logo

Hackers hijack antivirus updates to drop GuptiMiner malware

ID: 180f74c7-9f82-5d15-bf25-bba9b5ee4fe5

STIX ID: report--180f74c7-9f82-5d15-bf25-bba9b5ee4fe5

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2024-04-23

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Avast researchers found that North Korean-linked actors hijacked eScan antivirus update packages to distribute GuptiMiner — a sophisticated payload that sideloads a malicious DLL, fetches additional modules, disables security products, persists via scheduled tasks and registry entries, extracts payloads from images, and deploys backdoors and an XMRig miner; Avast released IoCs and eScan patched the update mechanism but infections persist, possibly from outdated clients.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.