Proprietary · · 13 days
KMPlayer updater pushed fake malware release
KMPlayer's update flow offered a fake 3.7.0.87 release that installed malware. KMP Media confirmed external attack activity and warned July-August 2013 users.
KMPlayer users saw an update prompt for version 3.7.0.87 even though the vendor's current clean release was 3.6.0.87. Taiwanese reporting says the prompt led to a different site, which served KMP_3.7.0.87.exe rather than a normal upgrade.
Taiwanese security reporting said the fake updater installed malware into a hidden folder. It also described relay or command domains under abacocafe.com, including pen.abacocafe.com, pens.abacocafe.com, cdn.abacocafe.com, and vpen.abacocafe.com.
KMP Media acknowledged an external attack through a KMPlayer emergency notice. The company warned users who downloaded or installed KMPlayer between 2013-07-26 and 2013-08-08 to scan their systems, said it had strengthened software security, and referred the matter to investigators.
Notes
- The sha256 recorded here previously also appeared on the ibm-aptiva record, a 1999 incident that predates SHA-256; it has been removed there. VirusTotal holds no file with this digest, so it remains unverified here rather than confirmed.
- This record supersedes an earlier, weaker 2018 entry about adware bundling; the 2013 update-channel compromise is the documented supply-chain event.
- The point of compromise is not established. The Taiwanese advisory reports it as an assessment that the update host or its network segment had been entered, not a finding.
Appendix · Affected releases
- A SHA-256 of 5f778e1f90c67968a95874380a19198f7a0a860f9521935096c6bf46905f79a9 was recorded here and removed on 2026-09-11: it is unknown to MalwareBazaar, Triage, ReversingLabs and VirusTotal, and appears in none of the cited sources.
- VirusTotal resolves the SHA-1 above to fe4985b1...bd54, which is already recorded, so the removed value was not this artifact's SHA-256 either.
- Taiwanese reporting described 3.6.0.87 as the current legitimate vendor release while the update mechanism presented a fake 3.7.0.87 update.
References
- KMPlayer officially confirms malware distribution and refers case to investigatorsithome.com.tw
- KM Player compromised, update mechanism downloads malwareinformationsecurity.com.tw
- Trend Micro Threat Encyclopedia - BKDR_PLUGX.ZZXXtrendmicro.com
Source record: proprietary/kmplayer/meta.yaml