ESET Research


2290 articles

Fake call logs, real payments: How CallPhantom tricks Android users

Fake call logs, real payments: How CallPhantom tricks Android users

Fake call logs, real payments: How CallPhantom tricks Android users

ESET researchers uncovered fraudulent apps on Google Play that claim to provide the call history “for any number” and had been downloaded more than seven million times before being taken down

Lukas Stefanko07 May 2026


A rigged game: ScarCruft compromises gaming platform in a supply-chain attack

A rigged game: ScarCruft compromises gaming platform in a supply-chain attack

A rigged game: ScarCruft compromises gaming platform in a supply-chain attack

ESET researchers have investigated an ongoing attack by the ScarCruft APT group that targets the Yanbian region via backdoor-laced Windows and Android games

Filip Jurčacko05 May 2026


GopherWhisper: A burrow full of malware

GopherWhisper: A burrow full of malware

GopherWhisper: A burrow full of malware

ESET Research has discovered a new China-aligned APT group that we’ve named GopherWhisper, which targets Mongolian governmental institutions

Eric Howard23 Apr 2026


New NGate variant hides in a trojanized NFC payment app

New NGate variant hides in a trojanized NFC payment app

New NGate variant hides in a trojanized NFC payment app

ESET researchers discover another iteration of NGate malware, this time possibly developed with the assistance of AI

Lukas Stefanko21 Apr 2026


EDR killers explained: Beyond the drivers

EDR killers explained: Beyond the drivers

EDR killers explained: Beyond the drivers

ESET researchers dive deeper into the EDR killer ecosystem, disclosing how attackers abuse vulnerable drivers

Jakub Souček19 Mar 2026


Sednit reloaded: Back in the trenches

Sednit reloaded: Back in the trenches

Sednit reloaded: Back in the trenches

The resurgence of one of Russia’s most notorious APT groups

ESET Research10 Mar 2026


PromptSpy ushers in the era of Android threats using GenAI

PromptSpy ushers in the era of Android threats using GenAI

PromptSpy ushers in the era of Android threats using GenAI

ESET researchers discover PromptSpy, the first known Android malware to abuse generative AI in its execution flow

Lukas Stefanko19 Feb 2026


DynoWiper update: Technical analysis and attribution

DynoWiper update: Technical analysis and attribution

DynoWiper update: Technical analysis and attribution

ESET researchers present technical details on a recent data destruction incident affecting a company in Poland’s energy sector

ESET Research30 Jan 2026


Love? Actually: Fake dating app used as lure in targeted spyware campaign in Pakistan

Love? Actually: Fake dating app used as lure in targeted spyware campaign in Pakistan

Love? Actually: Fake dating app used as lure in targeted spyware campaign in Pakistan

ESET researchers discover an Android spyware campaign targeting users in Pakistan via romance scam tactics, revealing links to a broader spy operation

Lukas Stefanko28 Jan 2026