The GuptiMiner eScan Update Hijack
Updated 5 Oct 2026 · Incident date 19 Apr 2018 · vendor binary
eScan antivirus virus-definition update package updll62.dlz, delivered over plain HTTP and injected in transit; fixed 31 July 2023version.dll injected into the updll62.dlz definition pa...Attackers intercepted eScan antivirus update downloads sent over plain HTTP and replaced the package with one that held a malicious version.dll. Avast researchers named the campaign GuptiMiner.
The first sample dates from 19 April 2018. eScan confirmed a fix on 31 July 2023.
What happened
Attackers used a man-in-the-middle position to swap a genuine eScan update for a malicious one. Avast reports that the eScan client fetched updates from http://update3.mwti.net/pub/update/updll3.dlz over unencrypted HTTP. The attacker replaced the genuine package on the wire. The vendor did not publish the bad file. Most users received clean updates. BleepingComputer and The Hacker News name the trojanized package updll62.dlz, while Avast's write-up names the update path updll3.dlz. BleepingComputer adds that the malware avoids sandboxes by checking for at least 4 CPU cores and 4 GB of RAM.
The bad package carried a DLL, usually version.dll, placed in C:\Program Files\eScan\ so that eScan would load it. The DLL then ran more code. Avast lists these payloads.
- An XMRig cryptocurrency miner injected into
credwiz.exe. - A backdoor built on PuTTY that scans SMB and spreads to Windows 7 and Server 2008 machines.
- A modular backdoor aimed at enterprise networks. Avast reports more than 7,000 computers in one domain.
Avast reports that eScan fixed the problem after disclosure on 31 July 2023. The vendor added HTTPS downloads, a requirement for EV code signing, and checks for unsigned binaries. The Hacker News says the flaw went undetected for at least five years and that infections continued on outdated eScan clients. Avast notes possible links to the Kimsuky group, based on shared code and infrastructure. Read the Avast research. BleepingComputer and The Hacker News covered it too.
The update package gained a new DLL that downloads and runs code. A comparison of the package against a trusted copy shows that file.
Affected versions
Avast does not list eScan product version numbers. The weakness was the unencrypted HTTP update download, so any eScan client that used it was open to attack.
- Activity ran from at least 2018 to mid-2023.
- Avast saw the last variants in November 2023.
- eScan confirmed the fix on 31 July 2023.
Only users whose traffic an attacker could alter received the bad package.
Indicators of compromise
- File
version.dllinC:\Program Files\eScan\that eScan did not ship. - Other DLL names from later variants:
atiadlxx.dll(AMD CNext folder),BrLogAPI.dll(Brother folder),updll3.dll3(Crypto folder). - Domains:
ns1.peepzo.com,ext.peepzo.com,crl.peepzo.com,m.airequipment.net,gesucht.net,www.righttrak.net,www.elimpacific.net. - Registry:
HKLM\SYSTEM\CurrentControlSet\Control\CMF\Class,HKLM\SYSTEM\RNG\FFFF,HKLM\SOFTWARE\Microsoft\DECLAG. - Mutexes:
ONLY_ME_V1,SLDV01toSLDV15,PROCESS_. - SHA-256 of the first 2018 sample:
c3122448ae3b21ac2431d8fd523451ff25de7f6e399ff013d6fa6953a7998fa3
How to check
Look for the sideloaded DLL and the registry keys on each Windows machine that runs eScan.
dir "C:\Program Files\eScan\version.dll"
reg query "HKLM\SYSTEM\CurrentControlSet\Control\CMF\Class"
A version.dll that eScan did not ship, or the registry key, needs follow-up. Also search DNS logs for the domains above. Confirm the eScan client now uses HTTPS for updates.
What to do now
- Update eScan to a build that downloads over HTTPS, as the vendor fixed after July 2023.
- Run the file and registry checks above on every machine with eScan.
- If a check hits, isolate the machine. The malware spreads over SMB, so check neighbouring machines.
- Rebuild affected machines and reset credentials used on them.
- Block the listed domains and watch for new DLLs in application folders.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 20 (1 Added) HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. NEW FILE version.dll It downloads from the internet and runs other programs.
Frequently asked questions
What is GuptiMiner?
GuptiMiner is a campaign that hijacked eScan antivirus updates sent over HTTP. The attackers delivered a malicious DLL that installed a miner and backdoors.
How did attackers hijack eScan updates?
They intercepted the unencrypted HTTP request for the update package and replaced it with a package that held a malicious version.dll.
Did eScan fix the GuptiMiner problem?
Yes. Avast reports that eScan confirmed a fix on 31 July 2023 and added HTTPS downloads and stricter signing checks.
Sources
More supply chain attacks
- JDownloader official site installer swap 6 May 2026
- CPUID CPU-Z / HWMonitor download compromise 9 Apr 2026
- DAEMON Tools trojanized installers 8 Apr 2026
- eScan antivirus update server compromise (2026) 20 Jan 2026
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.