India
IND
On 20 January 2026, unauthorized access to MicroWorld Technologies' eScan regional update infrastructure placed an unauthorized file in the legitimate software-distribution path and delivered it to a subset of customers during an approximately two-hour window. MicroWorld confirmed the update-infrastructure compromise and temporarily disrupted update services while isolating and rebuilding affected infrastructure. Morphisec's independent analysis characterized the delivered file as a multi-stage malicious payload that established persistence, modified eScan configuration and blocked further updates on compromised endpoints. MicroWorld disputed aspects of Morphisec's characterization and scope but confirmed the unauthorized distribution event.
Estimated severity
70 / 100
Source reliability
90 / 100
Approximate Date
20/01/2026
Targeted Company
MICROWORLD TECHNOLOGIES
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
No information
India
IND
No other affected countries reported
Target country
India
Affected countries
No information
Impacted regions
No information
Duration
No information
Financial impact (USD M)
No information
Impact types
Affected sectors
Affected departments
Attack types
Attributed threat actors
No information
Incident Sources
Please rotate your phone