Lukas Stefanko

Lukas Stefanko

Malware Researcher


Education: Masters in Informatic Engineering of the Technical University in Kosice

Highlights of your career? Malware Researcher

Position and history at ESET? Joined ESET as a Malware Researcher in 2011

What malware do you hate the most? Adware and ransomware

Favorite activities? Gym, squash, reading

What is your golden rule for cyberspace? Be reasonably paranoid

Favorite computer game/activity? Elasto Mania


70 articles by Lukas Stefanko

ESET research

New Telegram-abusing Android RAT discovered in the wild

New Telegram-abusing Android RAT discovered in the wild

ESET research

New Telegram-abusing Android RAT discovered in the wild

Entirely new malware family discovered by ESET researchers

Lukas Stefanko18 Jun 20184 min. read


ESET research

Android users: Beware these popularity-faking tricks on Google Play

Android users: Beware these popularity-faking tricks on Google Play

ESET research

Android users: Beware these popularity-faking tricks on Google Play

Tricksters have been misleading users about the functionality of apps by displaying bogus download numbers

Lukas Stefanko11 Jun 20183 min. read


ESET research

Beware ad slingers thinly disguised as security apps

Beware ad slingers thinly disguised as security apps

ESET research

Beware ad slingers thinly disguised as security apps

ESET researchers have analyzed a newly discovered set of apps on Google Play, Google's official Android app store, that pose as security applications. Instead of security, all they provide is unwanted ads and ineffective pseudo-security.

Lukas Stefanko05 Apr 20184 min. read


ESET research

Pingu Cleans Up: Subscription scam on Google Play

Pingu Cleans Up: Subscription scam on Google Play

ESET research

Pingu Cleans Up: Subscription scam on Google Play

The game was uploaded to Google Play and attempted to trick users into unwittingly signing up for a weekly paid subscription

Lukas Stefanko29 Mar 20183 min. read


ESET research

Cryptocurrency scams on Android: Do you know what to watch out for?

Cryptocurrency scams on Android: Do you know what to watch out for?

ESET research

Cryptocurrency scams on Android: Do you know what to watch out for?

The recent rise in cryptocurrency scams appearing on the Android platform in disguise has shown that such incidents are not exclusive to PCs and also highlight the importance of knowing what to look out for so you do not unintentionally take part.

Lukas Stefanko28 Feb 20184 min. read


ESET research

Banking malware on Google Play targets Polish banks

Banking malware on Google Play targets Polish banks

ESET research

Banking malware on Google Play targets Polish banks

Besides delivering the promised functionalities, the malicious apps can display fake notifications and login forms seemingly coming from legitimate banking applications, harvest credentials entered into the fake forms, as well as intercept text messages to bypass SMS-based 2-factor authentication.

Lukas Stefanko11 Dec 20173 min. read


ESET research

New campaigns spread banking malware through Google Play

New campaigns spread banking malware through Google Play

ESET research

New campaigns spread banking malware through Google Play

For a user, it can be difficult to figure out whether an app is malicious. First off it is always good only to install applications from the Google Play store, since most malware is still mainly spread through alternative stores.

Lukas Stefanko21 Nov 20176 min. read


ESET research

Multi-stage malware sneaks into Google Play

Multi-stage malware sneaks into Google Play

ESET research

Multi-stage malware sneaks into Google Play

In all the cases we investigated, the final payload was a mobile banking trojan. Once installed, it behaves like a typical malicious app of this kind: it may present the user with fake login forms to steal credentials or credit card details.

Lukas Stefanko15 Nov 20173 min. read


ESET research

Fake cryptocurrency trading apps on Google Play

Fake cryptocurrency trading apps on Google Play

ESET research

Fake cryptocurrency trading apps on Google Play

With all the hype around cryptocurrencies, cybercriminals are trying to grab whatever new opportunity they can – be it hijacking users’ computing power to mine cryptocurrencies via browsers or by compromising unpatched machines, or various scam schemes utilizing phishing websites and fake apps.

Lukas Stefanko23 Oct 20174 min. read