Anton Cherepanov

Anton Cherepanov

Senior Malware Researcher


Education: Specialist degree in IT

Favorite activities? Traveling, reading

What is your golden rule for cyberspace? Use common sense

When did you get your first computer and what kind was it? In 1996 a 486DX4-100

Favorite computer game/activity? CTF games


32 articles by Anton Cherepanov

ESET research

GreyEnergy: Updated arsenal of one of the most dangerous threat actors

GreyEnergy: Updated arsenal of one of the most dangerous threat actors

ESET research

GreyEnergy: Updated arsenal of one of the most dangerous threat actors

ESET research reveals a successor to the infamous BlackEnergy APT group targeting critical infrastructure, quite possibly in preparation for damaging attacks

Anton Cherepanov and Robert Lipovsky17 Oct 20185 min. read


ESET research

New TeleBots backdoor: First evidence linking Industroyer to NotPetya

New TeleBots backdoor: First evidence linking Industroyer to NotPetya

ESET research

New TeleBots backdoor: First evidence linking Industroyer to NotPetya

ESET’s analysis of a recent backdoor used by TeleBots – the group behind the massive NotPetya ransomware outbreak – uncovers strong code similarities to the Industroyer main backdoor, revealing a rumored connection that was not previously proven

Anton Cherepanov and Robert Lipovsky11 Oct 20188 min. read


ESET research

Certificates stolen from Taiwanese tech-companies misused in Plead malware campaign

Certificates stolen from Taiwanese tech-companies misused in Plead malware campaign

ESET research

Certificates stolen from Taiwanese tech-companies misused in Plead malware campaign

D-Link and Changing Information Technologies code-signing certificates stolen and abused by highly skilled cyberespionage group focused on East Asia, particularly Taiwan

Anton Cherepanov09 Jul 20182 min. read


ESET research

A tale of two zero-days

A tale of two zero-days

ESET research

A tale of two zero-days

Double zero-day vulnerabilities fused into one. A mysterious sample enables attackers to execute arbitrary code with the highest privileges on intended targets

Anton Cherepanov15 May 20184 min. read


ESET research

Lazarus KillDisks Central American casino

Lazarus KillDisks Central American casino

ESET research

Lazarus KillDisks Central American casino

The Lazarus Group gained notoriety especially after cyber-sabotage against Sony Pictures Entertainment in 2014. Fast forward to late 2017 and the group continues to deploy its malicious tools, including disk-wiping malware known as KillDisk, to attack a number of targets.

Peter Kálnai and Anton Cherepanov03 Apr 20187 min. read


ESET research

Analysis of TeleBots’ cunning backdoor

Analysis of TeleBots’ cunning backdoor

ESET research

Analysis of TeleBots’ cunning backdoor

This article reveals details about the initial infection vector that was used during the DiskCoder.C outbreak.

Anton Cherepanov04 Jul 20176 min. read


ESET research

TeleBots are back: Supply-chain attacks against Ukraine

TeleBots are back: Supply-chain attacks against Ukraine

ESET research

TeleBots are back: Supply-chain attacks against Ukraine

This blogpost reveals many details about the Diskcoder.C (aka ExPetr or NotPetya) outbreak and related information about previously unpublished attacks.

Anton Cherepanov30 Jun 201710 min. read


ESET research

Industroyer: Biggest threat to industrial control systems since Stuxnet

Industroyer: Biggest threat to industrial control systems since Stuxnet

ESET research

Industroyer: Biggest threat to industrial control systems since Stuxnet

ESET has analyzed a sophisticated and extremely dangerous malware, known as Industroyer, which is designed to disrupt critical industrial processes.

Anton Cherepanov and Robert Lipovsky12 Jun 20175 min. read


Ransomware

XData ransomware making rounds amid global WannaCryptor scare

XData ransomware making rounds amid global WannaCryptor scare

Ransomware

XData ransomware making rounds amid global WannaCryptor scare

A week after the global outbreak of WannaCryptor, also known as WannaCry, another ransomware, known as XData, has been making rounds.

Anton Cherepanov23 May 20172 min. read