cognitive cybersecurity intelligence

News and Analysis

Search

Hackers infect users of antivirus service that delivered updates over HTTP

Hackers used an antivirus service, eScan, to spread malware for five years by exploiting its HTTP update protocol. Unknown attackers linked to North Korea replaced a genuine update with malware that infected users with advanced backdoor software. The attackers used various coding techniques to avoid detection. Researchers from Avast discovered the breach and eScan confirmed it had been fixed. The GuptiMiner malware has been active since 2018 and may be connected to the North Korean group Kimsuky.

Source: arstechnica.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts