Supply chain attack on eScan antivirus: detecting and remediating malicious updates
ID: 2d88e74f-85b6-57df-8637-6b3df12423a1
STIX ID: report--2d88e74f-85b6-57df-8637-6b3df12423a1
Feed Name: Securelist by Kaspersky
Date Published: 2026-01-29
Date Updated: 2026-04-29
Author: Georgy Kucherin, Kirill Korchemny, Ilya Savelyev
On January 20 an eScan antivirus regional update server was breached and used to distribute a malicious updater (Reload.exe) that prevented antivirus updates by modifying the hosts file, created persistence via scheduled tasks (example: CorelDefrag), dropped additional payloads (e.g., consctlx.exe), and communicated with command-and-control domains; vendors contained the incident, provided a cleanup utility, and investigators published IoCs and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
