 SHA-1:
AA3D31A1A6FE6888E4B455DADDA4755A6D42BEEB - Command servers:
210.209.72[.]180,103.255.177[.]138,185.239.226[.]172,45.158.32[.]65 - Domains:
cdn.cloudistcdn[.]com,q.cloudistcdn[.]com,update.boshiamys[.]com,cdn.cloudfronter[.]com,cdn.cloudfronte[.]com
How to check
Test for the dropped files first. Run this in PowerShell.
'C:\Program Files\Internet Explorer\ieproxysocket.dll','C:\Program Files\Internet Explorer\ieproxysocket64.dll','C:\ProgramData\Sandboxie\SbieDll.dll','C:\ProgramData\LoGiTech\LBTServ.dll' | ForEach-Object { "$_ " + (Test-Path $_) }Then check the updater file for a signature.
Get-AuthenticodeSignature "$env:LOCALAPPDATA\Nox\update\UpdatePackageSilence.exe"
Search proxy and DNS logs for the domains and addresses above. A genuine Sandboxie or Logitech folder can exist on a machine for other reasons. Compare the file with the hashes before you act.
What to do now
- If any dropped file exists, treat the machine as compromised.
- Reinstall the system from clean media. ESET recommends this step.
- Block the command servers and domains at the firewall.
- Check for open connections to the listed servers.
- If you are not affected, avoid NoxPlayer updates until BigNox fixes the threat. ESET gives this advice. BigNox announced fixes on 3 February 2021.
Vigilance compares the version you trust with the new one. NoxPlayer had a long clean update history. The poisoned update added a new executable component with remote-access capability. That addition shows in the comparison with the clean update.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 64 (1 Added) HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. NEW FILE ieproxysocket.dll It downloads from the internet.
Frequently asked questions
What was Operation NightScout?
It was a supply chain attack on BigNox NoxPlayer found by ESET. Attackers used the product's own update system to send malware to a few chosen victims from September 2020 to January 2021.
How many people did the NoxPlayer attack hit?
ESET confirmed five victims in Taiwan, Hong Kong, and Sri Lanka. NoxPlayer has over 150 million users.
Sources
More supply chain attacks
- JDownloader official site installer swap 6 May 2026
- CPUID CPU-Z / HWMonitor download compromise 9 Apr 2026
- DAEMON Tools trojanized installers 8 Apr 2026
- eScan antivirus update server compromise (2026) 20 Jan 2026
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.