# GuptiMiner — North Korean (Kimsuky/APT43) Supply Chain Attack Hijacking eScan Antivirus HTTP Updates via AitM

> North Korean threat actors (suspected Kimsuky/APT43) hijacked the update mechanism of eScan antivirus to deliver GuptiMiner — a highly sophisticated multi-stage malware framework that deploys backdoors and XMRig cryptocurrency miners onto corporate networks. The attack used an adversary-in-the-middle (AitM) position to intercept eScan's HTTP-based virus definition update traffic, replacing legitimate update packages ('updll62.dlz') with trojanized versions containing GuptiMiner as a DLL sideloaded by eScan's own legitimate signed binaries. The malware achieves system-level privileges through DLL sideloading via eScan's trusted executables, then deploys: (1) an enhanced PuTTY Link backdoor for network reconnaissance and SMB lateral movement targeting Windows 7/Server 2008 systems, (2) a modular backdoor that scans for stored private keys and cryptocurrency wallets with registry-based command-and-control, and (3) XMRig Monero miner as possible distraction from the primary espionage objective. GuptiMiner exhibits exceptional operational sophistication: DNS-based C2 communication with attacker-controlled DNS servers, payload extraction from steganographic PNG images, payload signing for integrity verification, code virtualization for anti-analysis, XOR-encrypted payload storage in Windows registry, shellcode injection into legitimate processes, and comprehensive sandbox/analysis tool detection (Wireshark, WinDbg, Process Explorer, etc.). The campaign has been active since at least 2018, discovered by Avast (Gen Digital) researchers Jan Rubín and Jiří Kaňovský in April 2024. eScan acknowledged the vulnerability and implemented HTTPS-based updates, but Avast continued to observe new infections from outdated eScan clients. The attack represents the weaponization of the most trusted software channel — antivirus updates — by a nation-state actor for espionage and financial gain.

- **Published:** 2026-02-02T22:40:00Z
- **Last reviewed:** 2026-02-02T22:40:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0028
- **ID:** TL-2026-0028
- **Severity:** CRITICAL
- **Category:** SUPPLY_CHAIN
- **Status:** MONITORING
- **Actor:** Kimsuky (North Korea)
- **Detections:** 9 · **IOCs:** 51 (full data via the Threadlinqs MCP server — Purple tier)

## Description

The GuptiMiner/eScan supply chain attack is a textbook example of the SECURITY TOOL PARADOX: the software designed to protect systems becomes the vector that compromises them. By hijacking the antivirus update mechanism — the single most trusted software delivery channel on any endpoint — North Korean actors achieved persistent, system-level access to corporate networks while operating under the protective umbrella of the security product itself.

**THE ATTACK CHAIN:**

1. **Adversary-in-the-Middle on Update Channel:** The attackers established an AitM position to intercept eScan's virus definition update traffic. eScan's update mechanism used HTTP (unencrypted) for downloading update packages, allowing the attackers to replace legitimate packages in transit.

2. **Trojanized Update Package:** The malicious package ('updll62.dlz') contained both the legitimate virus definition updates AND GuptiMiner malware as a DLL named 'version.dll'. The legitimate updates still functioned normally — users experienced no disruption.

3. **DLL Sideloading via Trusted Binaries:** eScan's own legitimate, signed executables loaded the malicious 'version.dll' through DLL search order hijacking. Because the parent process was a trusted antivirus binary, the malware inherited system-level privileges AND was effectively invisible to other security tools that whitelist antivirus processes.

4. **Multi-Stage Payload Deployment:** GuptiMiner then deployed multiple payloads:
   - Enhanced PuTTY Link backdoor for network reconnaissance and SMB lateral movement
   - Modular backdoor for cryptocurrency wallet/private key theft
   - XMRig Monero miner (possibly as distraction)

**GUPTIMINER SOPHISTICATION:**

GuptiMiner demonstrates nation-state level operational sophistication:

- **DNS-based C2:** Communicates with attacker-controlled DNS servers for command-and-control, evading network monitoring that focuses on HTTP/HTTPS traffic.
- **Steganographic Payloads:** Extracts additional payloads from PNG images, hiding malicious code within seemingly innocuous image files.
- **Payload Signing:** Signs its own payloads for integrity verification, mimicking legitimate software distribution practices.
- **Code Virtualization:** Uses code virtualization techniques to prevent reverse engineering and static analysis.
- **Registry-based Storage:** Stores XOR-encrypted payloads in the Windows registry, avoiding file-based detection.
- **Process Injection:** Injects shellcode into legitimate processes for execution camouflage.
- **Anti-Analysis:** Checks for 4+ CPU cores and 4GB+ RAM (sandbox detection), and detects Wireshark, WinDbg, TCPView, 360 Total Security, Huorong Internet Security, Process Explorer, Process Monitor, and OllyDbg.
- **Security Tool Deactivation:** Actively disables AhnLab and Cisco Talos products on compromised machines.

**KIMSUKY/APT43 ATTRIBUTION:**

Avast researchers identified similarities between GuptiMiner's information-stealing function and known Kimsuky keyloggers, plus shared infrastructure including the domain mygamesonline[.]org — a domain ordinarily seen in Kimsuky operations. Kimsuky (also tracked as APT43, Velvet Chollima, Emerald Sleet, Thallium) is a North Korean state-sponsored group primarily focused on espionage and cryptocurrency theft to fund the DPRK regime.

**THE ANTIVIRUS UPDATE PARADOX:**

This attack inverts the security model fundamentally:
- Antivirus updates are the MOST trusted software delivery channel
- Organizations specifically ALLOW antivirus to execute with system privileges
- Security tools WHITELIST antivirus processes from monitoring
- Antivirus updates are frequent (multiple times daily) and automated
- Users are TRAINED to keep antivirus updated — the update itself is the attack

Compromising the AV update channel gives attackers: system privileges, persistence, whitelisting by other security tools, and a delivery mechanism that runs automatically on every endpoint.

**ESCAN'S RESPONSE:**

eScan acknowledged the vulnerability and stated the last similar report was in 2019. In 2020, they implemented binary signature verification. In the most recent fix, eScan migrated update downloads to HTTPS. However, Avast continued observing new GuptiMiner infections, indicating outdated eScan clients remain vulnerable.

**CAMPAIGN TIMELINE:**

The campaign has been active since at least 2018, making it a 6+ year persistent operation. The longevity suggests the attackers had reliable AitM capability and the attack went undetected for years due to its inherent trust model exploitation.

## MITRE ATT&CK

- T1195 Supply Chain Compromise
- T1199 Trusted Relationship
- T1059 Command and Scripting Interpreter
- T1053 Scheduled Task/Job
- T1574 Hijack Execution Flow
- T1112 Modify Registry
- T1685 Disable or Modify Tools
- T1027 Obfuscated Files or Information
- T1055 Process Injection
- T1497 Virtualization/Sandbox Evasion
- T1036 Masquerading
- T1553 Subvert Trust Controls
- T1552 Unsecured Credentials
- T1082 System Information Discovery
- T1518 Software Discovery
- T1018 Remote System Discovery
- T1021 Remote Services
- T1570 Lateral Tool Transfer
- T1005 Data from Local System
- T1071 Application Layer Protocol
- T1132 Data Encoding
- T1105 Ingress Tool Transfer
- T1496 Resource Hijacking
- T1657 Financial Theft
- T1106 Native API
- T1547 Boot or Logon Autostart Execution
- T1543 Create or Modify System Process
- T1070 Indicator Removal
- T1140 Deobfuscate/Decode Files or Information
- T1056 Input Capture
- T1057 Process Discovery
- T1016 System Network Configuration Discovery
- T1083 File and Directory Discovery
- T1074 Data Staged
- T1573 Encrypted Channel
- T1095 Non-Application Layer Protocol
- T1090 Proxy
- T1041 Exfiltration Over C2 Channel
- T1048 Exfiltration Over Alternative Protocol

## Sources

- [BleepingComputer — Hackers hijack antivirus updates to drop GuptiMiner malware](https://www.bleepingcomputer.com/news/security/hackers-hijack-antivirus-updates-to-drop-guptiminer-malware/)
- [Avast (Gen Digital) — GuptiMiner: Hijacking Antivirus Updates for Distributing Backdoors and Casual Mining](https://decoded.avast.io/janrubin/guptiminer-hijacking-antivirus-updates-for-distributing-backdoors-and-casual-mining/)
- [Avast IOC Repository — GuptiMiner Indicators of Compromise](https://github.com/avast/ioc/tree/master/GuptiMiner)
- [MITRE ATT&CK — Kimsuky (G0094)](https://attack.mitre.org/groups/G0094/)
- [CISA — North Korean State-Sponsored Cyber Actors Use Cryptocurrency to Fund Operations](https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-108a)
- [Mandiant — APT43: North Korea's Crypto Espionage Group](https://www.mandiant.com/resources/blog/apt43-north-korea-cybercrime-espionage)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0028
