Proprietary · · 13 days
KMPlayer updater pushed fake malware release
KMPlayer's update flow offered a fake 3.7.0.87 release that installed malware. KMP Media confirmed external attack activity and warned July-August 2013 users.
KMPlayer users saw an update prompt for version 3.7.0.87 even though the vendor's current clean release was 3.6.0.87. Taiwanese reporting says the prompt led to a different site, which served KMP_3.7.0.87.exe rather than a normal upgrade.
Taiwanese security reporting said the fake updater installed malware into a hidden folder. It also described relay or command domains under abacocafe.com, including pen.abacocafe.com, pens.abacocafe.com, cdn.abacocafe.com, and vpen.abacocafe.com.
KMP Media acknowledged an external attack through a KMPlayer emergency notice. The company warned users who downloaded or installed KMPlayer between 2013-07-26 and 2013-08-08 to scan their systems, said it had strengthened software security, and referred the matter to investigators.
Notes
- This record supersedes an earlier, weaker 2018 entry about adware bundling; the 2013 update-channel compromise is the documented supply-chain event.
- The point of compromise is not established. The Taiwanese advisory reports it as an assessment that the update host or its network segment had been entered, not a finding.
Appendix · Affected releases
References
- KMPlayer officially confirms malware distribution and refers case to investigatorsithome.com.tw
- KM Player compromised, update mechanism downloads malwareinformationsecurity.com.tw
- Trend Micro Threat Encyclopedia - BKDR_PLUGX.ZZXXtrendmicro.com
Source record: proprietary/kmplayer/meta.yaml