Threat reportSupply ChainTL-2026-0038
eScan Antivirus Supply Chain Attack - Update Server Compromise
eScan Antivirus Supply Chain Attack (TL-2026-0038), also tracked as eScan Supply Chain, is a critical-severity supply-chain compromise scored CVSS 9.1, first published 2026-02-03. It is attributed to Kimsuky (North Korea) with low confidence, affects MicroWorld Technologies eScan Antivirus, maps to 38 MITRE ATT&CK techniques (T1005, T1021, T1027), and is covered by 12 detection rules and 55 indicators of compromise.
- CVSS
- 9.1/10Critical
- CVEs
- 0None referenced
- Techniques
- 38MITRE ATT&CK
- Actors
- 1Kimsuky
- Detection rules
- 12SPL · KQL · Sigma
- IOCs
- 55Indicators of compromise
Key facts for TL-2026-0038
- Threat ID
- TL-2026-0038
- Also known as
- eScan Supply Chain, MicroWorld Compromise, Antivirus Malware Delivery
- Severity
- CRITICAL
- CVSS
- 9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution
- Kimsuky
- Attribution confidence
- LOW
- Nation-state nexus
- North Korea
- Motivation
- FINANCIAL
- Target sectors
- Enterprise, Government, Financial Services, Technology, Healthcare, Defense
- Target regions
- India, South Asia, Southeast Asia, Europe, Global
- Detection rules
- 12
- Indicators of compromise
- 55
Malware and tooling in eScan Antivirus Supply Chain Attack
Malware and tooling: Modified PuTTY Link (plink.exe) backdoor with SMB scanning, Modified PuTTY Link (plink.exe) backdoor with SMB scanning targeting Win7/2008, XMRig Monero cryptominer (final payload #1), XMRig Monero cryptominer deployed as final payload
How eScan Antivirus Supply Chain Attack works
eScan antivirus update mechanism hijacked via HTTP MitM to deliver GuptiMiner: a multi-stage loader distributing cryptominers and backdoors through a trusted security tool's own update channel — the antivirus IS the infection vector.
GuptiMiner exploits a fundamental architectural flaw in eScan antivirus: the update mechanism uses HTTP (not HTTPS) for downloading update packages from update.escanav.com. This enables man-in-the-middle interception to swap legitimate antivirus definition updates with malicious packages containing GuptiMiner's DLL sideloading payload. The attack weaponizes the ENTIRE AV trust chain: (1) eScan's legitimate updater binary (msupdclient.exe) downloads an update package — the package is intercepted and replaced via MitM on the HTTP channel; (2) eScan's own updater unpacks the malicious package containing a crafted version.dll; (3) The DLL is sideloaded by eScan's legitimate signed binary, inheriting the AV process's elevated privileges and trusted status; (4) Because the malware runs INSIDE the AV process, other security tools (EDR, HIPS, additional AV) explicitly exempt it from scanning — the antivirus becomes an invisibility cloak for the malware. The multi-stage infection chain demonstrates exceptional sophistication: initial DLL sideload → shellcode injection into services.exe via Heaven's Gate (32-to-64-bit execution bridge) → scheduled task persistence → DNS-over-HTTPS for C2 resolution using attacker-controlled DNS servers (not standard DNS infrastructure) → PNG image steganography for payload delivery (valid T-Mobile logo images with appended shellcodes) → dual final payload: XMRig Monero cryptominer + custom PuTTY Link-based SMB scanning backdoor for lateral movement targeting Windows 7/Server 2008 systems + second modular backdoor for private key and cryptowallet theft. Attribution indicators point to Kimsuky (North Korea/APT43) based on keylogger code similarities. The campaign operated undetected for 5+ years (2018-2024), with Avast discovering and disclosing to eScan and India CERT in 2023 (confirmed fixed 2023-07-31). The true scope is unknown — as Avast noted, 'users rarely install more than one AV,' meaning limited visibility into GuptiMiner's actual footprint. Distinct from TL-0028 (parent: GuptiMiner malware framework broadly) — THIS threat focuses on the antivirus supply chain weaponization: HTTP update channels, AV process trust exploitation, DLL sideloading via signed binaries, and the security paradox that the tool protecting you IS the tool infecting you.
MITRE ATT&CK techniques used in TL-2026-0038
collection
T1005 Data from Local System; T1056 Input Capture; T1115 Clipboard Data
lateral-movement
defense-evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1036.005 Match Legitimate Resource Name or Location; T1055 Process Injection; T1070 Indicator Removal; T1218 System Binary Proxy Execution
exfiltration
T1041 Exfiltration Over C2 Channel
discovery
T1046 Network Service Discovery; T1057 Process Discovery; T1082 System Information Discovery
execution
T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter; T1106 Native API; T1129 Shared Modules; T1204.002 Malicious File
command-and-control
T1071 Application Layer Protocol; T1090 Proxy; T1105 Ingress Tool Transfer; T1132 Data Encoding; T1572 Protocol Tunneling; T1573 Encrypted Channel
defense-impairment
T1112 Modify Registry; T1553 Subvert Trust Controls; T1685 Disable or Modify Tools
initial-access
T1195 Supply Chain Compromise; T1195.002 Compromise Software Supply Chain; T1199 Trusted Relationship
impact
T1496 Resource Hijacking; T1657 Financial Theft
credential-access
T1552 Unsecured Credentials; T1555 Credentials from Password Stores
stealth
resource-development
Affected products and versions in eScan Antivirus Supply Chain Attack
- MicroWorld Technologies — eScan Antivirus
Vulnerable versions: Versions receiving updates during compromise window
Fixed in: Latest patched version
Remediation for eScan Antivirus Supply Chain Attack
Patches
- Apply latest eScan updates from verified MicroWorld channels
Immediate actions
- Isolate systems running eScan antivirus until investigation complete
- Verify eScan installation integrity against known-good hashes
- Check for unauthorized processes running under eScan context
- Review network connections from eScan processes
- Contact MicroWorld Technologies for incident guidance
Workarounds
- Temporarily disable automatic updates and apply manually after verification
- Use network-level blocking of suspicious update domains
- Run additional EDR alongside eScan for detection redundancy
Longer-term hardening
- Implement application allowlisting alongside antivirus
- Monitor security software update channels for anomalies
- Consider defense-in-depth with multiple AV vendors
- Implement network segmentation to limit update server access
- Regular integrity verification of security software installations
Weaknesses (CWE) in eScan Antivirus Supply Chain Attack
Timeline of eScan Antivirus Supply Chain Attack
- Earliest known GuptiMiner sample compiled (version.dll, c3122448ae). Uploaded to VirusTotal from India next day. Source: Avast/Gen Digital analysis.
- First VirusTotal upload of GuptiMiner sample from India, followed by Germany upload. Confirms multi-region targeting from inception. Source: Avast research.
- GuptiMiner evolves mutex naming scheme (MIVOD, SLDV series). Continuous development indicates active, well-resourced campaign. Source: Avast mutex timeline analysis.
- Malicious DNS server rotation accelerates. Attackers recognize DNS infrastructure is critical single point of failure. Requested domains are decoys — actual resolution via attacker-controlled DNS. Source: Avast domain timeline.
- GuptiMiner switches to date-based mutex naming (compilation/distribution dates). Indicates mature operational tempo with regular build cycles. Source: Avast analysis.
- Heaven's Gate technique (32-to-64-bit execution bridge) integrated. Enables shellcode injection into 64-bit services.exe from 32-bit DLL sideload. Source: Avast code analysis.
- PNG steganography payload delivery introduced. Valid T-Mobile logo images with appended shellcodes. Bypasses content inspection looking for obvious malware. Source: Avast analysis.
- DNS-over-HTTPS (DoH) for C2 resolution adopted. Attacker-controlled DNS servers (not standard DNS network) resolve true C2 destinations via DNS TXT responses. Evades DNS monitoring. Source: Avast.
- Avast/Gen Digital discovers GuptiMiner campaign during anomalous update behavior monitoring. Investigation reveals 5+ year operation. Source: Avast blog.
- eScan confirms vulnerability fixed after Avast disclosure to eScan and India CERT. HTTP update channel replaced with HTTPS. 5+ year window of exploitation closed. Source: Avast disclosure timeline.
- Avast/Gen Digital publishes full GuptiMiner analysis. Reveals 5+ year AV supply chain attack, Kimsuky attribution indicators, dual payload (XMRig + backdoors). IOCs published on GitHub. Source: decoded.avast.io.
- BleepingComputer, The Hacker News, SecurityWeek publish coverage. Industry recognizes parallels to SolarWinds supply chain attack. Source: Multiple outlets.
- First Exploitation
- Discovered
- Disclosed
- As of 2026-05-29, this eScan/GuptiMiner HTTP-update MitM supply-chain threat is not active: eScan fixed the root-cause unencrypted update channel (HTTPS + signed-binary enforcement) on 2023-07-31, and no CVE was ever assigned. A distinct Jan 2026 eScan update-server breach (Reload.exe/CONSCTLX, Morphisec/Kaspersky) was contained within ~1 day with rebuilt servers and dead C2, so no ongoing exploitation remains.
Sources cited for eScan Antivirus Supply Chain Attack
- SecurityWeek: eScan Antivirus Delivers Malware in Supply Chain Attack
- GuptiMiner: Hijacking Antivirus Updates — Avast/Gen Digital
- Avast GuptiMiner IOC Repository — GitHub
- eScan AV Update Mechanism Exploited — The Hacker News
- Hackers Hijack AV Updates to Drop GuptiMiner — BleepingComputer
- CISA: Russian Military Cyber Actors Target Global Infrastructure
- Mandiant: APT43 North Korea Cybercrime-Espionage
- MITRE ATT&CK: Supply Chain Compromise T1195.002
- MITRE ATT&CK: Kimsuky Group G0094
- MITRE ATT&CK: DLL Side-Loading T1574.002
- MITRE ATT&CK: Steganography T1027.003
- SolarWinds SUNBURST — Supply Chain Parallel
- OWASP: Software Update Security Cheat Sheet
- NIST Cyber Supply Chain Risk Management
- Heaven's Gate Technique Analysis
Detection coverage for TL-2026-0038
As of 2026-02-03, Threadlinqs Intelligence publishes 12 detection rule(s) for TL-2026-0038 across Splunk SPL, Microsoft KQL and Sigma, covering 55 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.