Hackers hijack antivirus updates to drop GuptiMiner malware
ID: 180f74c7-9f82-5d15-bf25-bba9b5ee4fe5
STIX ID: report--180f74c7-9f82-5d15-bf25-bba9b5ee4fe5
Feed Name: Bleeping Computer
Threat Score
Avast researchers found that North Korean-linked actors hijacked eScan antivirus update packages to distribute GuptiMiner — a sophisticated payload that sideloads a malicious DLL, fetches additional modules, disables security products, persists via scheduled tasks and registry entries, extracts payloads from images, and deploys backdoors and an XMRig miner; Avast released IoCs and eScan patched the update mechanism but infections persist, possibly from outdated clients.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
