MicroWorld Technologies’ eScan antivirus update infrastructure was compromised to distribute malicious, trojanized updates that deployed multi-stage malware to endpoints globally. Reporting indicates the initial payload replaced a legitimate 32-bit eScan component (Reload.exe) and initiated a chain that dropped additional stages, including a downloader and a 64-bit backdoor (CONSCTLX.exe) enabling broad remote compromise; Morphisec reported detecting and blocking the activity on customer endpoints and provided file-hash IOCs for hunting.
The malware attempted to prevent recovery and conceal activity by tampering with the Windows hosts file and eScan registry/update configuration to block remote updates, meaning automatic remediation may not work on affected systems and organizations may need to contact eScan/MicroWorld for manual remediation. Additional TTPs described include persistence via scheduled tasks (including Windows defragmentation job-spoofing under WindowsDefrag) and registry-based persistence; recommended response actions include hunting for known malicious hashes, reviewing suspicious scheduled tasks and registry keys, blocking identified C2 infrastructure, and revoking trust in the compromised eScan code-signing certificate if applicable in enterprise controls.

Trace attribution and downstream blast radius.
7 events from the most recent confirmed update back to the earliest known activity.
By 2026-01-29, Kaspersky published additional analysis showing the malware used a falsely signed Reload.exe, AMSI-bypassing PowerShell, scheduled-task persistence, and follow-on payloads including CONSCTLX.exe. Its telemetry indicated hundreds of infection attempts, primarily in India, Bangladesh, Sri Lanka, and the Philippines.
On 2026-01-28, eScan confirmed that one regional update server had been breached and used to distribute an unauthorized malicious file to a limited subset of customers. The company disputed Morphisec's characterization and timeline, saying the issue was unauthorized access to update infrastructure rather than a product vulnerability.
By 2026-01-28, Morphisec publicly released a threat bulletin describing the supply-chain compromise, malware stages, persistence, HOSTS-file and registry tampering, and C2 infrastructure. The advisory included hashes, certificate details, and guidance to assume compromise on unprotected systems and obtain a manual patch from eScan.
On 2026-01-21, eScan said it published a preliminary advisory and released a remediation patch/update to restore proper updater functionality on affected systems. A narrower customer advisory followed on 2026-01-22.
Morphisec said it identified the malicious eScan update on 2026-01-20 and blocked related activity on its customers' systems. The firm contacted eScan on 2026-01-21 to report the compromise and share findings.
Also on 2026-01-20, MicroWorld Technologies said it detected the incident internally, isolated the affected infrastructure within about an hour, and took the global update system offline for more than eight hours. The company later rebuilt affected systems and rotated credentials.
On 2026-01-20, attackers used unauthorized access to an eScan regional update server to push a malicious update during an approximately two-hour window. The trojanized package replaced Reload.exe and began a multi-stage infection chain on affected endpoints.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 21 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
11 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcerescana.com
Open sourcesecurityonline.info
Open sourcego.theregister.com
Open sourcemorphisec.com
Open sourcebleepingcomputer.com
Open sourcemorphisec.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.