ESET Research


2301 articles

Who’s swimming in South Korean waters? Meet ScarCruft’s Dolphin

Who’s swimming in South Korean waters? Meet ScarCruft’s Dolphin

Who’s swimming in South Korean waters? Meet ScarCruft’s Dolphin

ESET researchers uncover Dolphin, a sophisticated backdoor extending the arsenal of the ScarCruft APT group

Filip Jurčacko • 30 Nov 2022


RansomBoggs: New ransomware targeting Ukraine

RansomBoggs: New ransomware targeting Ukraine

RansomBoggs: New ransomware targeting Ukraine

ESET researchers spot a new ransomware campaign that goes after Ukrainian organizations and has Sandworm's fingerprints all over it

Editor • 28 Nov 2022


Bahamut cybermercenary group targets Android users with fake VPN apps

Bahamut cybermercenary group targets Android users with fake VPN apps

Bahamut cybermercenary group targets Android users with fake VPN apps

Malicious apps used in this active campaign exfiltrate contacts, SMS messages, recorded phone calls, and even chat messages from apps such as Signal, Viber, and Telegram

Lukas Stefanko • 23 Nov 2022


ESET APT Activity Report T2 2022

ESET APT Activity Report T2 2022

ESET APT Activity Report T2 2022

An overview of the activities of selected APT groups investigated and analyzed by ESET Research in T2 2022

Jean-Ian Boutin • 14 Nov 2022


Domestic Kitten campaign spying on Iranian citizens with new FurBall malware

Domestic Kitten campaign spying on Iranian citizens with new FurBall malware

Domestic Kitten campaign spying on Iranian citizens with new FurBall malware

APT-C-50’s Domestic Kitten campaign continues, targeting Iranian citizens with a new version of the FurBall malware masquerading as an Android translation app

Lukas Stefanko • 20 Oct 2022


POLONIUM targets Israel with Creepy malware

POLONIUM targets Israel with Creepy malware

POLONIUM targets Israel with Creepy malware

ESET researchers analyzed previously undocumented custom backdoors and cyberespionage tools deployed in Israel by the POLONIUM APT group

Matías Porolli • 11 Oct 2022


ESET Threat Report T2 2022

ESET Threat Report T2 2022

ESET Threat Report T2 2022

A view of the T2 2022 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts

Roman Kováč • 05 Oct 2022


Amazon-themed campaigns of Lazarus in the Netherlands and Belgium

Amazon-themed campaigns of Lazarus in the Netherlands and Belgium

Amazon-themed campaigns of Lazarus in the Netherlands and Belgium

ESET researchers have discovered Lazarus attacks against targets in the Netherlands and Belgium that use spearphishing emails connected to fake job offers

Peter Kálnai • 30 Sep 2022


You never walk alone: The SideWalk backdoor gets a Linux variant

You never walk alone: The SideWalk backdoor gets a Linux variant

You never walk alone: The SideWalk backdoor gets a Linux variant

ESET researchers have uncovered another tool in the already extensive arsenal of the SparklingGoblin APT group: a Linux variant of the SideWalk backdoor

Vladislav Hrčka, Thibaut Passilly, Mathieu Tartare • 14 Sep 2022