ESET Research


2223 articles

ESET Research

A tale of two zero-days

A tale of two zero-days

ESET Research

A tale of two zero-days

Double zero-day vulnerabilities fused into one. A mysterious sample enables attackers to execute arbitrary code with the highest privileges on intended targets

Anton Cherepanov15 May 2018


One year later: EternalBlue exploit more popular now than during WannaCryptor outbreak

One year later: EternalBlue exploit more popular now than during WannaCryptor outbreak

One year later: EternalBlue exploit more popular now than during WannaCryptor outbreak

The infamous outbreak may no longer be causing mayhem worldwide but the threat that enabled it is still very much alive and posing a major threat to unpatched and unprotected systems

Ondrej Kubovič10 May 2018


Digital Security

Inside fake Interac transfer and tax refund SMS phishing

Inside fake Interac transfer and tax refund SMS phishing

Digital Security

Inside fake Interac transfer and tax refund SMS phishing

It’s tax season in Canada and scammers are using fake tax refund forms to lure victims into supplying their personal information via phishing pages

Marc-Etienne M.Léveillé09 May 2018


ESET Research

Sednit update: Analysis of Zebrocy

Sednit update: Analysis of Zebrocy

ESET Research

Sednit update: Analysis of Zebrocy

Zebrocy heavily used by the Sednit group over last two years

ESET Research24 Apr 2018


Beware ad slingers thinly disguised as security apps

Beware ad slingers thinly disguised as security apps

Beware ad slingers thinly disguised as security apps

ESET researchers have analyzed a newly discovered set of apps on Google Play, Google's official Android app store, that pose as security applications. Instead of security, all they provide is unwanted ads and ineffective pseudo-security.

Lukas Stefanko05 Apr 2018


ESET Research

Lazarus KillDisks Central American casino

Lazarus KillDisks Central American casino

ESET Research

Lazarus KillDisks Central American casino

The Lazarus Group gained notoriety especially after cyber-sabotage against Sony Pictures Entertainment in 2014. Fast forward to late 2017 and the group continues to deploy its malicious tools, including disk-wiping malware known as KillDisk, to attack a number of targets.

Peter Kálnai and Anton Cherepanov03 Apr 2018


Scams

Pingu Cleans Up: Subscription scam on Google Play

Pingu Cleans Up: Subscription scam on Google Play

Scams

Pingu Cleans Up: Subscription scam on Google Play

The game was uploaded to Google Play and attempted to trick users into unwittingly signing up for a weekly paid subscription

Lukas Stefanko29 Mar 2018


ESET Research

The Last Windows XP Security White Paper

The Last Windows XP Security White Paper

ESET Research

The Last Windows XP Security White Paper

Using the strategies and procedures we present in our paper could help prevent an attacker from taking control of your computer

Aryeh Goretsky27 Mar 2018


ESET Research

Glupteba is no longer part of Windigo

Glupteba is no longer part of Windigo

ESET Research

Glupteba is no longer part of Windigo

Latest ESET research strongly suggests that Glupteba is no longer tied to the infamous Operation Windigo.

Frédéric Vachon22 Mar 2018