eScan Antivirus Update Server Breached to Deliver Malicious Software Updates
On January 20, 2026, MicroWorld Technologies' eScan antivirus platform experienced a supply chain attack. Threat actors compromised the update infrastructure to distribute multi-stage malware to endpoints globally.
On January 20, 2026, MicroWorld Technologies' eScan antivirus platform experienced a supply chain attack. Threat actors compromised the update infrastructure to distribute multi-stage malware to endpoints globally.
Security researchers alerted the vendor, prompting the isolation of the affected infrastructure within one hour. The global update system was offline for over eight hours. Due to the attack's nature, users are required to contact eScan directly for manual intervention, as standard patching processes are ineffective.
The attack used a three-stage architecture for persistence and defense evasion. The initial stage involved a trojanized eScan component replacing Reload.exe with malicious code. This code dropped CONSCTLX.exe, a 64-bit persistent downloader capable of executing PowerShell commands and maintaining command-and-control communications.
Persistence was established through scheduled tasks disguised within Windows\Defrag\ directories and tampering with hosts files and eScan registry settings to prevent legitimate updates.
Organizations are advised to search for the trojanized Reload.exe using the SHA-256 hash 36ef2ec9ada035c56644f677dab65946798575e1d8b14f1365f22d7c68269860 and scan for related samples on VirusTotal. Registry searches for suspicious keys under HKLM\Software\ and inspection of Windows\Defrag\ scheduled tasks are recommended.
Network security teams should block the identified C2 domains and IP addresses. eScan has released patches, but manual intervention is required before standard updates can be reinstalled.
Indicators of Compromise (IOCs) – eScan Supply Chain Attack
Component Details Hash/Value
Affected File Reload.exe (32-bit) Primary malicious payload
Primary Hash (SHA-256) 36ef2ec9ada035c56644f677dab65946798575e1d8b14f1365f22d7c68269860 Observed delivered payload
Related Sample 1 VirusTotal submission 674943387cc7e0fd18d0d6278e6e4f7a0f3059ee6ef94e0976fae6954ffd40dd
Related Sample 2 VirusTotal submission 386a16926aff225abc31f73e8e040ac0c53fb093e7daf3fbd6903c157d88958c
On January 20, 2026, MicroWorld Technologies' eScan antivirus platform experienced a supply chain attack.
Code Signing Certificate Issuer eScan (Microworld Technologies Inc.) Legitimate certificate misused
Certificate Thumbprint 76B0D9D51537DA06707AFA97B4AE981ED6D03483 For validation purposes
Stage 2: Command & Control Infrastructure
C2 Domain/IP Status Type
hxxps[://]vhs[.]delrosal[.]net/i Unconfirmed Domain (Defanged)
hxxps[://]tumama[.]hns[.]to Unconfirmed Domain (Defanged)
hxxps[://]blackice[.]sol-domain[.]org Unconfirmed Domain (Defanged)
hxxps[://]codegiant[.]io/dd/dd/dd[.]git/download/main/middleware[.]ts Unconfirmed Domain Path (Defanged)
504e1a42.host.njalla.net Unconfirmed Subdomain
185.241.208.115 Unconfirmed IP Address
Filename SHA-256 Hash
CONSCTLX.exe (64-bit) bec369597633eac7cc27a698288e4ae8d12bdd9b01946e73a28e1423b17252b1
Persistence Type Location/Key Details
Scheduled Tasks C:\Windows\Defrag\ Pattern: Windows\Defrag<Application>Defrag
Task Example Windows\Defrag\CorelDefrag Observed variant
Registry Persistence HKLM\Software<randomly generated GUID> Encoded PowerShell payload (byte array)
Hosts File Tampering C:\Windows\System32\drivers\etc\hosts Blocks eScan update servers
eScan Registry Tampering eScan product configuration keys Disables legitimate updates
Directory Marker programdata\efirst Sometimes generated as marking indicator
Based on reporting by GBHackers.
