eScan AV supply chain compromise: Users targeted with malicious updates

The update infrastructure for eScan antivirus, a product of Indian cybersecurity company MicroWorld Technologies, has been compromised by unknown attackers to deliver a persistent downloader to enterprise and consumer endpoints. The supply chain compromise also resulted in the eScan antivirus on those endpoints to stop working as intended, since the trojanized eScan update tampered with the solution’s registry, files and update configuration to block remote updates, Morphisec researchers revealed on Thursday. MicroWorld’s incident response It’s … More

The post eScan AV supply chain compromise: Users targeted with malicious updates appeared first on Help Net Security.

This article has been indexed from Help Net Security

Read the original article: