Romain Dumont

Romain Dumont

Malware Researcher



7 articles by Romain Dumont

ESET research

Separating the bee from the panda: CeranaKeeper making a beeline for Thailand

Separating the bee from the panda: CeranaKeeper making a beeline for Thailand

ESET research

Separating the bee from the panda: CeranaKeeper making a beeline for Thailand

ESET Research details the tools and activities of a new China-aligned threat actor, CeranaKeeper, focusing on massive data exfiltration in Southeast Asia

Romain Dumont02 Oct 202411 min. read


ESET research

Analysis of two arbitrary code execution vulnerabilities affecting WPS Office

Analysis of two arbitrary code execution vulnerabilities affecting WPS Office

ESET research

Analysis of two arbitrary code execution vulnerabilities affecting WPS Office

Demystifying CVE-2024-7262 and CVE-2024-7263

Romain Dumont28 Aug 202414 min. read


ESET research

HotPage: Story of a signed, vulnerable, ad-injecting driver

HotPage: Story of a signed, vulnerable, ad-injecting driver

ESET research

HotPage: Story of a signed, vulnerable, ad-injecting driver

A study of a sophisticated Chinese browser injector that leaves more doors open!

Romain Dumont18 Jul 202423 min. read


ESET research

A dive into Turla PowerShell usage

A dive into Turla PowerShell usage

ESET research

A dive into Turla PowerShell usage

ESET researchers analyze new TTPs attributed to the Turla group that leverage PowerShell to run malware in-memory only

Matthieu Faou and Romain Dumont29 May 201912 min. read


ESET research

OceanLotus: macOS malware update

OceanLotus: macOS malware update

ESET research

OceanLotus: macOS malware update

Latest ESET research describes the inner workings of a recently found addition to OceanLotus’s toolset for targeting Mac users

Romain Dumont09 Apr 20196 min. read


ESET research

Fake or Fake: Keeping up with OceanLotus decoys

Fake or Fake: Keeping up with OceanLotus decoys

ESET research

Fake or Fake: Keeping up with OceanLotus decoys

ESET researchers detail the latest tricks and techniques OceanLotus uses to deliver its backdoor while staying under the radar

Romain Dumont20 Mar 201912 min. read


ESET research

Phishing anniversary: Here’s a free $50/month subscription

Phishing anniversary: Here’s a free $50/month subscription

ESET research

Phishing anniversary: Here’s a free $50/month subscription

Adidas “prize” used as bait in attempt to lure people into biting

Romain Dumont14 Jun 20188 min. read