eScan confirms update server breached to push malicious update
ID: 3c4af92f-6971-555f-90d2-0abb01e3f53f
STIX ID: report--3c4af92f-6971-555f-90d2-0abb01e3f53f
Feed Name: Bleeping Computer
Threat Score
MicroWorld's eScan update infrastructure was breached on January 20, 2026, allowing a malicious update (modified Reload.exe leading to a CONSCTLX.exe backdoor/downloader) to be distributed to customers for a short window; Morphisec published technical findings (persistence via scheduled tasks, HOSTS modifications, C2 domains) and eScan has isolated and rebuilt impacted infrastructure, rotated credentials, and issued remediation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
