Sign in

ESET Research

@esetresearch.bsky.social
1.2K followers 14 following 585 posts

Security research and breaking news straight from ESET Research Labs. welivesecurity.com/research/

PostsRepliesMedia
ESET Research @esetresearch.bsky.social · 17/09/2026
#ESETresearch discovered SparroWocky, a new backdoor of the #FamousSparrow APT group. This new malware has quickly replaced SparrowDoor as the 🇨🇳 China-aligned group’s flagship backdoor. www.welivesecurity.com/en/eset-rese... 1/6
welivesecurity.com
https://www.welivesecurity.com/en/eset-research/beware-sparrowock-backdoor-bites-commands-catch/
177
ESET Research @esetresearch.bsky.social · 16/09/2026
Heading to #LABScon2026? Join #ESETresearch’s Anton Cherepanov and Peter Strýček on Sept. 18 at 2:45 PM MST in Scottsdale, AZ for: Inside a Sandworm Attack: UAC-0099 Access and a Yggdrasil-backed Backdoor. 1/4
132
ESET Research @esetresearch.bsky.social · 15/09/2026
Join #ESETresearch’s Filip Jurčacko at #LABScon2026, on Sept. 18 at 2:15 PM MST in Scottsdale, AZ for CinderRelay: The Linux Backbone of ScarCruft’s Covert Network. 1/4
142
ESET Research @esetresearch.bsky.social · 01/09/2026
#ESETresearch hunted for additional context and found that we detected this backdoor between 2020-11 and 2023-11, targeting financial services sector in the Netherlands and Kazakhstan. 1/6 x.com/genthreatlab...
x.com
Gen Threat Labs (@GenThreatLabs) on X
A WMI subscription named "Realtek" started a 12 KB backdoor at 19:50, and it never exited. It read its C2 domain by counting spaces in a fake desktop.ini, then called a domain its operator stopped paying for in July 2021. It kept trying for 11 months. Read more -> https://t.co/z7SSDdpWAq
186
ESET Research @esetresearch.bsky.social · 27/08/2026
#ESETresearch discovered #GuardBreaker - a technique used by Russia-aligned UAC-0099 against a victim in Ukraine, interfering with AI-assisted malware analysis by deliberately triggering LLM safety mechanisms. 1/3
1106
ESET Research @esetresearch.bsky.social · 05/08/2026
At #DEFCON34, @LukasStefanko explores the real-world attack techniques targeting mobile devices and what defenders need to know to stay ahead. 1/3
151
ESET Research @esetresearch.bsky.social · 30/07/2026
In H1 2026, #ESETresearch analyzed 900,000 agentic AI skills – add-ons providing instructions that teach agents how to perform specific tasks – and found 25,000 suspicious ones and more than 3,000 outright malicious. 1/6
244
ESET Research @esetresearch.bsky.social · 28/07/2026
In H1 2026, #ESETresearch continued tracking a growing number of #EDR killers, currently counting 100+ such tools. The dominant approach is still BYOVD, with 60+ of the EDR killers abusing legitimate yet vulnerable drivers. 1/5
1104
ESET Research @esetresearch.bsky.social · 24/07/2026
QR code phishing – also known as #quishing – reached record levels in ESET telemetry in H1 2026 as attackers exploit the widespread adoption of QR codes in everyday life. The technique is evolving rapidly in terms of automation, scalability, and detection evasion. 1/5
131
ESET Research @esetresearch.bsky.social · 22/07/2026
ESET detections of #ClickFix doubled (+108%) between H2 2025 and H1 2026 as attackers expanded beyond fake CAPTCHAs to AI platforms (#AI-fix), browser extensions (#CrashFix), and cloud authentication workflows (#ConsentFix). 1/5
143
ESET Research @esetresearch.bsky.social · 14/07/2026
#ESETresearch discovered and reported to @certcc 11 old Microsoft-signed UEFI shim bootloaders that allow bypassing UEFI Secure Boot on most UEFI systems. Read about it at www.welivesecurity.com/en/eset-rese... 1/5
welivesecurity.com
Forgotten UEFI shims undermining Secure Boot
ESET researchers discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass UEFI Secure Boot by exploiting decade-old vulnerabilities.
186
ESET Research @esetresearch.bsky.social · 08/07/2026
ESET Threat Report H1 2026: thousands of malicious Agentic AI skills identified, first AI-powered Android malware appears, and ClickFix expands beyond fake CAPTCHA prompts. Attackers are rapidly adapting to new platforms and technologies . Full report: web-assets.esetstatic.com/wls/en/paper...
142
ESET Research @esetresearch.bsky.social · 25/06/2026
#ESETresearch has published a technical analysis of new malicious tools and major infrastructure changes observed in 2025 in the arsenal of the Russia-aligned #Gamaredon #APTgroup targeting Ukraine 🇺🇦. Blogpost: www.welivesecurity.com/en/eset-rese... 1/8
welivesecurity.com
Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances
ESET Research analyzes Gamaredon’s new toolset and the group’s growing reliance on legitimate online services to hide its C&C infrastructure and exfiltrate stolen data.
174
ESET Research @esetresearch.bsky.social · 18/06/2026
#ESETresearch analyzed the robust EDR-killer toolset of the RaaS gang Gentlemen. Thanks to our continued incident-level visibility, we could provide a uniquely deep view into the group’s EDR-killer development practices. www.welivesecurity.com/en/eset-rese... 1/6
welivesecurity.com
153
ESET Research @esetresearch.bsky.social · 16/06/2026
#ESETresearch has observed DeadLock ransomware expanding its use of Polygon blockchain smart contracts. Previously used only for chat proxy server address rotation, DeadLock has now added a new contract with the gang's DLS entries - a first of its kind we are aware of. 1/6
162
ESET Research @esetresearch.bsky.social · 16/06/2026
#ESETresearch discovered two as-yet undocumented Windows variants of #SprySOCKS, a previously Linux-only backdoor reportedly used by #FishMonger. We attribute the new Windows variants to #FishMonger with high confidence. www.welivesecurity.com/en/eset-rese... 1/4
welivesecurity.com
FishMonger’s arsenal upgraded: SprySOCKS for Windows
ESET researchers have discovered SprySOCKS for Windows, FishMonger’s backdoor weaponizing a kernel driver for advanced stealthiness.
175
ESET Research @esetresearch.bsky.social · 11/06/2026
#ESETresearch has discovered a supply-chain attack targeting stock investors in Vietnam, distributing SPECTRALVIPER through the update mechanism of the FireAnt Metakit stock investment platform. www.welivesecurity.com/en/eset-rese... 1/4
274
ESET Research @esetresearch.bsky.social · 28/05/2026
#ESETresearch released its latest APT Activity Report (Oct 2025–Mar 2026): 🇨🇳China-aligned groups focused on Venezuela, Gulf states, and AI & robotics industry in 🇰🇷South Korea, while 🇰🇵North Korea-aligned APTs targeted the nuclear sector. Full report: web-assets.esetstatic.com/wls/en/paper...
053
ESET Research @esetresearch.bsky.social · 20/05/2026
#ESETresearch analyzed 2025 activity of the China -aligned Webworm APT group, focusing on its evolving toolset and techniques. www.welivesecurity.com/en/eset-rese... 1/8
welivesecurity.com
Webworm: New burrowing techniques
ESET researchers describe new tools and techniques that the Webworm APT group recently added to its arsenal.
183
ESET Research @esetresearch.bsky.social · 15/05/2026
#ESETresearch uncovered a new compromise that we attribute to #FrostyNeighbor, using links in malicious PDFs sent via spearphishing attachments to target governmental organizations in Ukraine. @dmnsch welivesecurity.com/en/eset-rese... 1/5
1104
ESET Research @esetresearch.bsky.social · 07/05/2026
#ESETresearch has uncovered CallPhantom scam apps, previously available on Google Play, that claim to provide call history data for any phone number, in exchange for payment. That’s impossible – and the data is entirely fabricated. www.welivesecurity.com/en/eset-rese... 1/5
142
ESET Research @esetresearch.bsky.social · 05/05/2026
#ESETresearch uncovered a multiplatform supply-chain attack by the North Korean #ScarCruft APT group targeting the Yanbian region via backdoor-laced Windows and Android games. www.welivesecurity.com/en/eset-rese... 1/6
1115
ESET Research @esetresearch.bsky.social · 24/04/2026
Approximately a month ago, F5 published advisory on malware deployed to BIG-IP systems vulnerable to CVE-2025-53521. #ESETresearch discovered two related malware components on VirusTotal and named the threat #PoisonedRefresh. 1/6 my.f5.com/manage/s/art...
my.f5.com
myF5
134
ESET Research @esetresearch.bsky.social · 23/04/2026
#BREAKING #ESETresearch uncovered an active NGate Android malware campaign targeting Spanish speaking users, combining fake app distribution, NFC relay abuse, PIN harvesting, and a shared Devil NFC MaaS backend. The operation is tied to the Devil NFC infrastructure used in Spain since Jan 2026 1/10
192
ESET Research @esetresearch.bsky.social · 23/04/2026
#ESETresearch discovered #GopherWhisper, a new China-aligned APT group that targeted a governmental entity in Mongolia. www.welivesecurity.com/en/eset-rese... 1/7
welivesecurity.com
264
ESET Research @esetresearch.bsky.social · 21/04/2026
#ESETresearch discovered a new #NGate malware variant that abuses the legitimate #HandyPay app, which has been patched with possibly AI-generated malicious code. The campaign is ongoing and targets Android users in Brazil. www.welivesecurity.com/en/eset-rese... 1/6
welivesecurity.com
173
ESET Research @esetresearch.bsky.social · 10/04/2026
Cisco Talos recently published an analysis of an EDR killer used by the #Qilin #ransomware gang. #ESETresearch tracks this threat as #CardSpaceKiller and we recently provided additional insights in our blog www.welivesecurity.com/en/eset-rese... 1/6
welivesecurity.com
EDR killers explained: Beyond the drivers
ESET researchers dive deeper into the EDR killer ecosystem, disclosing how attackers abuse vulnerable drivers.
1114
ESET Research @esetresearch.bsky.social · 08/04/2026
#ESETresearch's Eric Howard will be presenting at Botconf. Join him in Reims, France to hear about “GopherWhisper, Uncovering an APT’s secrets through its own words” on Apr 15 at 17.15 CEST. For more information, check out www.botconf.eu/botconf-2026... 1/3
133
ESET Research @esetresearch.bsky.social · 02/04/2026
#ESETresearch has identified an Akira lookalike ransomware campaign targeting South America. The threat actor is using a Babukbased encryptor that appends the .akira extension and drops a ransom note that mimics Akira both in Tor URLs and the overall content. 1/5
1104
ESET Research @esetresearch.bsky.social · 27/03/2026
#ESETresearch has identified a Silver Fox campaign that actively takes advantage of the current annual tax filing and organizational change season in Japan, a period when companies generate a high volume of legitimate financial and HRrelated comms. www.welivesecurity.com/en/business-... 1/8
welivesecurity.com
A cunning predator: How Silver Fox preys on Japanese firms this tax season
Silver Fox is back in Japan, spoofing tax and HR emails timed to the one season when many people don’t think twice about opening them
143
ESET Research @esetresearch.bsky.social · 24/03/2026
#ESETresearch detected a recent intrusion at a University of Warsaw consistent with #Interlock ransomware gang. Thanks to early warning from our experts and the university's swift cooperation, the attack was disrupted before encryptors could be deployed. www.eset.com/pl/about/new... 1/8
eset.com
To analitycy ESET zidentyfikowali atak na Uniwersytet Warszawski
News about ESET's events and conferences, directly from the maker of legendary NOD32 technology.
164
ESET Research @esetresearch.bsky.social · 23/03/2026
In cybersecurity, labels can distract from what really matters. At #RSAC2026, #ESETresearch’s Robert Lipovský will break down recent campaigns linked to state-sponsored actors and explore how hybrid threat tactics are evolving. The session focuses on practical defender takeaways.
020
ESET Research @esetresearch.bsky.social · 20/03/2026
#ESETresearch is hiring! Passionate about geopolitics, cyberespionage and cyber threat intelligence? We have a new opening for a strategic threat intelligence analyst at our Montréal office. Come join the team! eset.wd3.myworkdayjobs.com/ESET_Externa...
eset.wd3.myworkdayjobs.com
Analyste du renseignement stratégique sur les menaces – Cyberespionnage / Strategic Threat Intelligence Analyst – Cyberespionage
Résumé du poste / Summary English version follows ------------------------------------------------------------------------------------------------------------------------------- Nous sommes à la reche...
063
ESET Research @esetresearch.bsky.social · 19/03/2026
#ESETresearch analyzed more than 80 EDR killers, seen across real-world intrusions, and used ESET telemetry to document how these tools operate, who uses them, and how they evolve beyond simple driver abuse. www.welivesecurity.com/en/eset-rese... 1/6
1139
ESET Research @esetresearch.bsky.social · 10/03/2026
#ESETresearch has analyzed the resurgence of Sednit – one of the most long‑running Russia‑aligned APT groups – now using a modern toolkit built around paired implants, BeardShell and Covenant, each using a different cloud provider for resilience. www.welivesecurity.com/en/eset-rese... 1/5
welivesecurity.com
Sednit reloaded: Back in the trenches
ESET researchers document how the Sednit APT group has reemerged with a modern toolkit centered on two paired implants – BeardShell and Covenant.
186
ESET Research @esetresearch.bsky.social · 19/02/2026
#BREAKING #ESETresearch has discovered the first known Android malware to use generative AI in its execution flow; we have named it #PromptSpy. The malware abuses Google’s #Gemini to achieve persistence on the compromised device. www.welivesecurity.com/en/eset-rese... 1/6
1107
ESET Research @esetresearch.bsky.social · 30/01/2026
#BREAKING #ESETresearch provides technical details on #DynoWiper, a data‑wiping malware used in a data‑destruction incident on December 29, 2025, affecting a company in Poland’s energy sector. www.welivesecurity.com/en/eset-rese... 1/5
welivesecurity.com
1109
ESET Research @esetresearch.bsky.social · 28/01/2026
#ESETresearch has uncovered a new #Android spyware campaign using novel romance scam tactics to target individuals in 🇵🇰 Pakistan, with an added social engineering element previously unseen in similar schemes. www.welivesecurity.com/en/eset-rese... 1/9
welivesecurity.com
Love? Actually: Fake dating app used as lure in targeted spyware campaign in Pakistan
ESET researchers discover an Android spyware campaign targeting users in Pakistan via romance scam tactics, revealing links to a broader spy operation.
184
ESET Research @esetresearch.bsky.social · 23/01/2026
#BREAKING #ESETresearch identified the wiper #DynoWiper used in an attempted disruptive cyberattack against the Polish energy sector on Dec 29, 2025. At this point, no successful disruption is known, but the malware’s design clearly indicates destructive intent. 1/5
13429
ESET Research @esetresearch.bsky.social · 16/01/2026
#ESETresearch’s Lukas Stefanko will speak at Ransomware Resilience 2026 on Mon, Jan 19 in Kuala Lumpur at 4pm local time! Discover how Android NFC threats evolved to enable unauthorized ATM withdrawals. Learn about NGate - first Android malware to execute NFC relay attack for remote ATM cash-outs.
030
ESET Research @esetresearch.bsky.social · 15/01/2026
According to ESET telemetry, threat actors keep finding new ways to exploit #NFC technology: detections surged by 78% compared to H1 2025; however, overall numbers remain low. 1/6
121
ESET Research @esetresearch.bsky.social · 13/01/2026
In 2025, #ESETresearch saw a 62% year-over-year increase in detections of fake investment and snake oil scams – tracked as HTML/Nomani – amounting to hundreds of thousands of detections and over 64,000 unique URLs blocked. 1/5
112
ESET Research @esetresearch.bsky.social · 06/01/2026
In H2 2025, #ESETresearch saw a thirtyfold increase in #CloudEyE detections, amounting to more than 100,000 hits over the course of six months. CloudEyE is a #MaaS downloader and cryptor used to conceal and deploy other malware, such as #Rescoms, #Formbook, and #Agent Tesla. 1/5
152
ESET Research @esetresearch.bsky.social · 29/12/2025
In 2025, #ESETresearch analyzed hundreds of hands-on-keyboard ransomware attacks, mostly hitting manufacturing, construction, retail, technology, and healthcare. Most of these were seen in the US (17%), Spain (5%), and France, Italy, and Canada (4% each). 1/5
144
ESET Research @esetresearch.bsky.social · 23/12/2025
#ESETresearch has revisited CVE 2025 50165, a critical remote code execution vulnerability in the WindowsCodecs.dll library when processing JPG images, one of the most widely used image format s. www.welivesecurity.com/en/eset-rese... 1/6
132
ESET Research @esetresearch.bsky.social · 19/12/2025
#ESETresearch has detected a new MSIL loader, named #BlackHawk, protected by three layers of obfuscation, all of which show strong signs of being AI-generated. 1/9
141
ESET Research @esetresearch.bsky.social · 18/12/2025
#ESETresearch has discovered a new 🇨🇳-aligned APT group, #LongNosedGoblin. This group focuses on cyberespionage and targets mainly governmental entities in Southeast Asia and Japan. www.welivesecurity.com/en/eset-rese... 1/7
welivesecurity.com
LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan
ESET researchers discovered a China-aligned APT group, LongNosedGoblin, which uses Group Policy to deploy cyberespionage tools across networks of governmental institutions.
167
ESET Research @esetresearch.bsky.social · 16/12/2025
ESET Threat Report H2 2025: NFC threats grow in scale and sophistication, ransomware victim numbers surge, and AI-powered malware becomes reality with PromptLock. The threat landscape is evolving fast – read the full report: web-assets.esetstatic.com/wls/en/paper... #ESETresearch
022
ESET Research @esetresearch.bsky.social · 05/12/2025
#ESETresearch analyzed the #Gamaredon VBScript payload recently flagged by @ClearskySec. It wipes registry Run keys, scheduled tasks, and kills processes – however, our assessment is that this is likely to clean researchers’ machines, not a shift to destructive ops. x.com/ClearskySec/... 1/4
x.com
142
ESET Research @esetresearch.bsky.social · 02/12/2025
#ESETresearch discovered a new #MuddyWater campaign targeting critical infrastructure in 🇮🇱 Israel and 🇪🇬 Egypt, using a new backdoor – MuddyViper – and a variety of post-compromise tools www.welivesecurity.com/en/eset-rese... 1/7
welivesecurity.com
MuddyWater: Snakes by the riverbank
MuddyWater targets critical infrastructure in Israel and Egypt, relying on custom malware, improved tactics, and a predictable playbook.
176