logo

Supply chain attack on eScan antivirus: detecting and remediating malicious updates

ID: 2d88e74f-85b6-57df-8637-6b3df12423a1

STIX ID: report--2d88e74f-85b6-57df-8637-6b3df12423a1

Feed Name: Securelist by Kaspersky

Threat Score
82/100

Date Published: 2026-01-29

Date Updated: 2026-04-29

Author: Georgy Kucherin, Kirill Korchemny, Ilya Savelyev

...
...

On January 20 an eScan antivirus regional update server was breached and used to distribute a malicious updater (Reload.exe) that prevented antivirus updates by modifying the hosts file, created persistence via scheduled tasks (example: CorelDefrag), dropped additional payloads (e.g., consctlx.exe), and communicated with command-and-control domains; vendors contained the incident, provided a cleanup utility, and investigators published IoCs and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.