ESET Research


2300 articles

Avatar rootkit: the continuing saga

Avatar rootkit: the continuing saga

Avatar rootkit: the continuing saga

In this blog post we confirm that the Avatar rootkit continues to thrive in the wild, and disclose some new information about its kernel-mode self-defense tricks. We continue our research into this malware family.

Aleksandr Matrosov and Anton Cherepanov21 Aug 2013


Radar Love: how classic rock helps to highlight Java problems

Radar Love: how classic rock helps to highlight Java problems

Radar Love: how classic rock helps to highlight Java problems

Java has been – and still is – one of the more problematic issues security-wise. A website showing song lyrics from Golden Earring's Radar Love shows off problems that can leave users at the mercy of Java attacks.

Righard Zwienenberg19 Aug 2013


Catch me if you can: Can we predict who will fall for phishing emails?

Catch me if you can: Can we predict who will fall for phishing emails?

Catch me if you can: Can we predict who will fall for phishing emails?

A new paper aims to profile the victims most likely to fall for a phishing attack. But what is less clear is how you develop a profile while avoiding the pitfalls of stereotyping.

David Harley14 Aug 2013


Versatile and infectious: Win64/Expiro is a cross-platform file infector

Versatile and infectious: Win64/Expiro is a cross-platform file infector

Versatile and infectious: Win64/Expiro is a cross-platform file infector

ESET Research30 Jul 2013


The Home Campaign: overstaying its welcome

The Home Campaign: overstaying its welcome

The Home Campaign: overstaying its welcome

The Home Campaign is a malware campaign that uses a modified variant of Darkleech to direct visitors to the Blackhole exploit kit. We want to give a better idea of the size and extent of this campaign.

Sébastien Duquette02 Jul 2013


More malware targeting crypto-currencies: Litecoin stealing Trojan found

More malware targeting crypto-currencies: Litecoin stealing Trojan found

More malware targeting crypto-currencies: Litecoin stealing Trojan found

Bitcoin is not the only crypto-currency targeted by malware now that a Trojan designed to steal Litecoins has been discovered. In this post we review recent discoveries in malware impacting digital money.

Robert Lipovsky01 Jul 2013


Needles and haystacks - the art of threat attribution

Needles and haystacks - the art of threat attribution

Needles and haystacks - the art of threat attribution

ESET researchers explain the difficulties in attribution of targeted attacks; evidence is often circumstantial and the source never positively identified.

Aryeh Goretsky17 Jun 2013


Operation Hangover: more links to the Oslo Freedom Forum incident

Operation Hangover: more links to the Oslo Freedom Forum incident

Operation Hangover: more links to the Oslo Freedom Forum incident

In our previous post on Operation Hangover, we revealed the existence of an attack group, apparently operating from within India, who were mainly targeting systems in Pakistan. In this post, we will analyze the Mac OS X samples that have been linked to this group and will provide new evidence that the Mac and Windows spywares are related.

Jean-Ian Boutin05 Jun 2013


Tax returns: Slovakian spyware campaign

Tax returns: Slovakian spyware campaign

Tax returns: Slovakian spyware campaign

ESET’s Security Research Lab details a malware-spreading campaign leveraging the deadline for tax returns in Slovakia and examines a case of infection where a bank's two-factor authentication prevented financial loss.

Robert Lipovsky24 May 2013