Threat reportSupply ChainTL-2026-0038

eScan Antivirus Supply Chain Attack - Update Server Compromise

criticalPATCHED

eScan Antivirus Supply Chain Attack (TL-2026-0038), also tracked as eScan Supply Chain, is a critical-severity supply-chain compromise scored CVSS 9.1, first published 2026-02-03. It is attributed to Kimsuky (North Korea) with low confidence, affects MicroWorld Technologies eScan Antivirus, maps to 38 MITRE ATT&CK techniques (T1005, T1021, T1027), and is covered by 12 detection rules and 55 indicators of compromise.

CVSS
9.1/10Critical
CVEs
0None referenced
Techniques
38MITRE ATT&CK
Actors
1Kimsuky
Detection rules
12SPL · KQL · Sigma
IOCs
55Indicators of compromise

Key facts for TL-2026-0038

Threat ID
TL-2026-0038
Also known as
eScan Supply Chain, MicroWorld Compromise, Antivirus Malware Delivery
Severity
CRITICAL
CVSS
9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
PATCHED
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution
Kimsuky
Attribution confidence
LOW
Nation-state nexus
North Korea
Motivation
FINANCIAL
Target sectors
Enterprise, Government, Financial Services, Technology, Healthcare, Defense
Target regions
India, South Asia, Southeast Asia, Europe, Global
Detection rules
12
Indicators of compromise
55

Malware and tooling in eScan Antivirus Supply Chain Attack

Malware and tooling: Modified PuTTY Link (plink.exe) backdoor with SMB scanning, Modified PuTTY Link (plink.exe) backdoor with SMB scanning targeting Win7/2008, XMRig Monero cryptominer (final payload #1), XMRig Monero cryptominer deployed as final payload

How eScan Antivirus Supply Chain Attack works

eScan antivirus update mechanism hijacked via HTTP MitM to deliver GuptiMiner: a multi-stage loader distributing cryptominers and backdoors through a trusted security tool's own update channel — the antivirus IS the infection vector.

GuptiMiner exploits a fundamental architectural flaw in eScan antivirus: the update mechanism uses HTTP (not HTTPS) for downloading update packages from update.escanav.com. This enables man-in-the-middle interception to swap legitimate antivirus definition updates with malicious packages containing GuptiMiner's DLL sideloading payload. The attack weaponizes the ENTIRE AV trust chain: (1) eScan's legitimate updater binary (msupdclient.exe) downloads an update package — the package is intercepted and replaced via MitM on the HTTP channel; (2) eScan's own updater unpacks the malicious package containing a crafted version.dll; (3) The DLL is sideloaded by eScan's legitimate signed binary, inheriting the AV process's elevated privileges and trusted status; (4) Because the malware runs INSIDE the AV process, other security tools (EDR, HIPS, additional AV) explicitly exempt it from scanning — the antivirus becomes an invisibility cloak for the malware. The multi-stage infection chain demonstrates exceptional sophistication: initial DLL sideload → shellcode injection into services.exe via Heaven's Gate (32-to-64-bit execution bridge) → scheduled task persistence → DNS-over-HTTPS for C2 resolution using attacker-controlled DNS servers (not standard DNS infrastructure) → PNG image steganography for payload delivery (valid T-Mobile logo images with appended shellcodes) → dual final payload: XMRig Monero cryptominer + custom PuTTY Link-based SMB scanning backdoor for lateral movement targeting Windows 7/Server 2008 systems + second modular backdoor for private key and cryptowallet theft. Attribution indicators point to Kimsuky (North Korea/APT43) based on keylogger code similarities. The campaign operated undetected for 5+ years (2018-2024), with Avast discovering and disclosing to eScan and India CERT in 2023 (confirmed fixed 2023-07-31). The true scope is unknown — as Avast noted, 'users rarely install more than one AV,' meaning limited visibility into GuptiMiner's actual footprint. Distinct from TL-0028 (parent: GuptiMiner malware framework broadly) — THIS threat focuses on the antivirus supply chain weaponization: HTTP update channels, AV process trust exploitation, DLL sideloading via signed binaries, and the security paradox that the tool protecting you IS the tool infecting you.

MITRE ATT&CK techniques used in TL-2026-0038

collection

T1005 Data from Local System; T1056 Input Capture; T1115 Clipboard Data

lateral-movement

T1021 Remote Services

defense-evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1036.005 Match Legitimate Resource Name or Location; T1055 Process Injection; T1070 Indicator Removal; T1218 System Binary Proxy Execution

exfiltration

T1041 Exfiltration Over C2 Channel

discovery

T1046 Network Service Discovery; T1057 Process Discovery; T1082 System Information Discovery

execution

T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter; T1106 Native API; T1129 Shared Modules; T1204.002 Malicious File

command-and-control

T1071 Application Layer Protocol; T1090 Proxy; T1105 Ingress Tool Transfer; T1132 Data Encoding; T1572 Protocol Tunneling; T1573 Encrypted Channel

defense-impairment

T1112 Modify Registry; T1553 Subvert Trust Controls; T1685 Disable or Modify Tools

initial-access

T1195 Supply Chain Compromise; T1195.002 Compromise Software Supply Chain; T1199 Trusted Relationship

impact

T1496 Resource Hijacking; T1657 Financial Theft

credential-access

T1552 Unsecured Credentials; T1555 Credentials from Password Stores

stealth

T1574 Hijack Execution Flow

resource-development

T1583 Acquire Infrastructure; T1588 Obtain Capabilities

Affected products and versions in eScan Antivirus Supply Chain Attack

  • MicroWorld Technologies — eScan Antivirus
    Vulnerable versions: Versions receiving updates during compromise window
    Fixed in: Latest patched version

Remediation for eScan Antivirus Supply Chain Attack

Patches

  • Apply latest eScan updates from verified MicroWorld channels

Immediate actions

  • Isolate systems running eScan antivirus until investigation complete
  • Verify eScan installation integrity against known-good hashes
  • Check for unauthorized processes running under eScan context
  • Review network connections from eScan processes
  • Contact MicroWorld Technologies for incident guidance

Workarounds

  • Temporarily disable automatic updates and apply manually after verification
  • Use network-level blocking of suspicious update domains
  • Run additional EDR alongside eScan for detection redundancy

Longer-term hardening

  • Implement application allowlisting alongside antivirus
  • Monitor security software update channels for anomalies
  • Consider defense-in-depth with multiple AV vendors
  • Implement network segmentation to limit update server access
  • Regular integrity verification of security software installations

Weaknesses (CWE) in eScan Antivirus Supply Chain Attack

CWE-494, CWE-829

Timeline of eScan Antivirus Supply Chain Attack

  • Earliest known GuptiMiner sample compiled (version.dll, c3122448ae). Uploaded to VirusTotal from India next day. Source: Avast/Gen Digital analysis.
  • First VirusTotal upload of GuptiMiner sample from India, followed by Germany upload. Confirms multi-region targeting from inception. Source: Avast research.
  • GuptiMiner evolves mutex naming scheme (MIVOD, SLDV series). Continuous development indicates active, well-resourced campaign. Source: Avast mutex timeline analysis.
  • Malicious DNS server rotation accelerates. Attackers recognize DNS infrastructure is critical single point of failure. Requested domains are decoys — actual resolution via attacker-controlled DNS. Source: Avast domain timeline.
  • GuptiMiner switches to date-based mutex naming (compilation/distribution dates). Indicates mature operational tempo with regular build cycles. Source: Avast analysis.
  • Heaven's Gate technique (32-to-64-bit execution bridge) integrated. Enables shellcode injection into 64-bit services.exe from 32-bit DLL sideload. Source: Avast code analysis.
  • PNG steganography payload delivery introduced. Valid T-Mobile logo images with appended shellcodes. Bypasses content inspection looking for obvious malware. Source: Avast analysis.
  • DNS-over-HTTPS (DoH) for C2 resolution adopted. Attacker-controlled DNS servers (not standard DNS network) resolve true C2 destinations via DNS TXT responses. Evades DNS monitoring. Source: Avast.
  • Avast/Gen Digital discovers GuptiMiner campaign during anomalous update behavior monitoring. Investigation reveals 5+ year operation. Source: Avast blog.
  • eScan confirms vulnerability fixed after Avast disclosure to eScan and India CERT. HTTP update channel replaced with HTTPS. 5+ year window of exploitation closed. Source: Avast disclosure timeline.
  • Avast/Gen Digital publishes full GuptiMiner analysis. Reveals 5+ year AV supply chain attack, Kimsuky attribution indicators, dual payload (XMRig + backdoors). IOCs published on GitHub. Source: decoded.avast.io.
  • BleepingComputer, The Hacker News, SecurityWeek publish coverage. Industry recognizes parallels to SolarWinds supply chain attack. Source: Multiple outlets.
  • First Exploitation
  • Discovered
  • Disclosed
  • As of 2026-05-29, this eScan/GuptiMiner HTTP-update MitM supply-chain threat is not active: eScan fixed the root-cause unencrypted update channel (HTTPS + signed-binary enforcement) on 2023-07-31, and no CVE was ever assigned. A distinct Jan 2026 eScan update-server breach (Reload.exe/CONSCTLX, Morphisec/Kaspersky) was contained within ~1 day with rebuilt servers and dead C2, so no ongoing exploitation remains.

Sources cited for eScan Antivirus Supply Chain Attack

Detection coverage for TL-2026-0038

As of 2026-02-03, Threadlinqs Intelligence publishes 12 detection rule(s) for TL-2026-0038 across Splunk SPL, Microsoft KQL and Sigma, covering 55 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

12 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
55 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats