Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

eScan Antivirus Update Server Breached to Deliver Malicious Software Updates

On January 20, 2026, MicroWorld Technologies' eScan antivirus platform experienced a supply chain attack. Threat actors compromised the update infrastructure to distribute multi-stage malware to endpoints globally.

On January 20, 2026, MicroWorld Technologies' eScan antivirus platform experienced a supply chain attack. Threat actors compromised the update infrastructure to distribute multi-stage malware to endpoints globally.

Security researchers alerted the vendor, prompting the isolation of the affected infrastructure within one hour. The global update system was offline for over eight hours. Due to the attack's nature, users are required to contact eScan directly for manual intervention, as standard patching processes are ineffective.

The attack used a three-stage architecture for persistence and defense evasion. The initial stage involved a trojanized eScan component replacing Reload.exe with malicious code. This code dropped CONSCTLX.exe, a 64-bit persistent downloader capable of executing PowerShell commands and maintaining command-and-control communications.

Persistence was established through scheduled tasks disguised within Windows\Defrag\ directories and tampering with hosts files and eScan registry settings to prevent legitimate updates.

Organizations are advised to search for the trojanized Reload.exe using the SHA-256 hash 36ef2ec9ada035c56644f677dab65946798575e1d8b14f1365f22d7c68269860 and scan for related samples on VirusTotal. Registry searches for suspicious keys under HKLM\Software\ and inspection of Windows\Defrag\ scheduled tasks are recommended.

Network security teams should block the identified C2 domains and IP addresses. eScan has released patches, but manual intervention is required before standard updates can be reinstalled.

Indicators of Compromise (IOCs) – eScan Supply Chain Attack

Component Details Hash/Value

Affected File Reload.exe (32-bit) Primary malicious payload

Primary Hash (SHA-256) 36ef2ec9ada035c56644f677dab65946798575e1d8b14f1365f22d7c68269860 Observed delivered payload

Related Sample 1 VirusTotal submission 674943387cc7e0fd18d0d6278e6e4f7a0f3059ee6ef94e0976fae6954ffd40dd

Related Sample 2 VirusTotal submission 386a16926aff225abc31f73e8e040ac0c53fb093e7daf3fbd6903c157d88958c

On January 20, 2026, MicroWorld Technologies' eScan antivirus platform experienced a supply chain attack.
Rebecca Stone · Thehackingpost

Code Signing Certificate Issuer eScan (Microworld Technologies Inc.) Legitimate certificate misused

Certificate Thumbprint 76B0D9D51537DA06707AFA97B4AE981ED6D03483 For validation purposes

Stage 2: Command & Control Infrastructure

C2 Domain/IP Status Type

hxxps[://]vhs[.]delrosal[.]net/i Unconfirmed Domain (Defanged)

hxxps[://]tumama[.]hns[.]to Unconfirmed Domain (Defanged)

hxxps[://]blackice[.]sol-domain[.]org Unconfirmed Domain (Defanged)

hxxps[://]codegiant[.]io/dd/dd/dd[.]git/download/main/middleware[.]ts Unconfirmed Domain Path (Defanged)

504e1a42.host.njalla.net Unconfirmed Subdomain

185.241.208.115 Unconfirmed IP Address

Advertisement

Filename SHA-256 Hash

CONSCTLX.exe (64-bit) bec369597633eac7cc27a698288e4ae8d12bdd9b01946e73a28e1423b17252b1

Persistence Type Location/Key Details

Scheduled Tasks C:\Windows\Defrag\ Pattern: Windows\Defrag<Application>Defrag

Task Example Windows\Defrag\CorelDefrag Observed variant

Registry Persistence HKLM\Software<randomly generated GUID> Encoded PowerShell payload (byte array)

Hosts File Tampering C:\Windows\System32\drivers\etc\hosts Blocks eScan update servers

eScan Registry Tampering eScan product configuration keys Disables legitimate updates

Directory Marker programdata\efirst Sometimes generated as marking indicator

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories