Marc-Etienne M.Léveillé

Marc-Etienne M.Léveillé

Senior Malware Researcher


Education: Software Engineering student at École de Technologie supérieure

Highlights of your career? Winning the first Péter Szőr award for our research on Operation Windigo.

Position and history at ESET? Malware Researcher since January 2012

What malware do you hate the most? Malware that steals money or destroys documents

Favorite activities? Photography, Cycling, Playing the clarinet

When did you get your first computer and what kind was it? I remember playing with the TI-99 of my grandfather, but this first one I broke was his 486SX by editing the config.sys file incorrectly.

Favorite computer game/activity? CTF competitions


30 articles by Marc-Etienne M.Léveillé

Ebury is alive but unseen: 400k Linux servers compromised for cryptocurrency theft and financial gain

Ebury is alive but unseen: 400k Linux servers compromised for cryptocurrency theft and financial gain

Ebury is alive but unseen: 400k Linux servers compromised for cryptocurrency theft and financial gain

One of the most advanced server-side malware campaigns is still growing, with hundreds of thousands of compromised servers, and it has diversified to include credit card and cryptocurrency theft

Marc-Etienne M.Léveillé • 14 May 2024 • 3 min. read


Evasive Panda leverages Monlam Festival to target Tibetans

Evasive Panda leverages Monlam Festival to target Tibetans

Evasive Panda leverages Monlam Festival to target Tibetans

ESET researchers uncover strategic web compromise and supply-chain attacks targeting Tibetans

Anh Ho, Facundo Muñoz, Marc-Etienne M.Léveillé • 07 Mar 2024 • 14 min. read


A pernicious potpourri of Python packages in PyPI

A pernicious potpourri of Python packages in PyPI

A pernicious potpourri of Python packages in PyPI

The past year has seen over 10,000 downloads of malicious packages hosted on the official Python package repository

Marc-Etienne M.Léveillé and Rene Holt • 12 Dec 2023 • 7 min. read


Linux malware strengthens links between Lazarus and the 3CX supply-chain attack

Linux malware strengthens links between Lazarus and the 3CX supply-chain attack

Linux malware strengthens links between Lazarus and the 3CX supply-chain attack

Similarities with newly discovered Linux malware used in Operation DreamJob corroborate the theory that the infamous North Korea-aligned group is behind the 3CX supply-chain attack

Peter Kálnai and Marc-Etienne M.Léveillé • 20 Apr 2023 • 12 min. read


I see what you did there: A look at the CloudMensis macOS spyware

I see what you did there: A look at the CloudMensis macOS spyware

I see what you did there: A look at the CloudMensis macOS spyware

Previously unknown macOS malware uses cloud storage as its C&C channel and to exfiltrate documents, keystrokes, and screen captures from compromised Macs

Marc-Etienne M.Léveillé • 19 Jul 2022 • 11 min. read


Watering hole deploys new macOS malware, DazzleSpy, in Asia

Watering hole deploys new macOS malware, DazzleSpy, in Asia

Watering hole deploys new macOS malware, DazzleSpy, in Asia

Hong Kong pro-democracy radio station website compromised to serve a Safari exploit that installed cyberespionage malware on site visitors’ Macs

Marc-Etienne M.Léveillé and Anton Cherepanov • 25 Jan 2022 • 10 min. read


Flaw in the Quebec vaccine passport: analysis

Flaw in the Quebec vaccine passport: analysis

Flaw in the Quebec vaccine passport: analysis

ESET cybersecurity expert Marc-Étienne Léveillé analyses in-depth the Quebec vaccine proof apps VaxiCode and VaxiCode Verif.

Marc-Etienne M.Léveillé • 31 Aug 2021 • 8 min. read


Kobalos – A complex Linux threat to high performance computing infrastructure

Kobalos – A complex Linux threat to high performance computing infrastructure

Kobalos – A complex Linux threat to high performance computing infrastructure

ESET researchers publish a white paper about unique multiplatform malware they’ve named Kobalos

Marc-Etienne M.Léveillé and Ignacio Sanmillan • 02 Feb 2021 • 5 min. read


Mac cryptocurrency trading application rebranded, bundled with malware

Mac cryptocurrency trading application rebranded, bundled with malware

Mac cryptocurrency trading application rebranded, bundled with malware

ESET researchers lure GMERA malware operators to remotely control their Mac honeypots

Marc-Etienne M.Léveillé • 16 Jul 2020 • 11 min. read