What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
In 2021, attackers compromised MonPass’s public website and used it to distribute a client installer backdoored with Cobalt Strike. Avast said the infected installer was available from February 8 through March 3, 2021, and advised people who downloaded it during that period to look for and remove both the client and the backdoor. The evidence describes a software-distribution breach—not proven theft of certificate-signing keys or fraudulent certificate issuance.
What happened to MonPass?
MonPass, a major Mongolian certification authority, had its public web server compromised. Attackers placed a trojanized installer for the MonPass client on the official site, turning a trusted download source into a route for malware delivery. Avast’s technical report describes the payload as involving Cobalt Strike; ENISA later summarized the case as a supplier-code compromise that led to drive-by compromise and malware infection. Avast Threat Labs’ investigation and ENISA’s supply-chain case summary document the incident.
What “certificate authority compromise” means here
The reported breach affected MonPass’s public web server and client-software distribution. The cited accounts do not establish that attackers stole certificate-signing keys, accessed the certificate-issuance infrastructure, or issued fraudulent certificates. Those are distinct risks and should not be inferred from the compromised installer.
How the malware worked
Avast reported that the malware used steganography to decrypt a Cobalt Strike beacon. Avast assessed that the trusted Mongolian source was used to reach users in Mongolia, but the available reporting does not verify the attacker’s ultimate target or establish a broader motive.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minute#1 Best Overall
When was the MonPass installer infected?
Avast said the backdoored client was available for download from February 8 through March 3, 2021. Its discovery and response timeline was:
| Date | Reported event |
|---|---|
| February 8–March 3, 2021 | Period when the infected installer was available, according to Avast. |
| March 24, 2021 | Avast discovered the backdoored installer. |
| April 8, 2021 | Avast made initial contact with MonPass through MN CERT/CC. |
| April 20, 2021 | MonPass shared an image of an infected web server with Avast. |
| April 22, 2021 | Avast briefed MonPass and MN CERT/CC on its findings. |
| June 29, 2021 | Avast said MonPass had reported resolving the issues and notifying affected customers. This is a historical update, not a statement about MonPass’s security today. |
| July 1, 2021 | Avast published its investigation. |
The dates and status updates above come from Avast’s report.
What did investigators find, and how many users were affected?
Avast reported multiple webshells and backdoors on MonPass’s compromised public server. ENISA’s July 2021 case summary records at least one customer infection identified by Avast. The sources do not provide a verified total of affected users, a broader impact statistic, or a quantified loss estimate, so the overall number of victims remains unknown.
Who hacked MonPass?
Avast did not attribute the incident to a specific actor. Its report states: “At this time, we’re not able to make attribution of these attacks with an appropriate level of confidence.” Similarities to other campaigns discussed in contemporary coverage do not establish who was responsible. The Record’s July 1, 2021 report is a contemporary account; it should not be treated as confirmation of attribution.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWhat should someone do if they downloaded the client then?
Avast advised anyone who downloaded the MonPass client between February 8 and March 3, 2021, to look for and remove the client and the backdoor it installed. That is the cleanup guidance Avast published for the affected download window; the cited sources do not provide a current MonPass incident-response procedure or recommend a particular security product.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

