ESET Research


2279 articles

LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan

LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan

LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan

ESET researchers discovered a China-aligned APT group, LongNosedGoblin, which uses Group Policy to deploy cyberespionage tools across networks of governmental institutions

Anton Cherepanov and Peter Strýček18 Dec 2025


ESET Threat Report H2 2025

ESET Threat Report H2 2025

ESET Threat Report H2 2025

A view of the H2 2025 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts

Jiří Kropáč16 Dec 2025


MuddyWater: Snakes by the riverbank

MuddyWater: Snakes by the riverbank

MuddyWater: Snakes by the riverbank

MuddyWater targets critical infrastructure in Israel and Egypt, relying on custom malware, improved tactics, and a predictable playbook

ESET Research02 Dec 2025


PlushDaemon compromises network devices for adversary-in-the-middle attacks

PlushDaemon compromises network devices for adversary-in-the-middle attacks

PlushDaemon compromises network devices for adversary-in-the-middle attacks

ESET researchers have discovered a network implant used by the China-aligned PlushDaemon APT group to perform adversary-in-the-middle attacks

Facundo Muñoz and Dávid Gábriš19 Nov 2025


ESET APT Activity Report Q2 2025–Q3 2025

ESET APT Activity Report Q2 2025–Q3 2025

ESET APT Activity Report Q2 2025–Q3 2025

An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q2 2025 and Q3 2025

Jean-Ian Boutin06 Nov 2025


Gotta fly: Lazarus targets the UAV sector

Gotta fly: Lazarus targets the UAV sector

Gotta fly: Lazarus targets the UAV sector

ESET research analyzes a recent instance of the Operation DreamJob cyberespionage campaign conducted by Lazarus, a North Korea-aligned APT group

Peter Kálnai and Alexis Rapin23 Oct 2025


New spyware campaigns target privacy-conscious Android users in the UAE

New spyware campaigns target privacy-conscious Android users in the UAE

New spyware campaigns target privacy-conscious Android users in the UAE

ESET researchers have discovered campaigns distributing spyware disguised as Android Signal and ToTok apps, targeting users in the United Arab Emirates

Lukas Stefanko02 Oct 2025


DeceptiveDevelopment: From primitive crypto theft to sophisticated AI-based deception

DeceptiveDevelopment: From primitive crypto theft to sophisticated AI-based deception

DeceptiveDevelopment: From primitive crypto theft to sophisticated AI-based deception

Malware operators collaborate with covert North Korean IT workers, posing a threat to both headhunters and job seekers

Peter Kálnai and Matěj Havránek25 Sep 2025


Gamaredon X Turla collab

Gamaredon X Turla collab

Gamaredon X Turla collab

Notorious APT group Turla collaborates with Gamaredon, both FSB-associated groups, to compromise high‑profile targets in Ukraine

Matthieu Faou and Zoltán Rusnák19 Sep 2025