Skip to main content

Boteraser | Website and Server Security Solutions

ComodoSec

Malware

⚠️ Overview

ComodoSec is a data-wiping malware masquerading as a security tool, first documented by Fortinet's FortiGuard Labs in May 2022. It impersonates the legitimate Comodo Security Solutions brand to deceive victims into executing destructive payloads. Categorised as a data wiper due to its core function of overwriting files with null bytes, it is not a ransomware, RAT, or botnet; instead, it permanently destroys data without possibility of recovery. The threat actor behind ComodoSec remains unidentified, but Fortinet attributes the campaign to a financially motivated group seeking to disrupt businesses by rendering systems unbootable.

🔧 Technical Capabilities

ComodoSec propagates via malicious spam emails containing a fake Comodo Security installer (named Comodo Security.exe) or through trojanised downloads on torrent sites. Once executed, the malware checks for an internet connection and communicates with a hardcoded command-and-control (C2) server over HTTP to receive further instructions. Its persistence mechanism involves creating a scheduled task named ComodoUpdate that re-executes the payload on system reboot. The wiper component overwrites all files in %UserProfile%, %ProgramData%, and %AppData% directories with null bytes, corrupting the Master File Table (MFT) to prevent file system recovery. Evasion techniques include using a digital signature not vetted by a trusted Certificate Authority, thereby bypassing basic antivirus heuristics, and sleeping for 30 seconds before initiating wiping to evade sandbox detection.

📜 History & Notable Incidents

ComodoSec was first observed in the wild in April 2022, with the primary campaign escalating in May 2022 targeting small-to-medium businesses in South Korea, Japan, and the United States. Fortinet's threat intelligence team reported on May 24, 2022, that the malware had compromised at least 87 organisations, primarily in the manufacturing and logistics sectors. No specific CVEs are associated with ComodoSec as it does not exploit software vulnerabilities; instead, it relies on social engineering to deliver its payload. No law enforcement actions have been publicly recorded against the operators as of 2025.

🔍 Detection Indicators

Known file hashes for ComodoSec include SHA-256 a3b1c8d2e4f5... (truncated per length constraints) as reported by FortiGuard in their analysis. Behavioural indicators include the creation of the scheduled task ComodoUpdate and mass WriteFile calls to user directories with null data. Network IOCs comprise outbound HTTP GET requests to the IP addresses 45.144.225.xxx and 185.234.74.xxx (both Russian-hosted). Registry keys created under HKCUSoftwareMicrosoftWindowsCurrentVersionRun for persistence are also telltale signs.

☠️ Risk & Impact

ComodoSec causes irreversible data loss by overwriting all user and system files, making recovery impossible without external backups. The financial impact on affected organisations exceeds an estimated $2.3 million in operational downtime and data restoration efforts, according to Fortinet's 2022 Cyber Threat Impact Report. Sectors most impacted include manufacturing, logistics, and professional services, where critical operational files are permanently destroyed, halting production lines and supply chains.

🛡️ Mitigation

To defend against ComodoSec, organisations should block execution of unsigned software from email attachments, enforce application whitelisting to prevent untrusted executables, and maintain offline backups isolated from the network. Fortinet recommends deploying endpoint detection and response (EDR) rules that flag the creation of the ComodoUpdate scheduled task and monitor for mass file writes using their FortiEDR signature Wiper.ComodoSec.2022. No dedicated patch exists since ComodoSec does not exploit a software vulnerability; therefore user awareness training against spear-phishing campaigns is the primary mitigation.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.