PULSE NAME
Supply chain attack: what you should know
WHITE AlienVault 2026-01-29 Modified: 2026-02-02
15
IOCs
MEDIUM VOLUME
A supply chain attack targeted the eScan antivirus software, distributing malware through the update server. The attack, detected on January 20, involved a malicious Reload.exe file that initiated a multi-stage infection chain. This malware prevented further antivirus updates, ensured persistence through scheduled tasks, and communicated with control servers to download additional payloads. Attackers gained unauthorized access to a regional update server, deploying a malicious file with a fake digital signature. eScan developers quickly isolated the affected infrastructure and reset access credentials. Users are advised to check for infection signs, use a provided removal utility, and block known malware control server addresses. Kaspersky's security solutions successfully detect the malware used in this attack.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Reload.exe consctlx.exe
Indicators of Compromise (15)
All URL hostname FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
URL https://blackice.sol-domain.org 2026-01-29
URL https://codegiant.io/dd/dd/dd.git/download/main/middleware.ts 2026-01-29
URL https://csc.biologii.net/sooc 2026-01-29
URL https://vhs.delrosal.net/i 2026-01-29
hostname blackice.sol-domain.org 2026-01-29
hostname csc.biologii.net 2026-01-29
hostname vhs.delrosal.net 2026-01-29
FileHash-SHA1 1617949c0c9daa2d2a5a80f1028aeb95ce1c0dee 2026-02-02
FileHash-SHA1 a928bddfaa536c11c28c8d2c5d16e27cbeaf6357 2026-02-02
FileHash-SHA1 ebaf9715d7f34a77a6e1fd455fe0702274958e20 2026-02-02
FileHash-SHA1 96cdd8476faa7c6a7d2ad285658d3559855b168d 2026-02-02
FileHash-SHA1 2d2d58700a40642e189f3f1ccea41337486947f5 2026-02-02
FileHash-SHA256 36ef2ec9ada035c56644f677dab65946798575e1d8b14f1365f22d7c68269860 2026-02-02
FileHash-SHA256 674943387cc7e0fd18d0d6278e6e4f7a0f3059ee6ef94e0976fae6954ffd40dd 2026-02-02
FileHash-SHA256 386a16926aff225abc31f73e8e040ac0c53fb093e7daf3fbd6903c157d88958c 2026-02-02