logo

Threat Bulletin: Critical eScan Supply Chain Compromise

ID: f71eb28b-3e00-5af4-a7e9-2a00e8eff01a

STIX ID: report--f71eb28b-3e00-5af4-a7e9-2a00e8eff01a

Feed Name: Morphisec Blog

Threat Score
85/100

Date Published: 2026-01-28

Date Updated: 2026-04-28

...
...

**Executive Summary:** On January 20, 2026 Morphisec identified a supply-chain compromise of MicroWorld's eScan antivirus where malicious updates (trojanized Reload.exe) were distributed via the vendor's update infrastructure, deploying a multi-stage downloader (CONSCTLX.exe) that tampers with eScan registry, hosts file and update mechanisms to prevent automatic remediation; the report provides SHA-256 hashes, a code-signing thumbprint, C2 indicators, persistence details, detection steps, and remediation guidance including contacting eScan for a manual patch.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.