ESET Research


2296 articles

Killing me gently: Inside Gentlemen’s EDR killer framework

Killing me gently: Inside Gentlemen’s EDR killer framework

Killing me gently: Inside Gentlemen’s EDR killer framework

ESET Research shares the results of a months-long investigation into the suite of EDR killers maintained by the RaaS gang Gentlemen

Jakub Souček18 Jun 2026


FishMonger’s arsenal upgraded: SprySOCKS for Windows

FishMonger’s arsenal upgraded: SprySOCKS for Windows

FishMonger’s arsenal upgraded: SprySOCKS for Windows

ESET researchers have discovered SprySOCKS for Windows, FishMonger’s backdoor weaponizing a kernel driver for advanced stealthiness

ESET Research16 Jun 2026


OceanLotus: From external espionage to domestic targeting

OceanLotus: From external espionage to domestic targeting

OceanLotus: From external espionage to domestic targeting

A shift in operational pattern of the infamous Vietnam-aligned APT group

ESET Research11 Jun 2026


ESET APT Activity Report Q4 2025–Q1 2026

ESET APT Activity Report Q4 2025–Q1 2026

ESET APT Activity Report Q4 2025–Q1 2026

An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q4 2025 and Q1 2026

Jean-Ian Boutin28 May 2026


Webworm: New burrowing techniques

Webworm: New burrowing techniques

Webworm: New burrowing techniques

ESET researchers describe new tools and techniques that the Webworm APT group recently added to its arsenal

Eric Howard20 May 2026


FrostyNeighbor: Fresh mischief and digital shenanigans

FrostyNeighbor: Fresh mischief and digital shenanigans

FrostyNeighbor: Fresh mischief and digital shenanigans

ESET researchers uncovered new activities attributed to FrostyNeighbor, updating its compromise chain to support the group’s continual cyberespionage operations

Damien Schaeffer14 May 2026


Fake call logs, real payments: How CallPhantom tricks Android users

Fake call logs, real payments: How CallPhantom tricks Android users

Fake call logs, real payments: How CallPhantom tricks Android users

ESET researchers uncovered fraudulent apps on Google Play that claim to provide the call history “for any number” and had been downloaded more than seven million times before being taken down

Lukas Stefanko07 May 2026


A rigged game: ScarCruft compromises gaming platform in a supply-chain attack

A rigged game: ScarCruft compromises gaming platform in a supply-chain attack

A rigged game: ScarCruft compromises gaming platform in a supply-chain attack

ESET researchers have investigated an ongoing attack by the ScarCruft APT group that targets the Yanbian region via backdoor-laced Windows and Android games

Filip Jurčacko05 May 2026


GopherWhisper: A burrow full of malware

GopherWhisper: A burrow full of malware

GopherWhisper: A burrow full of malware

ESET Research has discovered a new China-aligned APT group that we’ve named GopherWhisper, which targets Mongolian governmental institutions

Eric Howard23 Apr 2026