ESET Research


2260 articles

Danabot: Analyzing a fallen empire

Danabot: Analyzing a fallen empire

Danabot: Analyzing a fallen empire

ESET Research shares its findings on the workings of Danabot, an infostealer recently disrupted in a multinational law enforcement operation

Tomáš Procházka22 May 2025


ESET takes part in global operation to disrupt Lumma Stealer

ESET takes part in global operation to disrupt Lumma Stealer

ESET takes part in global operation to disrupt Lumma Stealer

Our intense monitoring of tens of thousands of malicious samples helped this global disruption operation

Jakub Tomanek21 May 2025


ESET APT Activity Report Q4 2024–Q1 2025

ESET APT Activity Report Q4 2024–Q1 2025

ESET APT Activity Report Q4 2024–Q1 2025

An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q4 2024 and Q1 2025

Jean-Ian Boutin19 May 2025


Operation RoundPress

Operation RoundPress

Operation RoundPress

ESET researchers uncover a Russia-aligned espionage operation targeting webmail servers via XSS vulnerabilities

Matthieu Faou15 May 2025


TheWizards APT group uses SLAAC spoofing to perform adversary-in-the-middle attacks

TheWizards APT group uses SLAAC spoofing to perform adversary-in-the-middle attacks

TheWizards APT group uses SLAAC spoofing to perform adversary-in-the-middle attacks

ESET researchers analyzed Spellbinder, a lateral movement tool used to perform adversary-in-the-middle attacks

Facundo Muñoz30 Apr 2025


Shifting the sands of RansomHub’s EDRKillShifter

Shifting the sands of RansomHub’s EDRKillShifter

Shifting the sands of RansomHub’s EDRKillShifter

ESET researchers discover new ties between affiliates of RansomHub and of rival gangs Medusa, BianLian, and Play

Jakub Souček and Jan Holman26 Mar 2025


You will always remember this as the day you finally caught FamousSparrow

You will always remember this as the day you finally caught FamousSparrow

You will always remember this as the day you finally caught FamousSparrow

ESET researchers uncover the toolset used by the FamousSparrow APT group, including two undocumented versions of the group’s signature backdoor, SparrowDoor

Alexandre Côté Cyr26 Mar 2025


Operation FishMedley

Operation FishMedley

Operation FishMedley

ESET researchers detail a global espionage operation by FishMonger, the APT group run by I‑SOON

Matthieu Faou20 Mar 2025


Operation AkaiRyū: MirrorFace invites Europe to Expo 2025 and revives ANEL backdoor

Operation AkaiRyū: MirrorFace invites Europe to Expo 2025 and revives ANEL backdoor

Operation AkaiRyū: MirrorFace invites Europe to Expo 2025 and revives ANEL backdoor

ESET researchers uncovered MirrorFace activity that expanded beyond its usual focus on Japan and targeted a Central European diplomatic institute with the ANEL backdoor

Dominik Breitenbacher18 Mar 2025