ESET Research


2300 articles

Win32/Napolar – A new bot on the block

Win32/Napolar – A new bot on the block

Win32/Napolar – A new bot on the block

There is a new bot on the block. ESET identifies it as Win32/Napolar while its author calls it solarbot. This piece of malware came to our attention mid-August because of its interesting anti-debugging and code injection techniques.

Pierre-Marc Bureau25 Sep 2013


Filecoder: Holding your data to ransom

Filecoder: Holding your data to ransom

Filecoder: Holding your data to ransom

Trojans that encrypt user files and try to extort a ransom from the victim in exchange for a decryptor utility are nothing new. We’ve noted a significant increase in Filecoder activity over the past few summer months - in this blog post we address the questions we’re getting about this issue.

Robert Lipovsky23 Sep 2013


Known unknowns - detecting rootkits under OS X

Known unknowns - detecting rootkits under OS X

Known unknowns - detecting rootkits under OS X

We think that there could be rootkits targeting the OS X platform, but we have very limited visibility into that threat right now. We know that we don’t know. Today, ESET is releasing a simple tool to detect rootkits on OS X.

Marc-Etienne M.Léveillé23 Sep 2013


Hesperbot - technical analysis: part 2/2

Hesperbot - technical analysis: part 2/2

Hesperbot - technical analysis: part 2/2

In this 3rd Hesperbot blog post we’ll look at the most intriguing part of the malware - the way it handles network traffic interception.

Robert Lipovsky09 Sep 2013


Hesperbot – Technical analysis part 1/2

Hesperbot – Technical analysis part 1/2

Hesperbot – Technical analysis part 1/2

Win32/Spy.Hesperbot is a new banking trojan that has been targeting online banking users in Turkey, the Czech Republic, Portugal and the United Kingdom. For more information about its malware spreading campaigns and victims, refer to our first blog post. In this post we’ll cover the technical details of the malware, including the overall architecture, as well as the mobile component.

Robert Lipovsky06 Sep 2013


Hesperbot – A New, Advanced Banking Trojan in the Wild

Hesperbot – A New, Advanced Banking Trojan in the Wild

Hesperbot – A New, Advanced Banking Trojan in the Wild

A new and effective banking trojan has been discovered targeting online banking users in Turkey, the Czech Republic, Portugal and the United Kingdom. It uses very credible-looking phishing-like campaigns, related to trustworthy organizations, to lure victims into running the malware.

Robert Lipovsky04 Sep 2013


The Powerloader 64-bit update based on leaked exploits

The Powerloader 64-bit update based on leaked exploits

The Powerloader 64-bit update based on leaked exploits

A few months ago on this blog I described PowerLoader functionality - including an interesting way for privilege escalation into the explorer.exe system process. The leaked PowerLoader code is also used in other malware families.

Aleksandr Matrosov27 Aug 2013


Nymaim - obfuscation chronicles

Nymaim - obfuscation chronicles

Nymaim - obfuscation chronicles

We look at malware delivered by a campaign that has infected thousands of websites around the world - and the various control flow obfuscation techniques that make its analysis as interesting as it is challenging.

Jean-Ian Boutin26 Aug 2013


Orbital Decay: the dark side of a popular file downloading tool

Orbital Decay: the dark side of a popular file downloading tool

Orbital Decay: the dark side of a popular file downloading tool

Orbit Downloader by Innoshock is a popular browser add-on often used to download embedded videos from sites such as YouTube. But the popular add-on has disturbing hidden functions.

Aryeh Goretsky21 Aug 2013