Research has been at the core of ESET and its technology since the company's inception. The journey began in 1987, when ESET co-founders Miroslav Trnka and Peter Paško uncovered one of the world's first computer viruses, which they named "Vienna" and wrote a program to detect it. Many other discoveries quickly followed.

More than 30 years later, ESET remains at the forefront of cybersecurity research, operating 11 R&D centers across the world that analyze, monitor and anticipate new threats. In recent years alone, ESET researchers have made a number of significant discoveries that shed light on various malicious campaigns orchestrated by the world’s most advanced threat actors. They have also identified multiple high-impact vulnerabilities in third-party products and services.

Over the years, ESET’s experts have assisted law enforcement with disruptions of several notorious cybercrime operations. They also frequently present at leading industry conferences and are among the most referenced contributors to the MITRE ATT&CK® knowledge base of adversary tactics and techniques.

ESET Coordinated Vulnerability Disclosure Policy


2300 articles

ESET takes part in global operation to disrupt Gamarue

ESET takes part in global operation to disrupt Gamarue

ESET takes part in global operation to disrupt Gamarue

Wauchos is an extensible bot that allows its owner to create and use custom plugins. However, there are some plugins that are widely available and that are used by many different botnets.

Jean-Ian Boutin04 Dec 2017


New campaigns spread banking malware through Google Play

New campaigns spread banking malware through Google Play

New campaigns spread banking malware through Google Play

For a user, it can be difficult to figure out whether an app is malicious. First off it is always good only to install applications from the Google Play store, since most malware is still mainly spread through alternative stores.

Lukas Stefanko21 Nov 2017


Multi-stage malware sneaks into Google Play

Multi-stage malware sneaks into Google Play

Multi-stage malware sneaks into Google Play

In all the cases we investigated, the final payload was a mobile banking trojan. Once installed, it behaves like a typical malicious app of this kind: it may present the user with fake login forms to steal credentials or credit card details.

Lukas Stefanko15 Nov 2017


Transparency of machine-learning algorithms is a double-edged sword

Transparency of machine-learning algorithms is a double-edged sword

Transparency of machine-learning algorithms is a double-edged sword

Unless companies processing citizens’ personal data fully understand the reasoning behind the decisions made based on their machine-learning models, they will find themselves between a rock and a hard place.

Juraj Jánošík13 Nov 2017


Fighting persistent malware with a UEFI scanner, or 'What's it all about UEFI?"

Fighting persistent malware with a UEFI scanner, or 'What's it all about UEFI?"

Fighting persistent malware with a UEFI scanner, or 'What's it all about UEFI?"

The biggest news in malware so far this year has been WannaCryptor a.k.a. WannaCry, and one reason that particular ransomware spread so fast was because it used a “top secret” exploit developed by the NSA, an agency known to have dabbled in UEFI compromise.

Stephen Cobb10 Nov 2017


Learn how a research lab works

Learn how a research lab works

Learn how a research lab works

The story of viruses took place in a university laboratory and, keeping in mind the parallelism, we want to show you what is a malware research laboratory like and what exactly happens there.

Santiago Sassone02 Nov 2017


Windigo Still not Windigone: An Ebury Update

Windigo Still not Windigone: An Ebury Update

Windigo Still not Windigone: An Ebury Update

In 2014, ESET researchers wrote a blog post about an OpenSSH backdoor and credential stealer called Linux/Ebury In 2017, the team found a new Ebury sample.

Frédéric Vachon30 Oct 2017


Bad Rabbit: Not-Petya is back with improved ransomware

Bad Rabbit: Not-Petya is back with improved ransomware

Bad Rabbit: Not-Petya is back with improved ransomware

A new ransomware outbreak today has hit some major infrastructure in Ukraine including Kiev metro. Here are some details about this new variant of Petya.

Marc-Etienne M.Léveillé24 Oct 2017


Fake cryptocurrency trading apps on Google Play

Fake cryptocurrency trading apps on Google Play

Fake cryptocurrency trading apps on Google Play

With all the hype around cryptocurrencies, cybercriminals are trying to grab whatever new opportunity they can – be it hijacking users’ computing power to mine cryptocurrencies via browsers or by compromising unpatched machines, or various scam schemes utilizing phishing websites and fake apps.

Lukas Stefanko23 Oct 2017