ESET Research


2300 articles

Android banking trojan masquerades as Flash Player and bypasses 2FA

Android banking trojan masquerades as Flash Player and bypasses 2FA

Android banking trojan masquerades as Flash Player and bypasses 2FA

This malware masquerades as Flash Player, behaves like a screen locker, and can bypass two-factor authentication. This combination of features turns it into a powerful tool for stealing money from victims’ bank accounts.

Lukas Stefanko09 Mar 2016


New Mac ransomware appears: KeRanger, spread via Transmission app

New Mac ransomware appears: KeRanger, spread via Transmission app

New Mac ransomware appears: KeRanger, spread via Transmission app

New ransomware infecting Apple OS X surfaced on March 4th, 2016, with the emergence of KeRanger. The first inkling of trouble came at the weekend.

Peter Stancik07 Mar 2016


ESET expert: Google Play porn clicker 'is a truly large-scale campaign'

ESET expert: Google Play porn clicker 'is a truly large-scale campaign'

ESET expert: Google Play porn clicker 'is a truly large-scale campaign'

Google Play porn clicker campaign: A single family of malicious apps masquerading as popular games or apps, designed to bypass Google’s security checks.

Editor24 Feb 2016


Porn clicker trojans at Google Play: An analysis

Porn clicker trojans at Google Play: An analysis

Porn clicker trojans at Google Play: An analysis

ESET researchers have found a large campaign of malicious porn clicker type apps on Google Play. These trojans belong to a single family of malicious apps masquerading as popular games and/or applications. They are designed and systematically modified to bypass Google’s security checks.

Lukas Stefanko24 Feb 2016


The rise of Android ransomware

The rise of Android ransomware

The rise of Android ransomware

Lock-screen types and file-encrypting “crypto-ransomware”, both of which have been causing major financial and data losses for many years, have made their way to the Android platform. ESET has prepared a topical white paper on the growth of this insidious Android malware.

Robert Lipovsky and Lukas Stefanko18 Feb 2016


How to isolate VBS or JScript malware with Visual Studio

How to isolate VBS or JScript malware with Visual Studio

How to isolate VBS or JScript malware with Visual Studio

ESET has seen a rise in malware developed using scripting languages. We can understand the threats better by isolating them in a dynamic analysis environment.

Diego Perez11 Feb 2016


Windows exploitation in 2015

Windows exploitation in 2015

Windows exploitation in 2015

Hacking Team exploits and new security features in Google Chrome and Microsoft Edge are just a few of the highlights of ESET's annual Windows exploitation in 2015 report.

ESET Research26 Jan 2016


BlackEnergy by the SSHBearDoor: attacks against Ukrainian news media and electric industry

BlackEnergy by the SSHBearDoor: attacks against Ukrainian news media and electric industry

BlackEnergy by the SSHBearDoor: attacks against Ukrainian news media and electric industry

The cybercriminal group behind BlackEnergy, the malware family that has been around since 2007 and has made a comeback in 2014, was also active in the year 2015.

Anton Cherepanov03 Jan 2016


Nemucod malware spreads ransomware Teslacrypt around the world

Nemucod malware spreads ransomware Teslacrypt around the world

Nemucod malware spreads ransomware Teslacrypt around the world

ESET has recently observed a huge increase in detections of the Nemucod trojan, a threat that usually tries to download another malware from the internet. Those detections ratios were very high in some countries.

Josep Albors16 Dec 2015