Threat reportSupply ChainTL-2026-0028
GuptiMiner — North Korean (Kimsuky/APT43) Supply Chain Attack Hijacking eScan Antivirus HTTP Updates via AitM
GuptiMiner — North Korean (Kimsuky/APT43) Supply Chain (TL-2026-0028), also tracked as eScan Supply Chain, is a critical-severity supply-chain compromise, first published 2026-02-02. It is attributed to Kimsuky (North Korea) with medium confidence, affects MicroWorld Technologies eScan Antivirus, maps to 39 MITRE ATT&CK techniques (T1005, T1016, T1018), and is covered by 9 detection rules and 51 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 0None referenced
- Techniques
- 39MITRE ATT&CK
- Actors
- 1Kimsuky
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 51Indicators of compromise
Key facts for TL-2026-0028
- Threat ID
- TL-2026-0028
- Also known as
- eScan Supply Chain, MicroWorld Compromise, Antivirus Update Attack
- Severity
- CRITICAL
- Status
- MONITORING
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution
- Kimsuky
- Attribution confidence
- MEDIUM
- Nation-state nexus
- North Korea
- Motivation
- ESPIONAGE
- Target sectors
- Technology, Financial Services, Government, Cryptocurrency, Corporate Networks
- Target regions
- Global, South Asia, Southeast Asia
- Detection rules
- 9
- Indicators of compromise
- 51
Malware and tooling in GuptiMiner — North Korean (Kimsuky/APT43) Supply Chain
Malware and tooling: Enhanced PuTTY Link backdoor, Enhanced PuTTY Link backdoor — SMB lateral movement to Win7/2008, Enhanced PuTTY Link backdoor — network reconnaissance and SMB lateral movement tool, GuptiMiner, GuptiMiner — multi-stage framework: DLL sideload → backdoors → crypto miner, GuptiMiner — multi-stage malware framework delivered via hijacked eScan AV updates, Modular backdoor with crypto wallet scanner, Modular backdoor — crypto wallet/private key scanner with registry C2, Modular backdoor — cryptocurrency wallet and private key scanner with registry-based C2, Monero Miner, XMRig Monero miner — cryptocurrency mining (possible distraction), XMRig Monero miner — cryptocurrency mining payload (possible distraction)
How GuptiMiner — North Korean (Kimsuky/APT43) Supply Chain works
North Korean threat actors (suspected Kimsuky/APT43) hijacked the update mechanism of eScan antivirus to deliver GuptiMiner — a highly sophisticated multi-stage malware framework that deploys backdoors and XMRig cryptocurrency miners onto corporate networks. The attack used an adversary-in-the-middle (AitM) position to intercept eScan's HTTP-based virus definition update traffic, replacing legitimate update packages ('updll62.dlz') with trojanized versions containing GuptiMiner as a DLL sideloaded by eScan's own legitimate signed binaries. The malware achieves system-level privileges through DLL sideloading via eScan's trusted executables, then deploys: (1) an enhanced PuTTY Link backdoor for network reconnaissance and SMB lateral movement targeting Windows 7/Server 2008 systems, (2) a modular backdoor that scans for stored private keys and cryptocurrency wallets with registry-based command-and-control, and (3) XMRig Monero miner as possible distraction from the primary espionage objective. GuptiMiner exhibits exceptional operational sophistication: DNS-based C2 communication with attacker-controlled DNS servers, payload extraction from steganographic PNG images, payload signing for integrity verification, code virtualization for anti-analysis, XOR-encrypted payload storage in Windows registry, shellcode injection into legitimate processes, and comprehensive sandbox/analysis tool detection (Wireshark, WinDbg, Process Explorer, etc.). The campaign has been active since at least 2018, discovered by Avast (Gen Digital) researchers Jan Rubín and Jiří Kaňovský in April 2024. eScan acknowledged the vulnerability and implemented HTTPS-based updates, but Avast continued to observe new infections from outdated eScan clients. The attack represents the weaponization of the most trusted software channel — antivirus updates — by a nation-state actor for espionage and financial gain.
The GuptiMiner/eScan supply chain attack is a textbook example of the SECURITY TOOL PARADOX: the software designed to protect systems becomes the vector that compromises them. By hijacking the antivirus update mechanism — the single most trusted software delivery channel on any endpoint — North Korean actors achieved persistent, system-level access to corporate networks while operating under the protective umbrella of the security product itself.
**THE ATTACK CHAIN:**
1. **Adversary-in-the-Middle on Update Channel:** The attackers established an AitM position to intercept eScan's virus definition update traffic. eScan's update mechanism used HTTP (unencrypted) for downloading update packages, allowing the attackers to replace legitimate packages in transit.
2. **Trojanized Update Package:** The malicious package ('updll62.dlz') contained both the legitimate virus definition updates AND GuptiMiner malware as a DLL named 'version.dll'. The legitimate updates still functioned normally — users experienced no disruption.
3. **DLL Sideloading via Trusted Binaries:** eScan's own legitimate, signed executables loaded the malicious 'version.dll' through DLL search order hijacking. Because the parent process was a trusted antivirus binary, the malware inherited system-level privileges AND was effectively invisible to other security tools that whitelist antivirus processes.
4. **Multi-Stage Payload Deployment:** GuptiMiner then deployed multiple payloads: - Enhanced PuTTY Link backdoor for network reconnaissance and SMB lateral movement - Modular backdoor for cryptocurrency wallet/private key theft - XMRig Monero miner (possibly as distraction)
**GUPTIMINER SOPHISTICATION:**
GuptiMiner demonstrates nation-state level operational sophistication:
- **DNS-based C2:** Communicates with attacker-controlled DNS servers for command-and-control, evading network monitoring that focuses on HTTP/HTTPS traffic. - **Steganographic Payloads:** Extracts additional payloads from PNG images, hiding malicious code within seemingly innocuous image files. - **Payload Signing:** Signs its own payloads for integrity verification, mimicking legitimate software distribution practices. - **Code Virtualization:** Uses code virtualization techniques to prevent reverse engineering and static analysis. - **Registry-based Storage:** Stores XOR-encrypted payloads in the Windows registry, avoiding file-based detection. - **Process Injection:** Injects shellcode into legitimate processes for execution camouflage. - **Anti-Analysis:** Checks for 4+ CPU cores and 4GB+ RAM (sandbox detection), and detects Wireshark, WinDbg, TCPView, 360 Total Security, Huorong Internet Security, Process Explorer, Process Monitor, and OllyDbg. - **Security Tool Deactivation:** Actively disables AhnLab and Cisco Talos products on compromised machines.
**KIMSUKY/APT43 ATTRIBUTION:**
Avast researchers identified similarities between GuptiMiner's information-stealing function and known Kimsuky keyloggers, plus shared infrastructure including the domain mygamesonline[.]org — a domain ordinarily seen in Kimsuky operations. Kimsuky (also tracked as APT43, Velvet Chollima, Emerald Sleet, Thallium) is a North Korean state-sponsored group primarily focused on espionage and cryptocurrency theft to fund the DPRK regime.
**THE ANTIVIRUS UPDATE PARADOX:**
This attack inverts the security model fundamentally: - Antivirus updates are the MOST trusted software delivery channel - Organizations specifically ALLOW antivirus to execute with system privileges - Security tools WHITELIST antivirus processes from monitoring - Antivirus updates are frequent (multiple times daily) and automated - Users are TRAINED to keep antivirus updated — the update itself is the attack
Compromising the AV update channel gives attackers: system privileges, persistence, whitelisting by other security tools, and a delivery mechanism that runs automatically on every endpoint.
**ESCAN'S RESPONSE:**
eScan acknowledged the vulnerability and stated the last similar report was in 2019. In 2020, they implemented binary signature verification. In the most recent fix, eScan migrated update downloads to HTTPS. However, Avast continued observing new GuptiMiner infections, indicating outdated eScan clients remain vulnerable.
**CAMPAIGN TIMELINE:**
The campaign has been active since at least 2018, making it a 6+ year persistent operation. The longevity suggests the attackers had reliable AitM capability and the attack went undetected for years due to its inherent trust model exploitation.
MITRE ATT&CK techniques used in TL-2026-0028
collection
T1005 Data from Local System; T1056 Input Capture; T1074 Data Staged
discovery
T1016 System Network Configuration Discovery; T1018 Remote System Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1518 Software Discovery
lateral-movement
T1021 Remote Services; T1570 Lateral Tool Transfer
defense-evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1055 Process Injection; T1070 Indicator Removal; T1112 Modify Registry; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion
exfiltration
T1041 Exfiltration Over C2 Channel; T1048 Exfiltration Over Alternative Protocol
execution
T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter; T1106 Native API
command-and-control
T1071 Application Layer Protocol; T1090 Proxy; T1095 Non-Application Layer Protocol; T1105 Ingress Tool Transfer; T1132 Data Encoding; T1573 Encrypted Channel
initial-access
T1195 Supply Chain Compromise; T1199 Trusted Relationship
impact
T1496 Resource Hijacking; T1657 Financial Theft
persistence
T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution
credential-access
defense-impairment
T1553 Subvert Trust Controls; T1685 Disable or Modify Tools
stealth
Affected products and versions in GuptiMiner — North Korean (Kimsuky/APT43) Supply Chain
- MicroWorld Technologies — eScan Antivirus
Vulnerable versions: Versions receiving updates during compromise period
Fixed in: Post-remediation updates
Remediation for GuptiMiner — North Korean (Kimsuky/APT43) Supply Chain
Patches
- eScan: Update to latest version with HTTPS-enforced updates and binary signature verification
- All endpoints: Scan for GuptiMiner IOCs from Avast's GitHub repository
Immediate actions
- UPDATE ESCAN IMMEDIATELY: Ensure eScan is running the latest version with HTTPS-enforced updates. Outdated clients are STILL being infected as of April 2024. Verify update URL uses HTTPS, not HTTP.
- SCAN FOR GUPTIMINER IOCs: Check all eScan-protected endpoints for GuptiMiner indicators: 'version.dll' in eScan directories, scheduled task persistence, DNS queries to known GuptiMiner C2 servers, XMRig processes, PuTTY Link variants, and registry entries with XOR-encrypted data.
- NETWORK TRAFFIC ANALYSIS: Monitor for DNS queries to attacker-controlled DNS servers (not your organization's resolvers). GuptiMiner uses DNS-based C2 that bypasses standard web traffic monitoring.
- CRYPTOCURRENCY WALLET AUDIT: GuptiMiner's modular backdoor specifically scans for stored private keys and cryptocurrency wallets. If eScan was installed on systems with crypto wallets, assume wallet keys are compromised and transfer funds immediately.
- CHECK FOR LATERAL MOVEMENT: GuptiMiner deploys an enhanced PuTTY Link backdoor that scans for Windows 7/Server 2008 systems and performs SMB-based lateral movement. Check for unusual SMB traffic patterns, especially targeting legacy OS systems.
Workarounds
- If unable to update eScan immediately: block eScan update traffic at firewall and manually download/verify updates via HTTPS
- Monitor for version.dll in eScan installation directories that is not signed by MicroWorld Technologies
- Block DNS queries to known GuptiMiner C2 infrastructure at DNS resolver level
Longer-term hardening
- ANTIVIRUS UPDATE CHANNEL SECURITY: Verify that ALL security tools use HTTPS with certificate pinning for update delivery. HTTP-based updates are susceptible to AitM interception. This applies to all endpoint security products, not just eScan.
- SECURITY TOOL SUPPLY CHAIN VERIFICATION: Implement integrity verification for security tool updates independent of the tool's own verification. Use host-based IDS to detect unexpected DLLs loaded by security product processes.
- DEFENSE-IN-DEPTH FOR SECURITY TOOLS: Do not rely on a single antivirus product. Layer EDR, network monitoring, and behavioral analysis. If one security tool is compromised, others should detect the anomaly.
- VENDOR SECURITY ASSESSMENT FOR SECURITY PRODUCTS: Evaluate security product vendors' update infrastructure security. Products that deliver updates over HTTP in 2024 represent unacceptable risk regardless of other capabilities.
- LEGACY SYSTEM REMEDIATION: GuptiMiner specifically targets Windows 7/Server 2008 for lateral movement. Migrate or isolate legacy systems that remain on the network.
Weaknesses (CWE) in GuptiMiner — North Korean (Kimsuky/APT43) Supply Chain
Timeline of GuptiMiner — North Korean (Kimsuky/APT43) Supply Chain
- GuptiMiner campaign begins. North Korean actors (suspected Kimsuky/APT43) establish adversary-in-the-middle capability to intercept eScan antivirus HTTP update traffic. The campaign would operate for 6+ years before discovery. The longevity indicates reliable AitM positioning and the inherent difficulty of detecting supply chain attacks through trusted software channels.
- eScan receives report of update mechanism vulnerability (per eScan's statement to Avast). The nature and scope of the 2019 report is unclear, but eScan acknowledged awareness of the attack vector at this point.
- eScan implements binary signature verification for update packages — 'a more robust checking mechanism to make sure that non-signed binaries were rejected.' This was intended to prevent trojanized update packages from being accepted. However, GuptiMiner infections continued, suggesting either the signing check was bypassable or the AitM attack was modified.
- Mandiant publishes detailed report on APT43 (Kimsuky), establishing the group's dual mandate: espionage collection for the DPRK regime AND cryptocurrency theft to fund operations. APT43 is described as 'moderately-sophisticated' with a unique capability to fund itself through cybercrime. Source: https://www.mandiant.com/resources/blog/apt43-north-korea-cybercrime-espionage
- eScan confirms migration to HTTPS-based update delivery for cloud-facing servers. This prevents AitM interception of update traffic. However, Avast reports continued new GuptiMiner infections, indicating outdated eScan clients that haven't updated to the HTTPS-enabled version remain vulnerable. The window between vulnerability disclosure and client updates is itself a period of elevated risk.
- Avast publishes GuptiMiner indicators of compromise (IOCs) on GitHub (github.com/avast/ioc/tree/master/GuptiMiner). IOCs include file hashes, network indicators, DNS C2 domains, and behavioral indicators. BleepingComputer, SecurityWeek, The Record, and other outlets publish coverage. Source: https://www.bleepingcomputer.com/news/security/hackers-hijack-antivirus-updates-to-drop-guptiminer-malware/
- Avast (Gen Digital) researchers Jan Rubín and Jiří Kaňovský publish comprehensive analysis of GuptiMiner. The malware is described as 'a highly sophisticated threat' that hijacks eScan antivirus updates via AitM. Key findings: DNS-based C2, steganographic payload extraction from PNGs, payload signing, code virtualization, XOR-encrypted registry storage, and suspected Kimsuky attribution via shared domain mygamesonline[.]org. Source: https://decoded.avast.io/janrubin/guptiminer-hijacking-antivirus-updates-for-distributing-backdoors-and-casual-mining/
- Revalidation assessment: The GuptiMiner campaign represents one of the most sophisticated supply chain attacks targeting security software. Key lasting impacts: (1) demonstrated that antivirus update channels are viable nation-state attack vectors, (2) established that HTTP-based security tool updates are an unacceptable risk, (3) showed that DLL sideloading via trusted security binaries provides exceptional evasion, (4) confirmed North Korean actors combine espionage with cryptocurrency theft in unified campaigns. Legacy eScan clients may still be vulnerable. The attack pattern is replicable against any security product using insecure update mechanisms.
- As of 2026-05-29, the GuptiMiner AitM/HTTP vector is patched (eScan fixed the flaw 2023-07-31 and migrated updates to HTTPS), but Avast/Gen Digital telemetry still shows residual infections on outdated clients and attributed actor Kimsuky/APT43 remains active (Jan 2026 FBI quishing alert). A separate, unattributed Jan-2026 eScan server-breach incident is distinct and does not supersede this campaign.
Sources cited for GuptiMiner — North Korean (Kimsuky/APT43) Supply Chain
- BleepingComputer — Hackers hijack antivirus updates to drop GuptiMiner malware
- Avast (Gen Digital) — GuptiMiner: Hijacking Antivirus Updates for Distributing Backdoors and Casual Mining
- Avast IOC Repository — GuptiMiner Indicators of Compromise
- MITRE ATT&CK — Kimsuky (G0094)
- CISA — North Korean State-Sponsored Cyber Actors Use Cryptocurrency to Fund Operations
- Mandiant — APT43: North Korea's Crypto Espionage Group
Detection coverage for TL-2026-0028
As of 2026-02-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0028 across Splunk SPL, Microsoft KQL and Sigma, covering 51 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.