216.73.216.6

Supply chain attack: what you should know

· Published 29/01/2026 17:20 · Modified 02/02/2026 21:18

Export JSON

Essential information

Published
29/01/2026 17:20
Modified
02/02/2026 21:18
Tags
2026-01-29 antivirus consctlx.exe digital signature escan malware persistence reload.exe scheduled tasks supply-chain unauthorized access
Related entities
7 observables, 2 malware, 6 others

Description

A supply chain attack targeted the software, distributing through the update server. The attack, detected on January 20, involved a malicious file that initiated a multi-stage infection chain. This prevented further updates, ensured through , and communicated with control servers to download additional payloads. Attackers gained to a regional update server, deploying a malicious file with a fake . developers quickly isolated the affected infrastructure and reset access credentials. Users are advised to check for infection signs, use a provided removal utility, and block known control server addresses. Kaspersky's security solutions successfully detect the used in this attack.

External references