Lukas Stefanko

Lukas Stefanko

Malware Researcher


Education: Masters in Informatic Engineering of the Technical University in Kosice

Highlights of your career? Malware Researcher

Position and history at ESET? Joined ESET as a Malware Researcher in 2011

What malware do you hate the most? Adware and ransomware

Favorite activities? Gym, squash, reading

What is your golden rule for cyberspace? Be reasonably paranoid

Favorite computer game/activity? Elasto Mania


78 articles by Lukas Stefanko

Android users: Beware these popularity-faking tricks on Google Play

Android users: Beware these popularity-faking tricks on Google Play

Android users: Beware these popularity-faking tricks on Google Play

Tricksters have been misleading users about the functionality of apps by displaying bogus download numbers

Lukas Stefanko11 Jun 20183 min. read


Beware ad slingers thinly disguised as security apps

Beware ad slingers thinly disguised as security apps

Beware ad slingers thinly disguised as security apps

ESET researchers have analyzed a newly discovered set of apps on Google Play, Google's official Android app store, that pose as security applications. Instead of security, all they provide is unwanted ads and ineffective pseudo-security.

Lukas Stefanko05 Apr 20184 min. read


Pingu Cleans Up: Subscription scam on Google Play

Pingu Cleans Up: Subscription scam on Google Play

Pingu Cleans Up: Subscription scam on Google Play

The game was uploaded to Google Play and attempted to trick users into unwittingly signing up for a weekly paid subscription

Lukas Stefanko29 Mar 20183 min. read


Cryptocurrency scams on Android: Do you know what to watch out for?

Cryptocurrency scams on Android: Do you know what to watch out for?

Cryptocurrency scams on Android: Do you know what to watch out for?

The recent rise in cryptocurrency scams appearing on the Android platform in disguise has shown that such incidents are not exclusive to PCs and also highlight the importance of knowing what to look out for so you do not unintentionally take part.

Lukas Stefanko28 Feb 20184 min. read


Banking malware on Google Play targets Polish banks

Banking malware on Google Play targets Polish banks

Banking malware on Google Play targets Polish banks

Besides delivering the promised functionalities, the malicious apps can display fake notifications and login forms seemingly coming from legitimate banking applications, harvest credentials entered into the fake forms, as well as intercept text messages to bypass SMS-based 2-factor authentication.

Lukas Stefanko11 Dec 20173 min. read


New campaigns spread banking malware through Google Play

New campaigns spread banking malware through Google Play

New campaigns spread banking malware through Google Play

For a user, it can be difficult to figure out whether an app is malicious. First off it is always good only to install applications from the Google Play store, since most malware is still mainly spread through alternative stores.

Lukas Stefanko21 Nov 20176 min. read


Multi-stage malware sneaks into Google Play

Multi-stage malware sneaks into Google Play

Multi-stage malware sneaks into Google Play

In all the cases we investigated, the final payload was a mobile banking trojan. Once installed, it behaves like a typical malicious app of this kind: it may present the user with fake login forms to steal credentials or credit card details.

Lukas Stefanko15 Nov 20173 min. read


Fake cryptocurrency trading apps on Google Play

Fake cryptocurrency trading apps on Google Play

Fake cryptocurrency trading apps on Google Play

With all the hype around cryptocurrencies, cybercriminals are trying to grab whatever new opportunity they can – be it hijacking users’ computing power to mine cryptocurrencies via browsers or by compromising unpatched machines, or various scam schemes utilizing phishing websites and fake apps.

Lukas Stefanko23 Oct 20174 min. read


BankBot trojan returns to Google Play with new tricks

BankBot trojan returns to Google Play with new tricks

BankBot trojan returns to Google Play with new tricks

The Android banking trojan that we first informed about in the beginning of this year has found its way to Google Play again and contains new tricks designed to get access to the private banking information of the user.

Lukas Stefanko25 Sep 20176 min. read