# eScan Antivirus Supply Chain Attack - Update Server Compromise

> eScan antivirus update mechanism hijacked via HTTP MitM to deliver GuptiMiner: a multi-stage loader distributing cryptominers and backdoors through a trusted security tool's own update channel — the antivirus IS the infection vector.

- **Published:** 2026-02-03T01:40:00Z
- **Last reviewed:** 2026-02-03T01:40:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0038
- **ID:** TL-2026-0038
- **Severity:** CRITICAL (CVSS 9.1)
- **Category:** SUPPLY_CHAIN
- **Status:** PATCHED
- **Actor:** Kimsuky (North Korea)
- **Detections:** 12 · **IOCs:** 55 (full data via the Threadlinqs MCP server — Purple tier)

## Description

GuptiMiner exploits a fundamental architectural flaw in eScan antivirus: the update mechanism uses HTTP (not HTTPS) for downloading update packages from update.escanav.com. This enables man-in-the-middle interception to swap legitimate antivirus definition updates with malicious packages containing GuptiMiner's DLL sideloading payload. The attack weaponizes the ENTIRE AV trust chain: (1) eScan's legitimate updater binary (msupdclient.exe) downloads an update package — the package is intercepted and replaced via MitM on the HTTP channel; (2) eScan's own updater unpacks the malicious package containing a crafted version.dll; (3) The DLL is sideloaded by eScan's legitimate signed binary, inheriting the AV process's elevated privileges and trusted status; (4) Because the malware runs INSIDE the AV process, other security tools (EDR, HIPS, additional AV) explicitly exempt it from scanning — the antivirus becomes an invisibility cloak for the malware. The multi-stage infection chain demonstrates exceptional sophistication: initial DLL sideload → shellcode injection into services.exe via Heaven's Gate (32-to-64-bit execution bridge) → scheduled task persistence → DNS-over-HTTPS for C2 resolution using attacker-controlled DNS servers (not standard DNS infrastructure) → PNG image steganography for payload delivery (valid T-Mobile logo images with appended shellcodes) → dual final payload: XMRig Monero cryptominer + custom PuTTY Link-based SMB scanning backdoor for lateral movement targeting Windows 7/Server 2008 systems + second modular backdoor for private key and cryptowallet theft. Attribution indicators point to Kimsuky (North Korea/APT43) based on keylogger code similarities. The campaign operated undetected for 5+ years (2018-2024), with Avast discovering and disclosing to eScan and India CERT in 2023 (confirmed fixed 2023-07-31). The true scope is unknown — as Avast noted, 'users rarely install more than one AV,' meaning limited visibility into GuptiMiner's actual footprint. Distinct from TL-0028 (parent: GuptiMiner malware framework broadly) — THIS threat focuses on the antivirus supply chain weaponization: HTTP update channels, AV process trust exploitation, DLL sideloading via signed binaries, and the security paradox that the tool protecting you IS the tool infecting you.

## MITRE ATT&CK

- T1195.002 Compromise Software Supply Chain
- T1204.002 Malicious File
- T1036.005 Match Legitimate Resource Name or Location
- T1574 Hijack Execution Flow
- T1195 Supply Chain Compromise
- T1106 Native API
- T1129 Shared Modules
- T1053 Scheduled Task/Job
- T1553 Subvert Trust Controls
- T1055 Process Injection
- T1027 Obfuscated Files or Information
- T1036 Masquerading
- T1070 Indicator Removal
- T1552 Unsecured Credentials
- T1056 Input Capture
- T1046 Network Service Discovery
- T1057 Process Discovery
- T1082 System Information Discovery
- T1021 Remote Services
- T1005 Data from Local System
- T1071 Application Layer Protocol
- T1573 Encrypted Channel
- T1572 Protocol Tunneling
- T1105 Ingress Tool Transfer
- T1496 Resource Hijacking
- T1199 Trusted Relationship
- T1059 Command and Scripting Interpreter
- T1685 Disable or Modify Tools
- T1218 System Binary Proxy Execution
- T1112 Modify Registry
- T1555 Credentials from Password Stores
- T1115 Clipboard Data
- T1132 Data Encoding
- T1090 Proxy
- T1041 Exfiltration Over C2 Channel
- T1657 Financial Theft
- T1583 Acquire Infrastructure
- T1588 Obtain Capabilities

## Sources

- [SecurityWeek: eScan Antivirus Delivers Malware in Supply Chain Attack](https://www.securityweek.com/escan-antivirus-delivers-malware-in-supply-chain-attack/)
- [GuptiMiner: Hijacking Antivirus Updates — Avast/Gen Digital](https://decoded.avast.io/janvojtesek/guptiminer-hijacking-antivirus-updates-for-distributing-backdoors-and-casual-mining/)
- [Avast GuptiMiner IOC Repository — GitHub](https://github.com/avast/ioc/tree/master/GuptiMiner)
- [eScan AV Update Mechanism Exploited — The Hacker News](https://thehackernews.com/2024/04/escan-antivirus-update-mechanism.html)
- [Hackers Hijack AV Updates to Drop GuptiMiner — BleepingComputer](https://www.bleepingcomputer.com/news/security/hackers-hijack-antivirus-updates-to-drop-guptiminer-malware/)
- [CISA: Russian Military Cyber Actors Target Global Infrastructure](https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-249a)
- [Mandiant: APT43 North Korea Cybercrime-Espionage](https://cloud.google.com/blog/topics/threat-intelligence/apt43-north-korea-cybercrime-espionage)
- [MITRE ATT&CK: Supply Chain Compromise T1195.002](https://attack.mitre.org/techniques/T1195/002/)
- [MITRE ATT&CK: Kimsuky Group G0094](https://attack.mitre.org/groups/G0094/)
- [MITRE ATT&CK: DLL Side-Loading T1574.002](https://attack.mitre.org/techniques/T1574/002/)
- [MITRE ATT&CK: Steganography T1027.003](https://attack.mitre.org/techniques/T1027/003/)
- [SolarWinds SUNBURST — Supply Chain Parallel](https://www.mandiant.com/resources/blog/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor)
- [OWASP: Software Update Security Cheat Sheet](https://cheatsheetseries.owasp.org/cheatsheets/Software_Update_Security_Cheat_Sheet.html)
- [NIST Cyber Supply Chain Risk Management](https://csrc.nist.gov/Projects/cyber-supply-chain-risk-management)
- [Heaven's Gate Technique Analysis](https://attack.mitre.org/techniques/T1055/012/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0038
