ESET Research


2258 articles

ESET APT Activity Report Q4 2024–Q1 2025

ESET APT Activity Report Q4 2024–Q1 2025

ESET APT Activity Report Q4 2024–Q1 2025

An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q4 2024 and Q1 2025

Jean-Ian Boutin19 May 2025


Operation RoundPress

Operation RoundPress

Operation RoundPress

ESET researchers uncover a Russia-aligned espionage operation targeting webmail servers via XSS vulnerabilities

Matthieu Faou15 May 2025


TheWizards APT group uses SLAAC spoofing to perform adversary-in-the-middle attacks

TheWizards APT group uses SLAAC spoofing to perform adversary-in-the-middle attacks

TheWizards APT group uses SLAAC spoofing to perform adversary-in-the-middle attacks

ESET researchers analyzed Spellbinder, a lateral movement tool used to perform adversary-in-the-middle attacks

Facundo Muñoz30 Apr 2025


Shifting the sands of RansomHub’s EDRKillShifter

Shifting the sands of RansomHub’s EDRKillShifter

Shifting the sands of RansomHub’s EDRKillShifter

ESET researchers discover new ties between affiliates of RansomHub and of rival gangs Medusa, BianLian, and Play

Jakub Souček and Jan Holman26 Mar 2025


You will always remember this as the day you finally caught FamousSparrow

You will always remember this as the day you finally caught FamousSparrow

You will always remember this as the day you finally caught FamousSparrow

ESET researchers uncover the toolset used by the FamousSparrow APT group, including two undocumented versions of the group’s signature backdoor, SparrowDoor

Alexandre Côté Cyr26 Mar 2025


Operation FishMedley

Operation FishMedley

Operation FishMedley

ESET researchers detail a global espionage operation by FishMonger, the APT group run by I‑SOON

Matthieu Faou20 Mar 2025


Operation AkaiRyū: MirrorFace invites Europe to Expo 2025 and revives ANEL backdoor

Operation AkaiRyū: MirrorFace invites Europe to Expo 2025 and revives ANEL backdoor

Operation AkaiRyū: MirrorFace invites Europe to Expo 2025 and revives ANEL backdoor

ESET researchers uncovered MirrorFace activity that expanded beyond its usual focus on Japan and targeted a Central European diplomatic institute with the ANEL backdoor

Dominik Breitenbacher18 Mar 2025


Threat Report H2 2024: Infostealer shakeup, new attack vector for mobile, and Nomani

Threat Report H2 2024: Infostealer shakeup, new attack vector for mobile, and Nomani

Threat Report H2 2024: Infostealer shakeup, new attack vector for mobile, and Nomani

Big shifts in the infostealer scene, novel attack vector against iOS and Android, and a massive surge in investment scams on social media

ESET Research28 Feb 2025


DeceptiveDevelopment targets freelance developers

DeceptiveDevelopment targets freelance developers

DeceptiveDevelopment targets freelance developers

ESET researchers analyzed a campaign delivering malware bundled with job interview challenges

Matěj Havránek20 Feb 2025