Supply chain attack on eScan antivirus: detecting and remediating malicious updates
Read More On January 20, a supply chain attack has occurred, with the infected software being the eScan antivirus developed by an Indian company MicroWorld Technologies. The previously unknown malware was distributed through the eScan update server. The same day, our...
HoneyMyte updates CoolClient and deploys multiple stealers in recent campaigns
Read More Over the past few years, we’ve been observing and monitoring the espionage activities of HoneyMyte (aka Mustang Panda or Bronze President) within Asia and Europe, with the Southeast Asia region being the most affected. The primary targets of most of the...
The HoneyMyte APT evolves with a kernel-mode rootkit and a ToneShell backdoor
Read More Overview of the attacks In mid-2025, we identified a malicious driver file on computer systems in Asia. The driver file is signed with an old, stolen, or leaked digital certificate and registers as a mini-filter driver on infected machines. Its end-goal is...