logo

eScan Antivirus Update Mechanism Exploited to Spread Backdoors and Miners

ID: 19a2532d-608a-518f-8269-e3ffc95ba6fd

STIX ID: report--19a2532d-608a-518f-8269-e3ffc95ba6fd

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-04-24

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Avast reported a long-running GuptiMiner campaign exploiting an insecure eScan update mechanism (unsigned, non-HTTPS downloads) to sideload a malicious DLL (updll62.dlz -> version.dll) that implements a multi-stage loader: DNS-based C2 resolution, PNG files with appended shellcode, gzip-decompressed payloads, and a final Puppeteer backdoor that deploys XMRig miners and modular backdoors capable of lateral movement and credential/crypto-wallet theft; telemetry and artifact uploads date activity back to 2018 and researchers note overlaps with tools linked to the North Korean group Kimsuky.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.