Threat Bulletin: Critical eScan Supply Chain Compromise
ID: 7d4f0dad-2c8c-5b5f-aa44-4a3f1717f9d4
STIX ID: report--7d4f0dad-2c8c-5b5f-aa44-4a3f1717f9d4
Feed Name: Morphisec Blog
On January 20, 2026 Morphisec identified a supply-chain compromise of MicroWorld Technologies’ eScan antivirus: malicious update packages distributed through the vendor’s update infrastructure dropped a multi-stage downloader (Reload.exe → CONSCTLX.exe) that establishes persistence, connects to C2 infrastructure, and tampers with eScan registry, files, and hosts to block updates and automatic remediation; Morphisec provides IOCs (SHA-256 hashes, C2 domains, scheduled task patterns, registry keys) and advises isolating affected systems, contacting eScan for a manual patch, and conducting forensic investigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
