logo

eScan Antivirus Update Servers Compromised to Deliver Multi-Stage Malware

ID: f4bb6d84-c260-59f9-a6ec-33d74f0253ff

STIX ID: report--f4bb6d84-c260-59f9-a6ec-33d74f0253ff

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-02-02

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

On January 20, 2026, attackers gained unauthorized access to a regional eScan update server and pushed a malicious update that replaced reload.exe with a rogue, signed-but-invalid binary. The malicious binary executes Base64-encoded PowerShell payloads to tamper with eScan (preventing updates and detection), bypass AMSI, validate victims, and fetch additional payloads (CONSCTLX.exe and scheduled-task PowerShell malware) from attacker-controlled infrastructure; MicroWorld isolated affected update servers, released a remediation patch, and Kaspersky telemetry identified hundreds of attempted infections mainly in India, Bangladesh, Sri Lanka, and the Philippines.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.