Anton Cherepanov

Anton Cherepanov

Senior Malware Researcher


Education: Specialist degree in IT

Favorite activities? Traveling, reading

What is your golden rule for cyberspace? Use common sense

When did you get your first computer and what kind was it? In 1996 a 486DX4-100

Favorite computer game/activity? CTF games


32 articles by Anton Cherepanov

ESET research

Korplug military targeted attacks: Afghanistan & Tajikistan

Korplug military targeted attacks: Afghanistan & Tajikistan

ESET research

Korplug military targeted attacks: Afghanistan & Tajikistan

After taking a look at recent Korplug (PlugX) detections, we identified two larger scale campaigns employing this well-known Remote Access Trojan. This blog gives an overview of the first one

Robert Lipovsky and Anton Cherepanov12 Nov 20147 min. read


ESET Research

Corkow: Analysis of a business-oriented banking Trojan

Corkow: Analysis of a business-oriented banking Trojan

ESET Research

Corkow: Analysis of a business-oriented banking Trojan

Win32/Corkow is banking malware with a focus on corporate banking users. We can confirm that several thousand users, mostly in Russia and Ukraine, were victims of the Trojan in 2013. In this post, we expand on its unique functionality.

Robert Lipovsky and Anton Cherepanov27 Feb 20149 min. read


ESET research

Corkow: analysis of a business-oriented banking Trojan

Corkow: analysis of a business-oriented banking Trojan

ESET research

Corkow: analysis of a business-oriented banking Trojan

In his blog post last week, Graham Cluley introduced the Win32/Corkow banking trojan. The malware has demonstrated continuous activity in the past year, infecting thousands of users - various indicators point to the fact the malware authors are continually developing the trojan.

Robert Lipovsky and Anton Cherepanov21 Feb 201410 min. read


ESET research

Avatar rootkit: the continuing saga

Avatar rootkit: the continuing saga

ESET research

Avatar rootkit: the continuing saga

In this blog post we confirm that the Avatar rootkit continues to thrive in the wild, and disclose some new information about its kernel-mode self-defense tricks. We continue our research into this malware family.

Aleksandr Matrosov and Anton Cherepanov21 Aug 20136 min. read


ESET research

Mysterious Avatar rootkit with API, SDK, and Yahoo Groups for C&C communication

Mysterious Avatar rootkit with API, SDK, and Yahoo Groups for C&C communication

ESET research

Mysterious Avatar rootkit with API, SDK, and Yahoo Groups for C&C communication

The mysterious Avatar rootkit, detected by ESET as Win32/Rootkit.Avatar, appears to reflect a heavy investment in code development, with an API and a SDK available, plus an interesting abuse of Yahoo Groups for C&C communications.

Aleksandr Matrosov and Anton Cherepanov01 May 20139 min. read