Malware & RansomwareHIGH

Malicious Updates Target eScan Antivirus in Supply Chain Attack

KAKaspersky SecurelistJan 29, 2026
eScanKasperskysupply chain attackmalwarecybersecurity
🎯

Basically, hackers used fake updates to infect eScan antivirus software with malware.

Quick Summary

A supply chain attack has compromised eScan antivirus updates with malware. Users are at risk of data breaches and compromised security. Kaspersky is providing guidance to help detect and mitigate the threat.

What Happened

On January 20, a significant supply chain attack was uncovered involving eScan antivirus software. Kaspersky solutions identified malware? that had been inserted into legitimate updates, putting users at risk. This type of attack is particularly dangerous because it exploits trusted software, making it harder for users to detect the threat.

The malware? was designed to infiltrate systems through updates that users would normally trust. As a result, many users may have unknowingly downloaded this malicious software, compromising their devices and data. Indicators of compromise have been shared by Kaspersky to help users identify if they have been affected.

Why Should You Care

This incident is a wake-up call for everyone using antivirus software. Imagine trusting your security tool, only to find out it has been compromised. Your personal data, financial information, and privacy could be at stake. If you use eScan or any antivirus software, you need to be vigilant about updates and suspicious activity.

Think of it like locking your front door but leaving the window open. Just because you have security measures in place doesn’t mean you’re completely safe. Regularly checking for updates and understanding how to spot potential threats can make a huge difference in protecting your digital life.

What's Being Done

Kaspersky is actively investigating the attack and has provided guidance on how to detect and remediate the issue. Users are encouraged to:

  • Monitor their systems for unusual behavior or performance issues.
  • Check for the latest updates from eScan and ensure they are legitimate.
  • Follow Kaspersky's recommendations for threat hunting? and mitigation?.

Experts are closely watching for further developments, including potential new tactics from the attackers. Staying informed is crucial in the ever-evolving landscape of cybersecurity.

💡 Tap dotted terms for explanations

🔒 Pro insight: This incident highlights the vulnerabilities in supply chain security, emphasizing the need for enhanced verification processes for software updates.

Original article from

Kaspersky Securelist · Georgy Kucherin, Kirill Korchemny, Ilya Savelyev

Read Full Article

Related Pings

HIGHMalware & Ransomware

ClickFix Attackers Evolve Tactics to Bypass Security Measures

Microsoft warns about a new ClickFix phishing tactic. Attackers are tricking users into executing harmful commands via Windows Terminal. This method can compromise your data and security. Stay alert and educate yourself on these evolving threats!

CSO Online·Yesterday, 9:15 PM
HIGHMalware & Ransomware

Fake Google Meet Update Gives Attackers Control of Your PC

A fake Google Meet update is tricking users into giving hackers control of their PCs. This poses a serious risk to personal and sensitive data. Stay vigilant and avoid suspicious update prompts to protect yourself.

Malwarebytes Labs·Yesterday, 7:35 PM
HIGHMalware & Ransomware

Spyware Masquerades as Emergency App Targeting Israeli Smartphones

Israeli smartphones were targeted by spyware disguised as an emergency app. This deceptive tactic puts personal data at risk. Stay vigilant and verify app legitimacy to protect your privacy.

The Register Security·Yesterday, 6:56 PM
HIGHMalware & Ransomware

Metasploit Update: New Exploits and Enhanced Control Features

Metasploit has launched a new update with powerful exploits and features. Users of Tactical RMM and MajorDoMo are particularly at risk. Stay ahead of potential attacks by updating your systems and reviewing security measures.

Rapid7 Blog·Yesterday, 6:28 PM
HIGHMalware & Ransomware

New ClickFix Attack Uses Windows Terminal for Malicious Payloads

A new wave of ClickFix attacks targets Windows Terminal to deliver malicious payloads. Users are at risk of unauthorized access and data theft. Stay cautious and keep your software updated to protect yourself.

Cyber Security News·Yesterday, 6:05 PM
HIGHMalware & Ransomware

AI-Powered Malware: Transparent Tribe Targets India

A hacking group is using AI to create malware targeting India. This mass production of implants could compromise personal data and financial security. Experts recommend updating software and using strong passwords to protect against these threats.

The Hacker News·Yesterday, 3:11 PM