The eScan Antivirus Update Server Compromise

Updated 5 Oct 2026 · Incident date 20 Jan 2026 · vendor binary

PackageeScan antivirus (MicroWorld) - trojanized reload.exe delivered from a regional update server on 20 January 2026
Filereload.exe

On 20 January 2026 attackers used a regional update server of eScan antivirus, made by MicroWorld Technologies, to send a trojanized reload.exe to customers. eScan installed it as a normal update. The attack was not a software flaw. It was unauthorized access to the update infrastructure.

What happened

Attackers gained access to one eScan regional update server on 20 January 2026 and placed malicious files there. Kaspersky reports that its products detected and stopped the infections the same day. Help Net Security and The Hacker News describe an exposure window of about two hours. Morphisec made the case public on 29 January 2026.

The update replaced C:\Program Files (x86)\escan\reload.exe with a fake-signed, heavily obfuscated file. It ran PowerShell scripts through the .NET runtime. A second malicious file replaced the CONSCTLX.exe component.

Kaspersky describes three stages. First, the malware tampered with eScan itself. It deleted antivirus files, added exclusions for C:\Windows and both Program Files folders, and pointed the update server name update1.mwti.net to 2.3.4.0 in the hosts file so the product could not update. Second, it patched AmsiScanBuffer to blind the Windows scanning interface. Third, it checked the host against a block list of security tools, and Kaspersky reports it skipped systems with Kaspersky products.

Persistence used a scheduled task named Microsoft\Windows\Defrag\CorelDefrag and a PowerShell payload stored in the registry. Kaspersky reports hundreds of machines in India, Bangladesh, Sri Lanka and the Philippines.

MicroWorld isolated the affected infrastructure within one hour and took the global update system offline for more than eight hours, according to Help Net Security. It issued an advisory on 22 January 2026 and a removal utility.

The change was one trusted binary replaced by another with new behaviour. Vigilance flags that kind of change when it compares an installed version with the new one.

Affected versions

The sources do not give a version number. They name the product and the date.

Indicators of compromise

These come from Kaspersky. Defang domains before you share them.

How to check

You can check the file hash, the scheduled task and the hosts file on a Windows machine with eScan.

Get-FileHash -Algorithm SHA1 "C:\Program Files (x86)\escan\reload.exe"
Get-ScheduledTask -TaskName CorelDefrag
Select-String -Path C:\Windows\System32\drivers\etc\hosts -Pattern "mwti.net"

Compare the hash to the list above. Also check whether the machine took an eScan update on 20 January 2026.

What to do now

  1. If a machine took the update on 20 January 2026, isolate it from the network.
  2. Ask MicroWorld support for the removal utility. eScan says it removes the malware and rolls back the changes.
  3. Remove the scheduled task, registry key and hosts file entry if the utility does not.
  4. Block the command domains at the network edge.
  5. Ask MicroWorld for a manual patch if the product can no longer update.
  6. Treat credentials used on the machine as exposed.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old eScan-prev --new eScan-current
files scanned: 11

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    reload.exe
           It now runs a command on its own when it is installed, downloads from the internet and restarts itself after a reboot. It did not before.

Frequently asked questions

What happened in the eScan antivirus supply chain attack?

On 20 January 2026 attackers used a compromised eScan regional update server to send a trojanized reload.exe to customers, which downloaded more malware.

Which eScan versions were affected?

The sources give no version number. Machines that took an update from the compromised regional server on 20 January 2026 were affected.

How do I check if eScan was compromised?

Hash C:\Program Files (x86)\escan\reload.exe and compare it to the published hashes. Also look for the CorelDefrag scheduled task and a hosts entry for update1.mwti.net.

Sources

  1. securelist.com/escan-supply-chain-attack/118688/
  2. helpnetsecurity.com/2026/01/29/escan-antivirus-update-supply-chain-compromised/
  3. thehackernews.com/2026/02/escan-antivirus-update-servers.html

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free