eScan Antivirus Update Servers Compromised to Deliver Multi-Stage Malware
ID: f4bb6d84-c260-59f9-a6ec-33d74f0253ff
STIX ID: report--f4bb6d84-c260-59f9-a6ec-33d74f0253ff
Feed Name: The Hacker News
On January 20, 2026, attackers gained unauthorized access to a regional eScan update server and pushed a malicious update that replaced reload.exe with a rogue, signed-but-invalid binary. The malicious binary executes Base64-encoded PowerShell payloads to tamper with eScan (preventing updates and detection), bypass AMSI, validate victims, and fetch additional payloads (CONSCTLX.exe and scheduled-task PowerShell malware) from attacker-controlled infrastructure; MicroWorld isolated affected update servers, released a remediation patch, and Kaspersky telemetry identified hundreds of attempted infections mainly in India, Bangladesh, Sri Lanka, and the Philippines.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
