eScan Antivirus Update Mechanism Exploited to Spread Backdoors and Miners
ID: 19a2532d-608a-518f-8269-e3ffc95ba6fd
STIX ID: report--19a2532d-608a-518f-8269-e3ffc95ba6fd
Feed Name: The Hacker News
Avast reported a long-running GuptiMiner campaign exploiting an insecure eScan update mechanism (unsigned, non-HTTPS downloads) to sideload a malicious DLL (updll62.dlz -> version.dll) that implements a multi-stage loader: DNS-based C2 resolution, PNG files with appended shellcode, gzip-decompressed payloads, and a final Puppeteer backdoor that deploys XMRig miners and modular backdoors capable of lateral movement and credential/crypto-wallet theft; telemetry and artifact uploads date activity back to 2018 and researchers note overlaps with tools linked to the North Korean group Kimsuky.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
