ESET Research


2223 articles

ESET Research

Numando: Count once, code twice

Numando: Count once, code twice

ESET Research

Numando: Count once, code twice

The (probably) penultimate post in our occasional series demystifying Latin American banking trojans.

ESET Research17 Sep 2021


ESET Research

BladeHawk group: Android espionage against Kurdish ethnic group

BladeHawk group: Android espionage against Kurdish ethnic group

ESET Research

BladeHawk group: Android espionage against Kurdish ethnic group

ESET researchers have investigated a mobile espionage campaign that targets the Kurdish ethnic group and has been active since at least March 2020

Lukas Stefanko07 Sep 2021


COVID-19, ESET Research

Flaw in the Quebec vaccine passport: analysis

Flaw in the Quebec vaccine passport: analysis

COVID-19, ESET Research

Flaw in the Quebec vaccine passport: analysis

ESET cybersecurity expert Marc-Étienne Léveillé analyses in-depth the Quebec vaccine proof apps VaxiCode and VaxiCode Verif.

Marc-Etienne M.Léveillé31 Aug 2021


The SideWalk may be as dangerous as the CROSSWALK

The SideWalk may be as dangerous as the CROSSWALK

The SideWalk may be as dangerous as the CROSSWALK

Meet SparklingGoblin, a member of the Winnti family

Thibaut Passilly and Mathieu Tartare24 Aug 2021


ESET Research

IISerpent: Malware-driven SEO fraud as a service

IISerpent: Malware-driven SEO fraud as a service

ESET Research

IISerpent: Malware-driven SEO fraud as a service

The last in our series on IIS threats introduces a malicious IIS extension used to manipulate page rankings for third-party websites

Zuzana Hromcová11 Aug 2021


ESET Research

IISpy: A complex server-side backdoor with anti-forensic features

IISpy: A complex server-side backdoor with anti-forensic features

ESET Research

IISpy: A complex server-side backdoor with anti-forensic features

The second in our series on IIS threats dissects a malicious IIS extension that employs nifty tricks in an attempt to secure long-term espionage on the compromised servers

Zuzana Hromcová09 Aug 2021


ESET Research

IIStealer: A server-side threat to e-commerce transactions

IIStealer: A server-side threat to e-commerce transactions

ESET Research

IIStealer: A server-side threat to e-commerce transactions

The first in our series on IIS threats looks at a malicious IIS extension that intercepts server transactions to steal credit card information

Zuzana Hromcová06 Aug 2021


ESET Research

Anatomy of native IIS malware

Anatomy of native IIS malware

ESET Research

Anatomy of native IIS malware

ESET researchers publish a white paper putting IIS web server threats under the microscope

Zuzana Hromcová and Anton Cherepanov06 Aug 2021


ESET Research, Mobile Security

Some URL shortener services distribute Android malware, including banking or SMS trojans

Some URL shortener services distribute Android malware, including banking or SMS trojans

ESET Research, Mobile Security

Some URL shortener services distribute Android malware, including banking or SMS trojans

On iOS we have seen link shortener services pushing spam calendar files to victims’ devices.

Lukas Stefanko20 Jul 2021