ESET Research


2300 articles

Syndicasec in the sin bin: targeted espionage malware in action

Syndicasec in the sin bin: targeted espionage malware in action

Syndicasec in the sin bin: targeted espionage malware in action

Technical analysis of Win32/Syndicasec.A, malware active in Nepal and China as far back as 2010, with a JavaScript payload registered in the Windows WMI subsystem and a system of fake blogs to discover its C&C servers, hosted on Tibet-related domains.

Alexis Dorais-Joncas23 May 2013


Targeted information stealing attacks in South Asia use email, signed binaries

Targeted information stealing attacks in South Asia use email, signed binaries

Targeted information stealing attacks in South Asia use email, signed binaries

Detailed analysis of a targeted campaign that tries to steal sensitive information from different organizations throughout the world, but particularly in Pakistan.

Jean-Ian Boutin16 May 2013


Linux/Cdorked.A malware: Lighttpd and nginx web servers also affected

Linux/Cdorked.A malware: Lighttpd and nginx web servers also affected

Linux/Cdorked.A malware: Lighttpd and nginx web servers also affected

Some 400 web servers found infected with Linux/Cdorked.A. including 50 in Alexa’s top 100,000 websites. And this backdoor has been applied to Lighttpd and nginx binaries in addition to Apache.

Marc-Etienne M.Léveillé07 May 2013


The stealthiness of Linux/Cdorked: a clarification

The stealthiness of Linux/Cdorked: a clarification

The stealthiness of Linux/Cdorked: a clarification

We clarify that the Linux/Cdorked backdoor malware leaves no traces on the hard drive "other than its modified httpd binary" which can be scanned for detection in several ways.

Stephen Cobb02 May 2013


Mysterious Avatar rootkit with API, SDK, and Yahoo Groups for C&C communication

Mysterious Avatar rootkit with API, SDK, and Yahoo Groups for C&C communication

Mysterious Avatar rootkit with API, SDK, and Yahoo Groups for C&C communication

The mysterious Avatar rootkit, detected by ESET as Win32/Rootkit.Avatar, appears to reflect a heavy investment in code development, with an API and a SDK available, plus an interesting abuse of Yahoo Groups for C&C communications.

Aleksandr Matrosov and Anton Cherepanov01 May 2013


Linux/Cdorked.A: New Apache backdoor being used in the wild to serve Blackhole

Linux/Cdorked.A: New Apache backdoor being used in the wild to serve Blackhole

Linux/Cdorked.A: New Apache backdoor being used in the wild to serve Blackhole

Analysis of a malicious backdoor serving Blackhole exploit pack found on Linux Apache webserver compromised by malware dubbed Linux/Cdorked.A, together with remediation tool and techniques.

Pierre-Marc Bureau26 Apr 2013


Is Gapz the most complex bootkit yet?

Is Gapz the most complex bootkit yet?

Is Gapz the most complex bootkit yet?

Introducing a detailed analysis of Win32/Gapz malware in a new white paper titled: Mind the Gapz: The most complex bootkit ever analyzed?

Aleksandr Matrosov08 Apr 2013


Carberp: the never ending story

Carberp: the never ending story

Carberp: the never ending story

Aleksandr Matrosov reveals changes in banking Trojan Carberp relating to Java/Spy.Banker (AgentX.jar) and gaining remote access using legitimate software as backdoor components.

Aleksandr Matrosov25 Mar 2013


Job Scams: Nice Work If You Can Get It

Job Scams: Nice Work If You Can Get It

Job Scams: Nice Work If You Can Get It

The new ESET blog format must be striking a real chord with people. At any rate, job offers are just pouring in. Except that they don't seem to be jobs for security bloggers, or for web developers like the team that maintains this site.

David Harley21 Mar 2013