ESET Research


2223 articles

ESET Research

Linux/Cdorked.A: New Apache backdoor being used in the wild to serve Blackhole

Linux/Cdorked.A: New Apache backdoor being used in the wild to serve Blackhole

ESET Research

Linux/Cdorked.A: New Apache backdoor being used in the wild to serve Blackhole

Analysis of a malicious backdoor serving Blackhole exploit pack found on Linux Apache webserver compromised by malware dubbed Linux/Cdorked.A, together with remediation tool and techniques.

Pierre-Marc Bureau26 Apr 2013


Malware

Is Gapz the most complex bootkit yet?

Is Gapz the most complex bootkit yet?

Malware

Is Gapz the most complex bootkit yet?

Introducing a detailed analysis of Win32/Gapz malware in a new white paper titled: Mind the Gapz: The most complex bootkit ever analyzed?

Aleksandr Matrosov08 Apr 2013


Cybercrime

Carberp: the never ending story

Carberp: the never ending story

Cybercrime

Carberp: the never ending story

Aleksandr Matrosov reveals changes in banking Trojan Carberp relating to Java/Spy.Banker (AgentX.jar) and gaining remote access using legitimate software as backdoor components.

Aleksandr Matrosov25 Mar 2013


Scams

Job Scams: Nice Work If You Can Get It

Job Scams: Nice Work If You Can Get It

Scams

Job Scams: Nice Work If You Can Get It

The new ESET blog format must be striking a real chord with people. At any rate, job offers are just pouring in. Except that they don't seem to be jobs for security bloggers, or for web developers like the team that maintains this site.

David Harley21 Mar 2013


Malware

Win32/Cridex: Java pushes Cyprus into a Blackhole

Win32/Cridex: Java pushes Cyprus into a Blackhole

Malware

Win32/Cridex: Java pushes Cyprus into a Blackhole

Banking crisis in Cyprus is now being used in a spam campaign promoting the Blackhole exploit kit and the Win32/Cridex Trojan.

David Harley20 Mar 2013


Malware

Gapz and Redyms droppers based on Power Loader code

Gapz and Redyms droppers based on Power Loader code

Malware

Gapz and Redyms droppers based on Power Loader code

Technical analysis of Power Loader, a special bot builder for making downloaders for other malware families and yet another example of specialization and modularity in malware production.

Aleksandr Matrosov19 Mar 2013


Adobe and Microsoft release critical patches for March

Adobe and Microsoft release critical patches for March

Adobe and Microsoft release critical patches for March

Adobe and Microsoft have both released patches this week to address vulnerabilities in respective software applications and advise all users to apply the patches as soon as possible, if applicable to them.

Rob Waugh14 Mar 2013


Scams

Phishbait: not so much a Smile as a rictus

Phishbait: not so much a Smile as a rictus

Scams

Phishbait: not so much a Smile as a rictus

David Harley13 Mar 2013


Malware

How Theola malware uses a Chrome plugin for banking fraud

How Theola malware uses a Chrome plugin for banking fraud

Malware

How Theola malware uses a Chrome plugin for banking fraud

A deep dive into Win32/Theola, one of the most malicious components of the notorious bootkit family, Win32/Mebroot.FX. Theola uses malicious Chrome browser plugins to steal money.

Aleksandr Matrosov13 Mar 2013