ESET Research


2301 articles

Strategic web compromises in the Middle East with a pinch of Candiru

Strategic web compromises in the Middle East with a pinch of Candiru

Strategic web compromises in the Middle East with a pinch of Candiru

ESET researchers have discovered strategic web compromise (aka watering hole) attacks against high-profile websites in the Middle East

Matthieu Faou • 16 Nov 2021


Wslink: Unique and undocumented malicious loader that runs as a server

Wslink: Unique and undocumented malicious loader that runs as a server

Wslink: Unique and undocumented malicious loader that runs as a server

There are no code, functionality or operational similarities to suggest that this is a tool from a known threat actor

Vladislav Hrčka • 27 Oct 2021


FontOnLake: Previously unknown malware family targeting Linux

FontOnLake: Previously unknown malware family targeting Linux

FontOnLake: Previously unknown malware family targeting Linux

ESET researchers discover a malware family with tools that show signs they’re used in targeted attacks

Vladislav Hrčka • 07 Oct 2021


UEFI threats moving to the ESP: Introducing ESPecter bootkit

UEFI threats moving to the ESP: Introducing ESPecter bootkit

UEFI threats moving to the ESP: Introducing ESPecter bootkit

ESET research discovers a previously undocumented UEFI bootkit with roots going back all the way to at least 2012

Martin Smolár and Anton Cherepanov • 05 Oct 2021


ESET Threat Report T2 2021

ESET Threat Report T2 2021

ESET Threat Report T2 2021

A view of the T2 2021 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts

Roman Kováč • 30 Sep 2021


FamousSparrow: A suspicious hotel guest

FamousSparrow: A suspicious hotel guest

FamousSparrow: A suspicious hotel guest

Yet another APT group that exploited the ProxyLogon vulnerability in March 2021

Matthieu Faou and Tahseen Bin Taj • 23 Sep 2021


Numando: Count once, code twice

Numando: Count once, code twice

Numando: Count once, code twice

The (probably) penultimate post in our occasional series demystifying Latin American banking trojans.

ESET Research • 17 Sep 2021


BladeHawk group: Android espionage against Kurdish ethnic group

BladeHawk group: Android espionage against Kurdish ethnic group

BladeHawk group: Android espionage against Kurdish ethnic group

ESET researchers have investigated a mobile espionage campaign that targets the Kurdish ethnic group and has been active since at least March 2020

Lukas Stefanko • 07 Sep 2021


Flaw in the Quebec vaccine passport: analysis

Flaw in the Quebec vaccine passport: analysis

Flaw in the Quebec vaccine passport: analysis

ESET cybersecurity expert Marc-Étienne Léveillé analyses in-depth the Quebec vaccine proof apps VaxiCode and VaxiCode Verif.

Marc-Etienne M.Léveillé • 31 Aug 2021