Anton Cherepanov

Anton Cherepanov

Senior Malware Researcher


Education: Specialist degree in IT

Favorite activities? Traveling, reading

What is your golden rule for cyberspace? Use common sense

When did you get your first computer and what kind was it? In 1996 a 486DX4-100

Favorite computer game/activity? CTF games


35 articles by Anton Cherepanov

LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan

LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan

LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan

ESET researchers discovered a China-aligned APT group, LongNosedGoblin, which uses Group Policy to deploy cyberespionage tools across networks of governmental institutions

Anton Cherepanov and Peter Strýček • 18 Dec 2025 • 18 min. read


First known AI-powered ransomware uncovered by ESET Research

First known AI-powered ransomware uncovered by ESET Research

First known AI-powered ransomware uncovered by ESET Research

The discovery of PromptLock shows how malicious use of AI models could supercharge ransomware and other threats

Anton Cherepanov and Peter Strýček • 26 Aug 2025 • 2 min. read


Update WinRAR tools now: RomCom and others exploiting zero-day vulnerability

Update WinRAR tools now: RomCom and others exploiting zero-day vulnerability

Update WinRAR tools now: RomCom and others exploiting zero-day vulnerability

ESET Research discovered a zero-day vulnerability in WinRAR being exploited in the wild in the guise of job application documents; the weaponized archives exploited a path traversal flaw to compromise their targets

Anton Cherepanov, Peter Strýček, Damien Schaeffer • 11 Aug 2025 • 8 min. read


Watering hole deploys new macOS malware, DazzleSpy, in Asia

Watering hole deploys new macOS malware, DazzleSpy, in Asia

Watering hole deploys new macOS malware, DazzleSpy, in Asia

Hong Kong pro-democracy radio station website compromised to serve a Safari exploit that installed cyberespionage malware on site visitors’ Macs

Marc-Etienne M.Léveillé and Anton Cherepanov • 25 Jan 2022 • 10 min. read


UEFI threats moving to the ESP: Introducing ESPecter bootkit

UEFI threats moving to the ESP: Introducing ESPecter bootkit

UEFI threats moving to the ESP: Introducing ESPecter bootkit

ESET research discovers a previously undocumented UEFI bootkit with roots going back all the way to at least 2012

Martin Smolár and Anton Cherepanov • 05 Oct 2021 • 15 min. read


Anatomy of native IIS malware

Anatomy of native IIS malware

Anatomy of native IIS malware

ESET researchers publish a white paper putting IIS web server threats under the microscope

Zuzana Hromcová and Anton Cherepanov • 06 Aug 2021 • 8 min. read


Lazarus supply-chain attack in South Korea

Lazarus supply-chain attack in South Korea

Lazarus supply-chain attack in South Korea

ESET researchers uncover a novel Lazarus supply-chain attack leveraging WIZVERA VeraPort software

Anton Cherepanov and Peter Kálnai • 16 Nov 2020 • 15 min. read


Who is calling? CDRThief targets Linux VoIP softswitches

Who is calling? CDRThief targets Linux VoIP softswitches

Who is calling? CDRThief targets Linux VoIP softswitches

ESET researchers have discovered and analyzed malware that targets Voice over IP (VoIP) softswitches

Anton Cherepanov • 10 Sep 2020 • 5 min. read


Digging up InvisiMole’s hidden arsenal

Digging up InvisiMole’s hidden arsenal

Digging up InvisiMole’s hidden arsenal

ESET researchers reveal the modus operandi of the elusive InvisiMole group, including newly discovered ties with the Gamaredon group

Zuzana Hromcová and Anton Cherepanov • 18 Jun 2020 • 7 min. read