← Back to Pulse Feed
PULSE DETAIL
A supply chain attack targeted the eScan antivirus software, distributing malware through the update server. The attack, detected on January 20, involved a malicious Reload.exe file that initiated a multi-stage infection chain. This malware prevented further antivirus updates, ensured persistence through scheduled tasks, and communicated with control servers to download additional payloads. Attackers gained unauthorized access to a regional update server, deploying a malicious file with a fake digital signature. eScan developers quickly isolated the affected infrastructure and reset access credentials. Users are advised to check for infection signs, use a provided removal utility, and block known malware control server addresses. Kaspersky's security solutions successfully detect the malware used in this attack.
MITRE ATT&CK & Malware Families
Indicators of Compromise (15)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| URL | https://blackice.sol-domain.org | — | 2026-01-29 | |
| URL | https://codegiant.io/dd/dd/dd.git/download/main/middleware.ts | — | 2026-01-29 | |
| URL | https://csc.biologii.net/sooc | — | 2026-01-29 | |
| URL | https://vhs.delrosal.net/i | — | 2026-01-29 | |
| hostname | blackice.sol-domain.org | — | 2026-01-29 | |
| hostname | csc.biologii.net | — | 2026-01-29 | |
| hostname | vhs.delrosal.net | — | 2026-01-29 | |
| FileHash-SHA1 | 1617949c0c9daa2d2a5a80f1028aeb95ce1c0dee | — | 2026-02-02 | |
| FileHash-SHA1 | a928bddfaa536c11c28c8d2c5d16e27cbeaf6357 | — | 2026-02-02 | |
| FileHash-SHA1 | ebaf9715d7f34a77a6e1fd455fe0702274958e20 | — | 2026-02-02 | |
| FileHash-SHA1 | 96cdd8476faa7c6a7d2ad285658d3559855b168d | — | 2026-02-02 | |
| FileHash-SHA1 | 2d2d58700a40642e189f3f1ccea41337486947f5 | — | 2026-02-02 | |
| FileHash-SHA256 | 36ef2ec9ada035c56644f677dab65946798575e1d8b14f1365f22d7c68269860 | — | 2026-02-02 | |
| FileHash-SHA256 | 674943387cc7e0fd18d0d6278e6e4f7a0f3059ee6ef94e0976fae6954ffd40dd | — | 2026-02-02 | |
| FileHash-SHA256 | 386a16926aff225abc31f73e8e040ac0c53fb093e7daf3fbd6903c157d88958c | — | 2026-02-02 |
References (1)