eScan Antivirus Update Server Breached to Deliver Malicious Software Updates
ID: 56f23ebf-c61a-53fd-a7c7-70ea5ab22880
STIX ID: report--56f23ebf-c61a-53fd-a7c7-70ea5ab22880
Feed Name: GBHackers
MicroWorld Technologies’ eScan antivirus update infrastructure was compromised in a January 20, 2026 supply-chain attack that delivered multi-stage malware: a trojanized Reload.exe (SHA-256 36ef2e...) and a 64-bit persistent downloader CONSCTLX.exe (SHA-256 bec36959...). The threat actors disabled eScan update mechanisms, tampered with hosts and registry entries to block remediation, established persistence via scheduled tasks (e.g., Windows\Defrag\CorelDefrag), and used multiple C2 domains/IPs; eScan isolated infrastructure and issued patches but affected systems require manual remediation. The report includes detailed IOCs (file hashes, certificate thumbprint, C2 domains/IP) and recommended discovery and containment steps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
