When the memorial came to serve
In an era when many people started to see that Antivirus may not be as necessary as before, because Windows Defender with Windows does a good job and is free for free. But even then, there are still a lot of users who choose to buy more anti-viruses to install, to be comfortable that the system is safer.
.
Usually, we're pretty sure that "the more it gets, the safer it gets," but the story goes back to the extreme, because the program that was supposed to be the first shield turned out to be a way for malware to be sent directly to the user.
.
The incident happened to eScan Antivirus from the company MicroWorld Technologies, the latter of which was revealed that the company's update server had been hacked on January 20, 2026, resulting in users who downloaded the update during that period receiving fake update files instead of regular updates.
.
The attacked file, Reload.exe, which has been replaced by a malware embedded version, allows hackers to send in more malware later, as well as block automatic updates by editing HOSTS files on Windows.
.
According to Morphisec researchers, this malware is multi-stage, with Reload.exe downloading additional payloads such as CONSCTLX.exe and dangerous PowerShell scripts, with the ability to bypass Windows detection systems like AMSI to evade scans.
.
MicroWorld Technologies detected unauthorized access and quickly separated the affected server from the network more than 8 hours before releasing the patch, but the attacked machine could not be updated automatically. The user had to contact the company for the patch himself to find a new patch to repair.
.
The Kaspersky report also revealed that hundreds of machines, both corporate and general users, were found to have been infected by the attack, mainly in India, Bangladesh, Sri Lanka and the Philippines.
.
This event is a very rare form of attack because it is not very common for malware to be transmitted through the security software update system itself, and even more so, even tools built for protection can become vulnerable.
.
Source: thehackernews



































































