Internet of Things


492 articles

Malware

How Theola malware uses a Chrome plugin for banking fraud

How Theola malware uses a Chrome plugin for banking fraud

Malware

How Theola malware uses a Chrome plugin for banking fraud

A deep dive into Win32/Theola, one of the most malicious components of the notorious bootkit family, Win32/Mebroot.FX. Theola uses malicious Chrome browser plugins to steal money.

Aleksandr Matrosov13 Mar 2013


Malware

Sinkholing of Trojan Downloader Zortob.B reveals fast growing malware threat

Sinkholing of Trojan Downloader Zortob.B reveals fast growing malware threat

Malware

Sinkholing of Trojan Downloader Zortob.B reveals fast growing malware threat

Malware infecting 25,000 computers, mostly in the United States, pumping out 80 million spam messages per hour? ESET researchers sinkhole to investigate Win32/TrojanDownloader.Zortob.B

Sébastien Duquette08 Mar 2013


Malware

Caphaw attacking major European banks using webinject plugin

Caphaw attacking major European banks using webinject plugin

Malware

Caphaw attacking major European banks using webinject plugin

Analysis of malicious code dubbed Win32/Caphaw (a.k.a. Shylock) attacking major European banks, with ability to automatically steal money when the user is actively accessing his banking account.

Aleksandr Matrosov25 Feb 2013


Malware

NBC.com infected with malware for more than 24 hours?

NBC.com infected with malware for more than 24 hours?

Malware

NBC.com infected with malware for more than 24 hours?

NBC.com may have sent visitors to infected URLs serving up Trojan software (RedKit) for 24 hours. At the time of this blog post ESET researchers still see some related sites similarly compromised.

Stephen Cobb21 Feb 2013


Malware

Code certificate laissez-faire leads to banking Trojans

Code certificate laissez-faire leads to banking Trojans

Malware

Code certificate laissez-faire leads to banking Trojans

Technical analysis of malware that abuses code signing certificates normally used to positively identify a software publisher and to guarantee code is unchanged.

Jean-Ian Boutin21 Feb 2013


Malware

Free AV and relying on the luck of the Irish

Free AV and relying on the luck of the Irish

Malware

Free AV and relying on the luck of the Irish

ESET Ireland's Urban Schrott has blogged recently that "Research reveals nearly half of all Irish computers depend on free antivirus for protection".

David Harley09 Feb 2013


Malware

ComboFix fixed: popular utility safe to use

ComboFix fixed: popular utility safe to use

Malware

ComboFix fixed: popular utility safe to use

ESET’s threat researchers received a surprise earlier this week when they began receiving reports from ESET LiveGrid that downloads of ComboFix, a tool popular with advanced users for removing malware, were detected as being infected by a variant of the Sality virus, Win32/Sality.NBA.

Aryeh Goretsky05 Feb 2013


Malware

Scandal video of Justin Bieber: just don’t click here!

Scandal video of Justin Bieber: just don’t click here!

Malware

Scandal video of Justin Bieber: just don’t click here!

I received a “shared” messages from a friend about “a leaked scandal video of Justin Bieber and Selana Gomez” promising a “naked Justin Bieber”, with a Photoshopped picture, which we – for family-friendliness – censored a bit.

Righard Zwienenberg04 Feb 2013


Malware

What do Win32/Redyms and TDL4 have in common?

What do Win32/Redyms and TDL4 have in common?

Malware

What do Win32/Redyms and TDL4 have in common?

At the beginning of January 2013, we started tracking the interesting Win32/Redyms trojan family. Redyms is notable for changing search results from popular search engines on infected machines.

Aleksandr Matrosov04 Feb 2013