Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Oppo: New dual 200 MP flagship smartphone eyed in spy shots with iPhone 17 Pro Max

    Steam: City builder with 95% positive reviews hits all-time low of $6.70

    Xiaomi releases new projector accessory in Europe

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      To avoid accusations of AI cheating, college students are turning to AI

      January 29, 2026

      ChatGPT can embrace authoritarian ideas after just one prompt, researchers say

      January 24, 2026

      Ashley St. Clair, the mother of one of Elon Musk’s children, sues xAI over Grok sexual images

      January 17, 2026

      Anthropic joins OpenAI’s push into health care with new Claude tools

      January 12, 2026

      The mother of one of Elon Musk’s children says his AI bot won’t stop creating sexualized images of her

      January 7, 2026
    • Business

      New VoidLink malware framework targets Linux cloud servers

      January 14, 2026

      Nvidia Rubin’s rack-scale encryption signals a turning point for enterprise AI security

      January 13, 2026

      How KPMG is redefining the future of SAP consulting on a global scale

      January 10, 2026

      Top 10 cloud computing stories of 2025

      December 22, 2025

      Saudia Arabia’s STC commits to five-year network upgrade programme with Ericsson

      December 18, 2025
    • Crypto

      Murad’s Portfolio Value Drops Over 80% as SPX Hits a New Low

      January 29, 2026

      Gamma Prime Brings the Tokenized Capital Summit to Hong Kong on Feb 9, Highlighting Its Tokenized Global Marketplace for Private Investments

      January 29, 2026

      Whale Secure Over $30 Million in Tether Gold As Spot Price Blasts Past Goldman Sachs’ Target

      January 29, 2026

      Bitcoin Price Prediction: What To Expect From BTC In February 2026?

      January 29, 2026

      US Job Losses Stoke Recession Fears: What It Could Mean for Crypto

      January 29, 2026
    • Technology

      Oppo: New dual 200 MP flagship smartphone eyed in spy shots with iPhone 17 Pro Max

      January 29, 2026

      Steam: City builder with 95% positive reviews hits all-time low of $6.70

      January 29, 2026

      Xiaomi releases new projector accessory in Europe

      January 29, 2026

      Huawei Nova 14i goes official in Hong Kong with 7,000 mAh battery and 90 Hz display

      January 29, 2026

      Thomas Edison as a nanotech pioneer: The inventor likely produced graphene as early as 1879

      January 29, 2026
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»eScan confirms update server breached to push malicious update
    Technology

    eScan confirms update server breached to push malicious update

    TechAiVerseBy TechAiVerseJanuary 29, 2026No Comments4 Mins Read2 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    eScan confirms update server breached to push malicious update
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    eScan confirms update server breached to push malicious update

    MicroWorld Technologies, the maker of the eScan antivirus product, has confirmed that one of its update servers was breached and used to distribute an unauthorized update later analyzed as malicious to a small subset of customers earlier this month.

    The file was delivered to customers who downloaded updates from the regional update cluster during a two-hour window on January 20, 2026.

    eScan says the affected infrastructure has since been isolated and rebuilt, authentication credentials have been rotated, and remediation has been made available to impacted customers.

    Security firm Morphisec separately published a technical report analyzing malicious activity observed on customer endpoints, which it associates with updates delivered from eScan’s update infrastructure during the same timeframe.

    Morphisec states that it detected malicious activity on January 20, 2026, and later contacted eScan. MicroWorld Technologies told BleepingComputer it disputes Morphisec’s claims that it was the first to discover or report the incident.

    According to eScan, the company detected the issue internally on January 20 through monitoring and customer reports, isolated the affected infrastructure within hours, and issued a security advisory on January 21. eScan says Morphisec contacted the company later, after publishing public claims about the incident.

    eScan also disputes claims that affected customers were unaware of the issue, stating that it conducted proactive notifications and direct outreach to impacted customers while remediation was being finalized.

    Update infrastructure breached

    In its advisory, eScan classified the incident as an update infrastructure access incident, stating that unauthorized access to a regional update server configuration allowed an unauthorized file to be placed in the update distribution path.

    “Unauthorized access to one of our regional update server configurations resulted in an incorrect file (patch configuration binary/corrupt update) being placed in the update distribution path,” reads an advisory shared with BleepingComputer by MicroWorld Technologies.

    “This file was distributed to customers downloading updates from the affected server cluster during a limited timeframe on January 20, 2026.”

    The company emphasized that the incident did not involve a vulnerability in the eScan product itself.

    eScan stressed that only those whose software was updated from the specific regional cluster were impacted, while all other customers remained unaffected.

    However, eScan says that those who installed the malicious update may have seen this behavior on their systems:

    • Update service failure notifications
    • Modified system hosts file preventing connection to eScan update servers
    • eScan update configuration file modifications
    • Inability to receive new security definition updates
    • Update unavailability popup on client machines

    BleepingComputer contacted eScan with further questions on when its systems were initially breached and will update the story if we receive a reply back.

    Update deployed to push malware

    Morphisec’s security bulletin says that the malicious update pushed down a modified version of an eScan update component, “Reload.exe”.

    “Malicious updates were distributed through eScan’s legitimate update infrastructure, resulting in the deployment of multi-stage malware to enterprise and consumer endpoints globally,” reads Morphisec’s bulletin.

    While the modified Reload.exe is signed with what appears to be eScan’s code-signing certificate, both Windows and VirusTotal show the signature as invalid.

    According to Morphisec, the Reload.exe file [VirusTotal] was used to enable persistence, execute commands, modify the Windows HOSTS file to prevent remote updates, and connect to the C2 infrastructure to download further payloads.

    The researchers say the following command and control servers were observed:

    hxxps[://]vhs[.]delrosal[.]net/i
    hxxps[://]tumama[.]hns[.]to
    hxxps[://]blackice[.]sol-domain[.]org
    hxxps[://]codegiant[.]io/dd/dd/dd[.]git/download/main/middleware[.]ts
    504e1a42.host.njalla[.]net
    185.241.208[.]115
    

    The final payload seen deployed was a file named CONSCTLX.exe [VirusTotal], which Morphisec acts as a backdoor and a persistent downloader. Morphisec says that the malicious files created scheduled tasks for persistence using names like “CorelDefrag”.

    eScan has created a remediation update that customers can run to perform the following actions:

    • Automatically identifies and corrects incorrect modifications
    • Re-enables proper eScan update functionality
    • Verifies successful restoration
    • Requires standard system restart

    Both eScan and Morphisec recommend that customers block the above command and control servers for additional security.

    In 2024, North Korean hackers were observed exploiting the updating mechanism of eScan antivirus to plant backdoors on corporate networks.

    Secrets Security Cheat Sheet: From Sprawl to Control

    Whether you’re cleaning up old keys or setting guardrails for AI-generated code, this guide helps your team build securely from the start.

    Get the cheat sheet and take the guesswork out of secrets management.

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleViral Moltbot AI assistant raises concerns over data security
    Next Article Rules fail at the prompt, succeed at the boundary
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    Oppo: New dual 200 MP flagship smartphone eyed in spy shots with iPhone 17 Pro Max

    January 29, 2026

    Steam: City builder with 95% positive reviews hits all-time low of $6.70

    January 29, 2026

    Xiaomi releases new projector accessory in Europe

    January 29, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025643 Views

    Lumo vs. Duck AI: Which AI is Better for Your Privacy?

    July 31, 2025241 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 2025143 Views

    6 Best MagSafe Phone Grips (2025), Tested and Reviewed

    April 6, 2025111 Views
    Don't Miss
    Technology January 29, 2026

    Oppo: New dual 200 MP flagship smartphone eyed in spy shots with iPhone 17 Pro Max

    Oppo: New dual 200 MP flagship smartphone eyed in spy shots with iPhone 17 Pro…

    Steam: City builder with 95% positive reviews hits all-time low of $6.70

    Xiaomi releases new projector accessory in Europe

    Huawei Nova 14i goes official in Hong Kong with 7,000 mAh battery and 90 Hz display

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    Oppo: New dual 200 MP flagship smartphone eyed in spy shots with iPhone 17 Pro Max

    January 29, 20261 Views

    Steam: City builder with 95% positive reviews hits all-time low of $6.70

    January 29, 20262 Views

    Xiaomi releases new projector accessory in Europe

    January 29, 20262 Views
    Most Popular

    A Team of Female Founders Is Launching Cloud Security Tech That Could Overhaul AI Protection

    March 12, 20250 Views

    7 Best Kids Bikes (2025): Mountain, Balance, Pedal, Coaster

    March 13, 20250 Views

    VTOMAN FlashSpeed 1500: Plenty Of Power For All Your Gear

    March 13, 20250 Views
    © 2026 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.