US customers of Kaspersky antivirus find that UltraAV was installed remotely to replace Kaspersky on their PCs, after a Kaspersky deal with UltraAV owner Pango
switchover caught many users by surprise Ernestas Naprys / Cybernews.com : Kaspersky users shocked by automatic antivirus replacement without explicit permission Sofia Elizabella Wyciślik-Wilson / BetaNews : Kaspersky users in the US find themselves forcibly migrated to the mysterious UltraAV Luke Jones / WinBuzzer : Kaspersky Replaces Antivirus with UltraAV Following US Exit Ionut Arghire / SecurityWeek : Users Quick To Remove UltraAV After Silent Transition From Kaspersky Antivirus Alaina Yee / PCWorld : Kaspersky just slipped a different antivirus onto subscribers' PCs The Hacker News : Kaspersky Exits U.S., Automatically Replaces Software With UltraAV, Raising Concerns Paul Shread / The Cyber Express : Kaspersky's Weird Exit from the U.S. Market Catches Users Off Guard Kristina Beek / Dark Reading : Kaspersky Rolls Back for US Customers, Makes Way for UltraAV Zeljka Zorz / Help Net Security : US-based Kaspersky users startled by unexpected UltraAV installation Simon Batt / MakeUseOf : If “UltraAV” Has Randomly Appeared on Your PC, Here's Why Sayan Sen / Neowin : Kaspersky users suddenly finding “UltraAV” automatically installed on their PC, here's why X: Eva / @evacide : JFC Kaspersky, uninstalling your software from US devices is fine, but installing a different AV without warning or consent is bananas. This is not how you exit a market. https://www.bleepingcomputer.com/ ... Rob Joyce / @rgb_lights : This is why handing root-level access to Kaspersky was a huge risk. Users were “migrated” - software uninstalled and a totally different product was installed automagically. They had total control of your machine. #itsabouttrust Kontra / @counternotions : Can't for EU to force Apple to interop with Kaspersky in the name of competition in platform security, but I digress. https://techcrunch.com/... @malwrhunterteam : 🤡 sounding move from Kaspersky, but not really surprising... 🤷♂️ Lorenzo Franceschi-Bicchierai / @lorenzofb : NEW: Some U.S. customers of Kaspersky antivirus received a surprise, forced, and automatic update to little-known UltraAV antivirus. “They should NEVER push software onto someone's computer without explicit permission,” one ex Kaspersky customer told me. https://techcrunch.com/... Oleg Shakirov / @shakirov2036 : After Kaspersky's US sales were banned, a US company Pango purchased from it 1 mil users & is now migrating them to its own product by automatically deleting Kaspersky and installing UltraAV. Many users were caught by surprise & are not excited about this https://www.reddit.com/... [image] Forums: r/technews : Kaspersky deletes itself, installs UltraAV antivirus without warning r/nottheonion : Kaspersky deletes itself, installs UltraAV antivirus without warning r/antivirus : Kaspersky deletes itself, installs UltraAV antivirus without warning r/technology : Kaspersky deletes itself, installs UltraAV antivirus without warning Msmash / Slashdot : Some Kaspersky Customers Receive Surprise Forced-Update To New Antivirus Software 1
Context & Ripple Effects
The surprise migration is the operational follow-through from Kaspersky's planned US shutdown after the sales ban, which put its remaining US customer relationships into transition.
Related coverage subsequently reported Kaspersky's confirmation that UltraAV had replaced its software for US users, tying the incident to Pango's acquisition of those accounts rather than an isolated installation error.
First-order effects
- US Kaspersky customers received UltraAV remotely in place of their existing antivirus, changing the security software running on their PCs without an explicit opt-in at the point of installation.
- Pango immediately becomes responsible for serving the transferred customer base and for the trust implications of a migration users say they did not expect.
Second-order effects
- Users who remove the replacement product or question the handoff can create support, retention, and reputation pressure for Pango; the later confirmation of the replacement makes that transition more visible rather than resolving the consent concern.
- The episode raises the competitive value of clear export, uninstall, and migration paths for security vendors serving customers affected by market exits or policy-driven restrictions.
Third-order effects
- If endpoint-security providers increasingly transfer accounts during forced market exits, ownership of customer contracts and control of device-level update channels will become a more consequential part of security-market consolidation.
- The durable fault line is likely to be user consent in software succession: a legitimate account transfer does not automatically produce user trust in a remotely installed replacement.
The trend: Policy-driven vendor exits are turning endpoint-security distribution into a test of portable customer relationships and transparent, user-controlled software migration.