ESET Research


2300 articles

Corkow: analysis of a business-oriented banking Trojan

Corkow: analysis of a business-oriented banking Trojan

Corkow: analysis of a business-oriented banking Trojan

In his blog post last week, Graham Cluley introduced the Win32/Corkow banking trojan. The malware has demonstrated continuous activity in the past year, infecting thousands of users - various indicators point to the fact the malware authors are continually developing the trojan.

Robert Lipovsky and Anton Cherepanov21 Feb 2014


Windows exploitation in 2013

Windows exploitation in 2013

Windows exploitation in 2013

The year 2013 was notable for the appearance of 0-day vulnerabilities that were primarily used in targeted attacks. In this case, criminal hackers worked on developing exploits, only not for random propagation of malicious code, but rather for use in attacks on specific users.

ESET Research11 Feb 2014


Rob Slade: The truth about quantum cryptography - and what it means for privacy

Rob Slade: The truth about quantum cryptography - and what it means for privacy

Rob Slade: The truth about quantum cryptography - and what it means for privacy

'The first thing you need to know about quantum cryptography is that it isn't cryptography. At least, not the quantum part,' writes Rob Slade, information security researcher, author and malware expert.

Guest Author24 Jan 2014


Boaxxe adware: 'A good advert sells the product without drawing attention to itself' Part 2

Boaxxe adware: 'A good advert sells the product without drawing attention to itself' Part 2

Boaxxe adware: 'A good advert sells the product without drawing attention to itself' Part 2

In this post, we examine the complex it fits into a larger click fraud ecosystem, where users can be redirected either automatically, or through search engines browsing, to advertisement websites.

Joan Calvet17 Jan 2014


Getting started with Bitcoin

Getting started with Bitcoin

Getting started with Bitcoin

Everyone is talking about Bitcoin but is it a safe investment for your savings? We Live Security has five tips for protecting yourself against cybercriminals.

Editor15 Jan 2014


Boaxxe adware: 'A good ad sells the product without drawing attention to itself' – Pt 1

Boaxxe adware: 'A good ad sells the product without drawing attention to itself' – Pt 1

Boaxxe adware: 'A good ad sells the product without drawing attention to itself' – Pt 1

This is the first in a series of two blog posts on the malware family Win32/Boaxxe.BE whose end goal is to drive traffic to advertisement websites by using various click fraud techniques, and thus earn money from these websites as an “advertiser”.

Joan Calvet14 Jan 2014


The Death of Anti-Virus: conference paper

The Death of Anti-Virus: conference paper

The Death of Anti-Virus: conference paper

David Harley19 Dec 2013


Qadars – a banking Trojan with the Netherlands in its sights

Qadars – a banking Trojan with the Netherlands in its sights

Qadars – a banking Trojan with the Netherlands in its sights

The first sign we saw of this malware was in mid-May 2013, but it is still very active, and uses Android to bypass two-factor authentication systems. It clearly seeks to infect Dutch computers - 75% of detections come from this region.

Jean-Ian Boutin18 Dec 2013


New Hesperbot targets: Germany and Australia

New Hesperbot targets: Germany and Australia

New Hesperbot targets: Germany and Australia

In September we informed about a new banking trojan called Hesperbot (detected as Win32/Spy.Hesperbot). The perpetrators responsible for the threat are still active – November has been particularly eventful. In this post, we’ll give an update on the situation and malware developments.

Robert Lipovsky10 Dec 2013