Matthieu Faou

Matthieu Faou

Senior Malware Researcher


Education: Ingénieur civil at Mines Nancy / M. Sc. in Computer Engineering at Polytechnique Montréal

Position and history at ESET: I joined ESET in august 2016 as a Malware Researcher.

Favorite activities: Running, cycling, skiing.

What is your golden rule for cyberspace? Use your critical mindset.


24 articles by Matthieu Faou

Gelsemium: When threat actors go gardening

Gelsemium: When threat actors go gardening

Gelsemium: When threat actors go gardening

ESET researchers shed light on new campaigns from the quiet Gelsemium group

Matthieu Faou and Thomas Dupuy09 Jun 20214 min. read


Exchange servers under siege from at least 10 APT groups

Exchange servers under siege from at least 10 APT groups

Exchange servers under siege from at least 10 APT groups

ESET Research has found LuckyMouse, Tick, Winnti Group, and Calypso, among others, are likely using the recent Microsoft Exchange vulnerabilities to compromise email servers all around the world

Matthieu Faou, Thomas Dupuy, Mathieu Tartare10 Mar 202115 min. read


Operation SignSight: Supply-chain attack against a certification authority in Southeast Asia

Operation SignSight: Supply-chain attack against a certification authority in Southeast Asia

Operation SignSight: Supply-chain attack against a certification authority in Southeast Asia

ESET researchers have uncovered a supply-chain attack on the website of a government in Southeast Asia.

Ignacio Sanmillan and Matthieu Faou17 Dec 20205 min. read


Turla Crutch: Keeping the “back door” open

Turla Crutch: Keeping the “back door” open

Turla Crutch: Keeping the “back door” open

ESET researchers discover a new backdoor used by Turla to exfiltrate stolen documents to Dropbox

Matthieu Faou02 Dec 20207 min. read


XDSpy: Stealing government secrets since 2011

XDSpy: Stealing government secrets since 2011

XDSpy: Stealing government secrets since 2011

ESET researchers uncover a new APT group that has been stealing sensitive documents from several governments in Eastern Europe and the Balkans since 2011

Matthieu Faou02 Oct 20206 min. read


KryptoCibule: The multitasking multicurrency cryptostealer

KryptoCibule: The multitasking multicurrency cryptostealer

KryptoCibule: The multitasking multicurrency cryptostealer

ESET researchers analyze a previously undocumented trojan that is spread via malicious torrents and uses multiple tricks to squeeze cryptocoins from its victims while staying under the radar

Matthieu Faou and Alexandre Côté Cyr02 Sep 202011 min. read


From Agent.BTZ to ComRAT v4: A ten-year journey

From Agent.BTZ to ComRAT v4: A ten-year journey

From Agent.BTZ to ComRAT v4: A ten-year journey

Turla has updated its ComRAT backdoor and now uses the Gmail web interface for Command and Control

Matthieu Faou26 May 20206 min. read


Tracking Turla: New backdoor delivered via Armenian watering holes

Tracking Turla: New backdoor delivered via Armenian watering holes

Tracking Turla: New backdoor delivered via Armenian watering holes

Can an old APT learn new tricks? Turla’s TTPs are largely unchanged, but the group recently added a Python backdoor.

Matthieu Faou12 Mar 20208 min. read


A dive into Turla PowerShell usage

A dive into Turla PowerShell usage

A dive into Turla PowerShell usage

ESET researchers analyze new TTPs attributed to the Turla group that leverage PowerShell to run malware in-memory only

Matthieu Faou and Romain Dumont29 May 201912 min. read