ESET Research


2300 articles

The Industrialization of Malware: One of 2012's darkest themes persists

The Industrialization of Malware: One of 2012's darkest themes persists

The Industrialization of Malware: One of 2012's darkest themes persists

Stephen Cobb31 Dec 2012


Phishing and the Smile on the Face of the Tiger

Phishing and the Smile on the Face of the Tiger

Phishing and the Smile on the Face of the Tiger

Two rough and ready phishing emails that nevertheless tell us a great deal about the social engineering underlying more sophisticated, graphic-rich scams.

David Harley28 Dec 2012


Win32/Gapz: New Bootkit Technique

Win32/Gapz: New Bootkit Technique

Win32/Gapz: New Bootkit Technique

Win32/Gapz's new bootkit technique modifies just 4 bytes of the original VBR, has an enhanced dropper and complex kernel mode functionality, and evades ELAM.

Eugene Rodionov27 Dec 2012


Win32/Gapz: steps of evolution

Win32/Gapz: steps of evolution

Win32/Gapz: steps of evolution

Win32/Gapz has a new technique for code injection and a new VBR infection method. The dropper has many tricks for bypassing detection by security software.

Aleksandr Matrosov27 Dec 2012


Securing Your Holiday Tech Gifts, Part 2: Android Guide

Securing Your Holiday Tech Gifts, Part 2: Android Guide

Securing Your Holiday Tech Gifts, Part 2: Android Guide

Cameron Camp21 Dec 2012


Malicious Apache Module: a clarification

Malicious Apache Module: a clarification

Malicious Apache Module: a clarification

Apache modules are add-on code taking advantage of the Apache module API to extend the functionality of the standard Apache distro. In this case, the binary's functionality was malicious, but there is no exploitation of a known Apache vulnerability in this case.

David Harley20 Dec 2012


Win32/Spy.Ranbyus modifying Java code in RBS Ukraine systems

Win32/Spy.Ranbyus modifying Java code in RBS Ukraine systems

Win32/Spy.Ranbyus modifying Java code in RBS Ukraine systems

Win32/Spy.Ranbyus shows how it is possible to bypass payment transaction signing/authentication with smartcard devices and has started to modify java code in one of the most popular remote banking systems (RBS) in the Ukraine.

Aleksandr Matrosov19 Dec 2012


Malicious Apache module used for content injection: Linux/Chapro.A

Malicious Apache module used for content injection: Linux/Chapro.A

Malicious Apache module used for content injection: Linux/Chapro.A

More than half of all web servers on the Internet use Apache, so when we discovered a malicious Apache module in the wild last month, we were understandably concerned.

Pierre-Marc Bureau18 Dec 2012


A Load of (Red) Bull

A Load of (Red) Bull

A Load of (Red) Bull

A hoax/chain message claiming that a well-known energy drink poses a serious threat to health, is now spreading on Facebook.

David Harley17 Dec 2012