Lukas Stefanko

Lukas Stefanko

Malware Researcher


Education: Masters in Informatic Engineering of the Technical University in Kosice

Highlights of your career? Malware Researcher

Position and history at ESET? Joined ESET as a Malware Researcher in 2011

What malware do you hate the most? Adware and ransomware

Favorite activities? Gym, squash, reading

What is your golden rule for cyberspace? Be reasonably paranoid

Favorite computer game/activity? Elasto Mania


74 articles by Lukas Stefanko

ESET research

Banking malware on Google Play targets Polish banks

Banking malware on Google Play targets Polish banks

ESET research

Banking malware on Google Play targets Polish banks

Besides delivering the promised functionalities, the malicious apps can display fake notifications and login forms seemingly coming from legitimate banking applications, harvest credentials entered into the fake forms, as well as intercept text messages to bypass SMS-based 2-factor authentication.

Lukas Stefanko11 Dec 20173 min. read


ESET research

New campaigns spread banking malware through Google Play

New campaigns spread banking malware through Google Play

ESET research

New campaigns spread banking malware through Google Play

For a user, it can be difficult to figure out whether an app is malicious. First off it is always good only to install applications from the Google Play store, since most malware is still mainly spread through alternative stores.

Lukas Stefanko21 Nov 20176 min. read


ESET research

Multi-stage malware sneaks into Google Play

Multi-stage malware sneaks into Google Play

ESET research

Multi-stage malware sneaks into Google Play

In all the cases we investigated, the final payload was a mobile banking trojan. Once installed, it behaves like a typical malicious app of this kind: it may present the user with fake login forms to steal credentials or credit card details.

Lukas Stefanko15 Nov 20173 min. read


ESET research

Fake cryptocurrency trading apps on Google Play

Fake cryptocurrency trading apps on Google Play

ESET research

Fake cryptocurrency trading apps on Google Play

With all the hype around cryptocurrencies, cybercriminals are trying to grab whatever new opportunity they can – be it hijacking users’ computing power to mine cryptocurrencies via browsers or by compromising unpatched machines, or various scam schemes utilizing phishing websites and fake apps.

Lukas Stefanko23 Oct 20174 min. read


ESET research

BankBot trojan returns to Google Play with new tricks

BankBot trojan returns to Google Play with new tricks

ESET research

BankBot trojan returns to Google Play with new tricks

The Android banking trojan that we first informed about in the beginning of this year has found its way to Google Play again and contains new tricks designed to get access to the private banking information of the user.

Lukas Stefanko25 Sep 20176 min. read


ESET research

Turn the light on and give me your passwords!

Turn the light on and give me your passwords!

ESET research

Turn the light on and give me your passwords!

ESET researchers have discovered another banking trojan on Google Play targeting Android users – this time disguised as a Flashlight widget.

Lukas Stefanko19 Apr 20175 min. read


ESET research

Real or virtual currency? Scammers accept both

Real or virtual currency? Scammers accept both

ESET research

Real or virtual currency? Scammers accept both

ESET researchers have discovered and reported scammers stealing PayPal and Paxful credentials disguised as a tool for YouTube monetization, and a bitcoin trading marketplace.

Lukas Stefanko13 Apr 20175 min. read


ESET research

If you download Minecraft mods from Google Play, read on …

If you download Minecraft mods from Google Play, read on …

ESET research

If you download Minecraft mods from Google Play, read on …

ESET researchers have discovered 87 malicious apps on Google Play disguised as mods for Minecraft.

Lukas Stefanko23 Mar 20174 min. read


ESET research

New Instagram credential stealers discovered on Google Play

New Instagram credential stealers discovered on Google Play

ESET research

New Instagram credential stealers discovered on Google Play

ESET researchers discovered 13 new Instagram credential stealers on Google play and looked into the motivations behind their fraudulent schemes.

Lukas Stefanko09 Mar 20173 min. read