I had not heard of eScan anti-virus…

…but a North Korean threat actor group had and they hijacked the update process to inject malware into the “protected” systems.

Researchers at Avast believe the group is the North Korean APT group Kimsuki. The malware installs GuptiMiner – a crypto-miner – and disables several other security precautions if they are detected on the infected system.

Your Takeaway

If you use scan you, your IT team and cyber security support have a problem.

Your anti-virus solution is only one part of your cyber security defence-in-depth and should work with other solutions to provide integrated protection.

Clive Catton MSc (Cyber Security) – by-line and other articles

Further Reading