What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In 2021, attackers compromised MonPass’s public website and used it to distribute a client installer backdoored with Cobalt Strike. Avast said the infected installer was available from February 8 through March 3, 2021, and advised people who downloaded it during that period to look for and remove both the client and the backdoor. The evidence describes a software-distribution breach—not proven theft of certificate-signing keys or fraudulent certificate issuance.

What happened to MonPass?

MonPass, a major Mongolian certification authority, had its public web server compromised. Attackers placed a trojanized installer for the MonPass client on the official site, turning a trusted download source into a route for malware delivery. Avast’s technical report describes the payload as involving Cobalt Strike; ENISA later summarized the case as a supplier-code compromise that led to drive-by compromise and malware infection. Avast Threat Labs’ investigation and ENISA’s supply-chain case summary document the incident.

What “certificate authority compromise” means here

The reported breach affected MonPass’s public web server and client-software distribution. The cited accounts do not establish that attackers stole certificate-signing keys, accessed the certificate-issuance infrastructure, or issued fraudulent certificates. Those are distinct risks and should not be inferred from the compromised installer.

How the malware worked

Avast reported that the malware used steganography to decrypt a Cobalt Strike beacon. Avast assessed that the trusted Mongolian source was used to reach users in Mongolia, but the available reporting does not verify the attacker’s ultimate target or establish a broader motive.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall

When was the MonPass installer infected?

Avast said the backdoored client was available for download from February 8 through March 3, 2021. Its discovery and response timeline was:

Date Reported event
February 8–March 3, 2021 Period when the infected installer was available, according to Avast.
March 24, 2021 Avast discovered the backdoored installer.
April 8, 2021 Avast made initial contact with MonPass through MN CERT/CC.
April 20, 2021 MonPass shared an image of an infected web server with Avast.
April 22, 2021 Avast briefed MonPass and MN CERT/CC on its findings.
June 29, 2021 Avast said MonPass had reported resolving the issues and notifying affected customers. This is a historical update, not a statement about MonPass’s security today.
July 1, 2021 Avast published its investigation.

The dates and status updates above come from Avast’s report.

What did investigators find, and how many users were affected?

Avast reported multiple webshells and backdoors on MonPass’s compromised public server. ENISA’s July 2021 case summary records at least one customer infection identified by Avast. The sources do not provide a verified total of affected users, a broader impact statistic, or a quantified loss estimate, so the overall number of victims remains unknown.

Who hacked MonPass?

Avast did not attribute the incident to a specific actor. Its report states: “At this time, we’re not able to make attribution of these attacks with an appropriate level of confidence.” Similarities to other campaigns discussed in contemporary coverage do not establish who was responsible. The Record’s July 1, 2021 report is a contemporary account; it should not be treated as confirmation of attribution.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should someone do if they downloaded the client then?

Avast advised anyone who downloaded the MonPass client between February 8 and March 3, 2021, to look for and remove the client and the backdoor it installed. That is the cleanup guidance Avast published for the affected download window; the cited sources do not provide a current MonPass incident-response procedure or recommend a particular security product.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.