#GuptiMiner
Malware/Tool
2024-04-23 • GuptiMiner: Hijacking Antivirus Updates for Distributing Backdoors and Casual Mining
GuptiMiner is a Windows malware operation that hijacked the eScan antivirus update mechanism to distribute backdoors and cryptocurrency miners into corporate networks. Its multi-stage chain used attacker-controlled DNS, DLL side-loading, payloads hidden in images, and a custom trusted root certificate to make malicious components appear valid. Two backdoor types were observed, and XMRig was delivered as a final mining payload. Researchers reported possible Kimsuky ties, while disclosure to eScan and India CERT led to remediation of the update flaw.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days