Proprietary · · 146 days

NoxPlayer updates delivered targeted malware

BigNox's NoxPlayer update mechanism delivered tailored malware to a few Asian users. The payloads favored surveillance, not mass monetization.

Operation NightScout used NoxPlayer's own update flow. On launch, Nox.exe queried api.bignox.com for update metadata, then passed the returned URL, size, and hash to NoxPack.exe, which downloaded and installed the update.

ESET found enough evidence to say BigNox infrastructure was part of the delivery path. res06.bignox.com hosted malware, and the API response may have been changed so selected clients received attacker-chosen update URLs. ESET could reproduce malware downloads from BigNox infrastructure over HTTPS, which made a simple network-manipulation explanation unlikely.

The campaign stayed narrow. ESET saw more than 100,000 protected machines with NoxPlayer installed, but only five received malicious updates, in Taiwan, Hong Kong, and Sri Lanka. The malware families included a custom monitor, Gh0st RAT, and PoisonIvy, all consistent with surveillance.

BigNox first denied compromise, then told ESET it would use HTTPS for updates, add MD5 and signature checks, and scan installed application files at startup. Later ESET research linked victims from the supply-chain attack to Gelsemium tooling, but the original NightScout report left attribution cautious.

Notes

  • ESET found no evidence that BigNox's build system was compromised; malicious files were unsigned, pointing to update distribution rather than source or build tampering.
  • ESET later linked victims originally compromised by NightScout to Gelsemium tooling, but the original report did not attribute the supply-chain compromise to a named group.

Appendix · Affected releases

NoxPlayer malicious update variant 1 NoxPlayer update service
  • ESET described this as a preliminary malicious update hosted on compromised BigNox infrastructure.
NoxPlayer malicious update variant 2 NoxPlayer update service
  • This variant used a trident-style bundle with a signed Sandboxie executable, a malicious DLL, and an encrypted payload.
NoxPlayer malicious update variant 3 NoxPlayer update service
  • ESET saw this variant downloaded from attacker-controlled infrastructure after the initial malicious updates. The domains mimicked the BigNox CDN naming pattern.
  • ESET also published AA3D31A1A6FE6888E4B455DADDA4755A6D42BEEB as a SHA-1, but it is 41 hexadecimal characters and is not stored as a normalized hash.

References

  1. Operation NightScout: Supply-chain attack targets online gaming in Asiawelivesecurity.com
  2. ESET uncovers Operation NightScout: Cyberespionage supply-chain attack on gamers in Asiaeset.com
  3. Hacker group inserted malware in NoxPlayer Android emulatorzdnet.com
  4. Operation NightScout: supply chain attack on NoxPlayer Android emulatorsecurityaffairs.com
  5. NoxPlayer Supply-Chain Attack is Likely the Work of Gelsemium Hackersthehackernews.com

Source record: proprietary/noxplayer/meta.yaml