Threat Bulletin: Critical eScan Supply Chain Compromise
ID: f71eb28b-3e00-5af4-a7e9-2a00e8eff01a
STIX ID: report--f71eb28b-3e00-5af4-a7e9-2a00e8eff01a
Feed Name: Morphisec Blog
**Executive Summary:** On January 20, 2026 Morphisec identified a supply-chain compromise of MicroWorld's eScan antivirus where malicious updates (trojanized Reload.exe) were distributed via the vendor's update infrastructure, deploying a multi-stage downloader (CONSCTLX.exe) that tampers with eScan registry, hosts file and update mechanisms to prevent automatic remediation; the report provides SHA-256 hashes, a code-signing thumbprint, C2 indicators, persistence details, detection steps, and remediation guidance including contacting eScan for a manual patch.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
