ESET Research


2256 articles

Introducing Nimfilt: A reverse-engineering tool for Nim-compiled binaries

Introducing Nimfilt: A reverse-engineering tool for Nim-compiled binaries

Introducing Nimfilt: A reverse-engineering tool for Nim-compiled binaries

Available as both an IDA plugin and a Python script, Nimfilt helps to reverse engineer binaries compiled with the Nim programming language compiler by demangling package and function names, and applying structs to strings

Rene Holt23 May 2024


To the Moon and back(doors): Lunar landing in diplomatic missions

To the Moon and back(doors): Lunar landing in diplomatic missions

To the Moon and back(doors): Lunar landing in diplomatic missions

ESET researchers provide technical analysis of the Lunar toolset, likely used by the Turla APT group, that infiltrated a European ministry of foreign affairs

Filip Jurčacko15 May 2024


Ebury is alive but unseen: 400k Linux servers compromised for cryptocurrency theft and financial gain

Ebury is alive but unseen: 400k Linux servers compromised for cryptocurrency theft and financial gain

Ebury is alive but unseen: 400k Linux servers compromised for cryptocurrency theft and financial gain

One of the most advanced server-side malware campaigns is still growing, with hundreds of thousands of compromised servers, and it has diversified to include credit card and cryptocurrency theft

Marc-Etienne M.Léveillé14 May 2024


ESET APT Activity Report Q4 2023–Q1 2024

ESET APT Activity Report Q4 2023–Q1 2024

ESET APT Activity Report Q4 2023–Q1 2024

An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q4 2023 and Q1 2024

Jean-Ian Boutin14 May 2024


eXotic Visit campaign: Tracing the footprints of Virtual Invaders

eXotic Visit campaign: Tracing the footprints of Virtual Invaders

eXotic Visit campaign: Tracing the footprints of Virtual Invaders

ESET researchers uncovered the eXotic Visit espionage campaign that targets users mainly in India and Pakistan with seemingly innocuous apps

Lukas Stefanko10 Apr 2024


Rescoms rides waves of AceCryptor spam

Rescoms rides waves of AceCryptor spam

Rescoms rides waves of AceCryptor spam

Insight into ESET telemetry statistics about AceCryptor in H2 2023 with a focus on Rescoms campaigns in European countries

Jakub Kaloč20 Mar 2024


Evasive Panda leverages Monlam Festival to target Tibetans

Evasive Panda leverages Monlam Festival to target Tibetans

Evasive Panda leverages Monlam Festival to target Tibetans

ESET researchers uncover strategic web compromise and supply-chain attacks targeting Tibetans

Anh Ho, Facundo Muñoz, Marc-Etienne M.Léveillé07 Mar 2024


Operation Texonto: Information operation targeting Ukrainian speakers in the context of the war

Operation Texonto: Information operation targeting Ukrainian speakers in the context of the war

Operation Texonto: Information operation targeting Ukrainian speakers in the context of the war

A mix of PSYOPs, espionage and … fake Canadian pharmacies!

Matthieu Faou21 Feb 2024


VajraSpy: A Patchwork of espionage apps

VajraSpy: A Patchwork of espionage apps

VajraSpy: A Patchwork of espionage apps

ESET researchers discovered several Android apps carrying VajraSpy, a RAT used by the Patchwork APT group

Lukas Stefanko01 Feb 2024