Matthieu Faou

Matthieu Faou

Senior Malware Researcher


Education:Ingénieur civil at Mines Nancy / M. Sc. in Computer Engineering at Polytechnique Montréal

Position and history at ESET: I joined ESET in august 2016 as a Malware Researcher.

Favorite activities: Running, cycling, skiing.

What is your golden rule for cyberspace? Use your critical mindset.


22 articles by Matthieu Faou

ESET research

Operation SignSight: Supply-chain attack against a certification authority in Southeast Asia

Operation SignSight: Supply-chain attack against a certification authority in Southeast Asia

ESET research

Operation SignSight: Supply-chain attack against a certification authority in Southeast Asia

ESET researchers have uncovered a supply-chain attack on the website of a government in Southeast Asia.

Ignacio Sanmillan and Matthieu Faou17 Dec 20205 min. read


ESET research

Turla Crutch: Keeping the “back door” open

Turla Crutch: Keeping the “back door” open

ESET research

Turla Crutch: Keeping the “back door” open

ESET researchers discover a new backdoor used by Turla to exfiltrate stolen documents to Dropbox

Matthieu Faou02 Dec 20207 min. read


ESET research

XDSpy: Stealing government secrets since 2011

XDSpy: Stealing government secrets since 2011

ESET research

XDSpy: Stealing government secrets since 2011

ESET researchers uncover a new APT group that has been stealing sensitive documents from several governments in Eastern Europe and the Balkans since 2011

Matthieu Faou02 Oct 20206 min. read


ESET research

KryptoCibule: The multitasking multicurrency cryptostealer

KryptoCibule: The multitasking multicurrency cryptostealer

ESET research

KryptoCibule: The multitasking multicurrency cryptostealer

ESET researchers analyze a previously undocumented trojan that is spread via malicious torrents and uses multiple tricks to squeeze cryptocoins from its victims while staying under the radar

Matthieu Faou and Alexandre Côté Cyr02 Sep 202011 min. read


ESET research

From Agent.BTZ to ComRAT v4: A ten-year journey

From Agent.BTZ to ComRAT v4: A ten-year journey

ESET research

From Agent.BTZ to ComRAT v4: A ten-year journey

Turla has updated its ComRAT backdoor and now uses the Gmail web interface for Command and Control

Matthieu Faou26 May 20206 min. read


ESET research

Tracking Turla: New backdoor delivered via Armenian watering holes

Tracking Turla: New backdoor delivered via Armenian watering holes

ESET research

Tracking Turla: New backdoor delivered via Armenian watering holes

Can an old APT learn new tricks? Turla’s TTPs are largely unchanged, but the group recently added a Python backdoor.

Matthieu Faou12 Mar 20208 min. read


ESET research

A dive into Turla PowerShell usage

A dive into Turla PowerShell usage

ESET research

A dive into Turla PowerShell usage

ESET researchers analyze new TTPs attributed to the Turla group that leverage PowerShell to run malware in-memory only

Matthieu Faou and Romain Dumont29 May 201912 min. read


ESET research

Turla LightNeuron: An email too far

Turla LightNeuron: An email too far

ESET research

Turla LightNeuron: An email too far

ESET research uncovers Microsoft Exchange malware remotely controlled via steganographic PDF and JPG email attachments

Matthieu Faou07 May 20196 min. read


ESET research

OceanLotus: New watering hole attack in Southeast Asia

OceanLotus: New watering hole attack in Southeast Asia

ESET research

OceanLotus: New watering hole attack in Southeast Asia

ESET researchers identified 21 distinct websites that had been compromised including some particularly notable government and media sites

Matthieu Faou20 Nov 201810 min. read