{"id":10234,"date":"2026-01-29T10:04:28","date_gmt":"2026-01-29T10:04:28","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/01\/29\/escan-antivirus-update-server-hacked-to-push-malicious-update-packages\/"},"modified":"2026-01-29T10:04:28","modified_gmt":"2026-01-29T10:04:28","slug":"escan-antivirus-update-server-hacked-to-push-malicious-update-packages","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/01\/29\/escan-antivirus-update-server-hacked-to-push-malicious-update-packages\/","title":{"rendered":"eScan Antivirus Update Server Hacked to Push Malicious Update packages"},"content":{"rendered":"<p>    eScan Antivirus Update Server Hacked to Push Malicious Update packages<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A critical supply chain compromise affecting MicroWorld Technologies\u2019 eScan antivirus product, wherein threat actors successfully hijacked the vendor\u2019s legitimate update infrastructure to distribute malware.<\/p>\n<p>Discovered on January 20, 2026, by Morphisec, the attack utilized a trojanized update package to deploy multi-stage malware across enterprise and consumer endpoints globally. <\/p>\n<p>The incident renders the antivirus software ineffective and specifically tampers with system configurations to prevent automatic remediation.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-trojanized-update-mechanism-and-attack-chain\"><strong>Trojanized Update Mechanism and Attack Chain<\/strong><\/h2>\n<p>The compromise was initiated through a malicious update pushed directly via eScan\u2019s official channels. The attack chain begins with \u201cStage 1,\u201d where a trojanized component replaces the legitimate\u00a0<code>Reload.exe<\/code>\u00a0(32-bit) binary. <\/p>\n<p>Morphisec <a href=\"https:\/\/www.morphisec.com\/blog\/critical-escan-threat-bulletin\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">observed<\/a> that the malicious executable is digitally signed with a valid certificate belonging to \u201ceScan (Microworld Technologies Inc.),\u201d allowing it to bypass standard trust verifications.<\/p>\n<p>Once executed, this payload drops a \u201cStage 3\u201d downloader identified as\u00a0<code>CONSCTLX.exe<\/code>. Following the initial breach, a \u201cStage 2\u201d downloader establishes persistence and executes defense evasion maneuvers.<\/p>\n<p>This stage is particularly aggressive, employing PowerShell execution and tampering with the <a href=\"https:\/\/cybersecuritynews.com\/windows-registry-manipulated\/\" target=\"_blank\" rel=\"noreferrer noopener\">Windows Registry<\/a> to disable security features.<\/p>\n<p>The malware connects to <a href=\"https:\/\/cybersecuritynews.com\/command-and-controlc2-server\/\" target=\"_blank\" rel=\"noreferrer noopener\">Command and Control (C2)<\/a> infrastructure to retrieve additional payloads, effectively turning the security tool into a gateway for further compromise.<\/p>\n<p>A defining characteristic of this campaign is its focus on \u201canti-remediation.\u201d The malware actively modifies the infected system\u2019s\u00a0<code>hosts<\/code>\u00a0file to block communication with eScan\u2019s update servers. <\/p>\n<p>Furthermore, it alters specific eScan registry keys and configuration files to break the antivirus\u2019s update mechanism permanently. <\/p>\n<p>Consequently, infected systems cannot receive automatic patches or definitions, leaving them vulnerable even after the vendor restores their infrastructure.<\/p>\n<p>Persistence is achieved through the creation of deceptive Scheduled Tasks located in\u00a0<code>C:WindowsDefrag<\/code>. The malware generates tasks using a naming pattern that mimics legitimate system processes, such as\u00a0<code>WindowsDefragCorelDefrag<\/code>. <\/p>\n<p>Additionally, registry persistence is established under\u00a0<code>HKLMSoftware<\/code>\u00a0using randomly generated GUID keys containing encoded PowerShell payloads.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-indicators-of-compromise-iocs\"><strong>Indicators of Compromise (IOCs)<\/strong><\/h2>\n<p>Organizations utilizing eScan antivirus are urged to scan their environments immediately for the following indicators. <\/p>\n<p>Note that automatic remediation is not possible; the presence of these files indicates a compromise requiring manual intervention.<\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\">Component Description<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Filename<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">SHA-256 Hash<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">\n<strong>Stage 1 Payload<\/strong>\u00a0(Trojanized Update)<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Reload[.]exe (32-bit)<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">36ef2ec9ada035c56644f677dab65946798575e1d8b14f1365f22d7c68269860<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>Stage 3 Downloader<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">CONSCTLX[.]exe (64-bit)<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">bec369597633eac7cc27a698288e4ae8d12bdd9b01946e73a28e1423b17252b1<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>Related Sample<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">N\/A<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">674943387cc7e0fd18d0d6278e6e4f7a0f3059ee6ef94e0976fae6954ffd40dd<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><strong>Related Sample<\/strong><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">N\/A<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">386a16926aff225abc31f73e8e040ac0c53fb093e7daf3fbd6903c157d88958c<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<h2 class=\"wp-block-heading\" id=\"h-network-indicators-and-c2-infrastructure\"><strong>Network Indicators and C2 Infrastructure<\/strong><\/h2>\n<p>Network administrators should block egress traffic to the following domains, which have been identified as part of the attacker\u2019s command and control infrastructure.<\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\">Domain \/ IP<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Context<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">hxxps[:\/\/]vhs[.]delrosal[.]net\/i<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">C2 Infrastructure<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">hxxps[:\/\/]tumama[.]hns[.]to<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">C2 Infrastructure<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">hxxps[:\/\/]blackice[.]sol-domain[.]org<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">C2 Infrastructure<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">504e1a42.host.njalla.net<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Malicious Host<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">185.241.208[.]115<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Malicious IP<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<h2 class=\"wp-block-heading\" id=\"h-remediation-and-mitigation-measures\"><strong>Remediation and Mitigation Measures<\/strong><\/h2>\n<p>Because the malware effectively breaks the update mechanism of the antivirus software, automatic updates will fail on compromised machines. <\/p>\n<p>eScan has reportedly taken the global update system offline for over eight hours to isolate the infrastructure, but this does not clean already infected endpoints.<\/p>\n<p>Administrators must assume compromise for systems running eScan that were active on or after January 20, 2026. <\/p>\n<p>Immediate steps include verifying the\u00a0<code>hosts<\/code>\u00a0file for entries blocking eScan domains and inspecting the registry for suspicious GUID keys containing byte array data. <\/p>\n<p>Affected organizations must contact MicroWorld Technologies (eScan) directly to obtain a specialized manual patch designed to revert the configuration changes and restore the updater\u2019s functionality. <\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/escan-antivirus-update-server-hacked\/\">eScan Antivirus Update Server Hacked to Push Malicious Update packages<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/escan-antivirus-update-server-hacked\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>eScan Antivirus Update Server Hacked to Push Malicious Update packages A critical supply chain compromise affecting MicroWorld Technologies\u2019 eScan antivirus product, wherein threat actors successfully hijacked the vendor\u2019s legitimate update infrastructure to distribute malware. Discovered on January 20, 2026, by Morphisec, the attack utilized a trojanized update package to deploy multi-stage malware across enterprise and [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63],"tags":[130],"class_list":["post-10234","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10234"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=10234"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10234\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=10234"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=10234"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=10234"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}