Elektrine
EN
Log in Register
Paige Chat Timeline Gallery Friends Lists Email Drive DNS Resolver Domains VPN Kairo Nerve
Remote

ESET Research

@ESETresearch@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Security research and breaking news straight from ESET Research Labs.

2959 Followers
20 Following
41 Posts
Joined November 07, 2022
WWW 🔗:
https://www.welivesecurity.com
Bluesky 🦋:
https://bsky.app/profile/esetresearch.bsky.social
Twitter 𝕏:
https://twitter.com/esetresearch
Open post
ESET Research @ESETresearch@infosec.exchange
· 3d ago
#ESETresearch discovered SparroWocky, a new backdoor of the #FamousSparrow APT group. This new malware has quickly replaced SparrowDoor as the 🇨🇳 China-aligned group’s flagship backdoor. https://www.welivesecurity.com/en/eset-research/beware-sparrowock-backdoor-bites-commands-catch/ The switch to SparroWocky happened shortly after FamousSparrow started targeting Latin America almost exclusively, going mainly after governmental entities. This is most probably part of 🇨🇳 China’s reaction to the increased 🇺🇸 US interest in the region. SparroWocky is a highly modular C++ backdoor built with stealthiness in mind. Its capabilities include collecting general info about the compromised machine, exfiltrating files, and taking screenshots. It can also load and execute BOF (Beacon Object File) files. With the transition to the new backdoor, FamousSparrow started to incorporate code from open-source projects directly into its malware. Specifically, we noticed that SparroWocky uses Mbed TLS, MinHook, and COFF Loader. The developers also implemented various anti-analysis techniques: SilentMoonwalk for call spoofing, concealing thread start address from security products using the MinHook library, and a custom PE loader with integrated host process camouflage. IoCs available in our GitHub repo: https://github.com/eset/malware-ioc/tree/master/famoussparrow
5
0
4
1
Open post
ESET Research @ESETresearch@infosec.exchange
· 2mo ago

#ESETresearch discovered and reported to @certcc@infosec.exchange 11 old Microsoft-signed UEFI shim bootloaders that allow bypassing UEFI Secure Boot on most UEFI systems. Read about it at https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/
Tracked by #CVE-2026-8863 and #CVE-2026-10797, all these vulnerable shims were revoked in Microsoft’s June Patch Tuesday updates.

https://www.cve.org/CVERecord?id=CVE-2026-8863

https://www.cve.org/CVERecord?id=CVE-2026-10797
Exploiting these vulnerable shims allows execution of untrusted code at system boot by using the Bring Your Own Vulnerable Driver (#BYOVD) technique, enabling deployment of malicious UEFI bootkits on systems that trust the Microsoft Corporation UEFI CA 2011 certificate.
What makes these old shims dangerous is not a novel vulnerability, it’s that no new vulnerability is needed to bypass Secure Boot. Just an old, still-trusted, unrevoked shim and basic knowledge of how UEFI works is enough to bypass UEFI Secure Boot and deploy a UEFI bootkit.
For more details and instructions on how to verify that the dbx patches were properly applied on your system, read our blogpost:
https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/

Infosec Exchange

20
0
18
2
Open post
ESET Research @ESETresearch@infosec.exchange
· 1mo ago
In H1 2026, #ESETresearch continued tracking a growing number of #EDR killers, currently counting 100+ such tools. The dominant approach is still BYOVD, with 60+ of the EDR killers abusing legitimate yet vulnerable drivers. We expect those numbers to keep growing, as threat actors can weaponize any of thousands of available vulnerable drivers – some with public PoC exploits – while leveraging AI coding tools to adapt them, giving them a virtually endless supply. The report also details #ESETresearch findings from the Gentlemen leak. We found the gang uses a shared defense-evasion layer across its EDR killer suite – spanning in-house GentleKiller, third-party, and leaked tools – and can operationalize new BYOVD PoCs within days. While ransomware gangs are ramping up attacks (+50% YoY) only a minority of victims are willing to pay, with public reports putting that figure at just 14–28%. The total sum of ransom payments is also trending down, falling 8% from 2024 to 2025. For more on developments across the ransomware scene in H1 2026 – including gang infighting and successes in the fight against the gangs – read the full report: https://web-assets.esetstatic.com/wls/en/papers/threat-reports/eset-threat-report-h12026.pdf
4
0
5
1
Open post
ESET Research @ESETresearch@infosec.exchange
· 1mo ago
In H1 2026, #ESETresearch analyzed 900,000 agentic AI skills – add-ons providing instructions that teach agents how to perform specific tasks – and found 25,000 suspicious ones and more than 3,000 outright malicious. Many of the malicious AI skills were designed to perform red-teaming actions, such as attacking Active Directory, enumerating data, exfiltrating credentials, or gaining highly privileged, persistent access. Their instructions referenced external offensive security tools and platforms such as Impacket, Mimikatz, or BloodHound. In other words, some AI skills do not just “help” an agent – they can steer it toward offensive behavior. One skill, labeled by ESET as suspicious, was instructed to create a persistence mechanism via a JSON file and a tool for self-modification in Python. While this can improve the skill, it can also lead to unpredictable agent behavior or abuse by an attacker. Even some benign skills are problematic, such as those marked as security scanners, many of which implement basic techniques, resembling AV tools from the 1990s: catching obvious threats, but offering little protection against complex, emerging, or obfuscated attacks. Read more about the growing attack surface of agentic AI in H1 2026 ESET Threat Report https://web-assets.esetstatic.com/wls/en/papers/threat-reports/eset-threat-report-h12026.pdf
3
0
3
0
Open post
ESET Research @ESETresearch@infosec.exchange
· 2mo ago
ESET detections of #ClickFix doubled (+108%) between H2 2025 and H1 2026 as attackers expanded beyond fake CAPTCHAs to AI platforms (#AI-fix), browser extensions (#CrashFix), and cloud authentication workflows (#ConsentFix). In AI-fix attacks, attackers craft web pages that impersonate legitimate AI services, including #Anthropic Artifacts, #OpenAI Canvas, and Microsoft #Copilot Pages. The web pages display fake troubleshooting content designed to trick users into executing malicious commands. Another ClickFix evolution, CrashFix, operates in the browser environment through a fake ad blocker, causing fake browser crashes and displaying warnings of data loss to pressure victims into following malicious "quick fix" instructions. Finally, ConsentFix targets OAuth authorization tokens instead of passwords. Victims are tricked into handing over tokens that can provide access to Microsoft accounts without the need for credential theft. Read more about the evolution of ClickFix threat landscape in the latest #ESETThreatReport: https://web-assets.esetstatic.com/wls/en/papers/threat-reports/eset-threat-report-h12026.pdf
2
0
2
0
Open post
ESET Research @ESETresearch@infosec.exchange
· 6mo ago

#ESETresearch analyzed more than 80 EDR killers, seen across real-world intrusions, and used ESET telemetry to document how these tools operate, who uses them, and how they evolve beyond simple driver abuse. https://www.welivesecurity.com/en/eset-research/edr-killers-explained-beyond-the-drivers/
By following attacker workflows, we identified how affiliates reuse the same vulnerable drivers across unrelated codebases and how individual EDR killers switch drivers over time, demonstrating that driver-centric attribution is unreliable.
We emphasize that in RaaS gangs, it is the affiliates, not the operators, who select and deploy the EDR killers, complicating defense strategies, but also revealing otherwise hidden affiliations.
Our research highlights a significant rise in commercialized tooling, including packer-as-a-service ecosystems and hardened EDR killers that incorporate encrypted drivers, obfuscation, and external payload staging.
Based on these findings and the difficulties of driver blocking, we emphasize a prevention-first approach to defense that focuses on stopping the user-mode component of the EDR killer before any vulnerable driver is loaded, rather than relying solely on kernel-level blocking.
IoCs are available in our GitHub repo: https://github.com/eset/malware-ioc/tree/master/edr_killers

Infosec Exchange

14
0
13
0
Open post
ESET Research @ESETresearch@infosec.exchange
· 3mo ago

#ESETresearch analyzed the robust EDR-killer toolset of the RaaS gang Gentlemen. Thanks to our continued incident-level visibility, we could provide a uniquely deep view into the group’s EDR-killer development practices.
https://www.welivesecurity.com/en/eset-research/killing-me-gently-inside-gentlemens-edr-killer-framework/
Gentlemen was one of the most active RaaS gangs in Q1 2026. Unlike the majority of top-tier gangs, which target the US [🇺🇸], Gentlemen goes after victims across Southeast Asia, South America, and Western Europe.
Gentlemen operators develop and maintain a suite of EDR killers, combining an in-house tool, GentleKiller, with externally sourced tooling (HexKiller, ThrottleBlood, and HavocKiller). The gang applies a standardized set of defense evasion techniques across its portfolio.
GentleKiller is Gentlemen’s most prevalent EDR killer. We found eight distinct variants of the tool, each impersonating a different legitimate product. Across all builds, GentleKiller targets more than 400 processes, which we mapped with the help of AI to 48 products.
We hypothesized that GentleKiller was an internal tool in February 2026, and the recent leak of Gentlemen data confirmed our suspicions. The leaked data also allowed us to link one of Gentlemen’s affiliates to a credential stealer we named OxideHarvest.
IoCs available in our GitHub repo: https://github.com/eset/malware-ioc/tree/master/gentlemen

Infosec Exchange

4
0
7
0
Open post
ESET Research @ESETresearch@infosec.exchange
· 3mo ago

#ESETresearch discovered two as-yet undocumented Windows variants of #SprySOCKS, a previously Linux-only backdoor reportedly used by #FishMonger. We attribute the new Windows variants to #FishMonger with high confidence. https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/
Both newly discovered Windows variants, named WIN_PLUS and WIN_DRV by their authors, support communication over TCP, UDP, and WebSocket protocols, while WIN_DRV weaponizes a kernel driver for enhanced stealth.
The WIN_DRV variant creates a stealthy passive TCP backdoor and uses a kernel driver to redirect traffic to the backdoor’s hidden TCP port whenever specially crafted data is detected inside a received TCP packet.
IoCs available in our GitHub repo: https://github.com/eset/malware-ioc/tree/master/sprysocks
Read the full analysis on WeLiveSecurity: https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/

Infosec Exchange

4
0
2
0
Open post
ESET Research @ESETresearch@infosec.exchange
· 2mo ago

#ESETresearch has published a technical analysis of new malicious tools and major infrastructure changes observed in 2025 in the arsenal of the Russia-aligned #Gamaredon #APTgroup targeting Ukraine 🇺🇦. Blogpost: https://www.welivesecurity.com/en/eset-research/gamaredon-2025-leveraging-tunnels-workers-dead-drops-new-alliances
In 2025, #Gamaredon exclusively targeted Ukrainian governmental and military institutions. We observed 35 distinct #spearphishing campaigns, with activity significantly increasing in the second half of the year, as shown in the graph.
Gamaredon developed six new PowerShell tools in 2025: #PteroDee, #PteroDum, #PteroPaste, #PteroOdd, #PteroEffigy, and #PteroCache. It also resurrected the old #PteroSetup weaponizer. Most of the tools are simple downloaders built for fast deployment and flexible chaining.
#PteroPaste stands out; it combines a downloader, a USB weaponizer, and (for persistence) a runner. Early versions used rentry.co as a dead drop for encrypted payloads; later ones retrieved an encrypted C&C hostname from Dropbox and connected via tunnel services.
In 2025, #Gamaredon significantly expanded how it hides its network infrastructure. Besides #Cloudflare tunnels, it started using Cloudflare workers, Microsoft devtunnels, and Loophole, often combining several of these services as primary and fallback communication paths.
Gamaredon also heavily abused legitimate online services as dead drops for resolving C&C servers and distributing payloads, including t.me, telegra.ph, teletype.in, rentry.co, write.as, gofile.io, dev.to, mastodon.social, lesma.eu, nopaste.net, and pastee.dev. It also returned to No-IP #DDNS and abused PaaS services such as Clever Cloud and Supabase.
Our full technical analysis of #Gamaredon’s 2025 tools, infrastructure, and TTPs is available in the white paper: https://web-assets.esetstatic.com/wls/en/papers/white-papers/gamaredon-in-2025.pdf
IoCs are included in the white paper and also in our GitHub repo: https://github.com/eset/malware-ioc/tree/master/gamaredon

Infosec Exchange

3
0
4
0
Open post
ESET Research @ESETresearch@infosec.exchange
· 4mo ago

#ESETresearch uncovered a new compromise that we attribute to #FrostyNeighbor, using links in malicious PDFs sent via spearphishing attachments to target governmental organizations in Ukraine. @dmnsch@infosec.exchange https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/
The compromise chain is the newest observed to date, and starts with a blurry lure PDF file that contains a malicious link to download a document hosted on a delivery server. If the request does not come from an expected victim, the server delivers a benign PDF file.
If the victim request comes from an expected location, the server instead delivers a malicious RAR archive, containing the first stage and displays an unblurred version of the PDF file as a decoy, while executing the next stage silently.
The victim’s computer-related information is collected, and its fingerprint is sent to the C&C server. The response contains a Cobalt Strike beacon as initial implant only if the victim is of interest.
Detailed analysis is available at https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/. IoCs available in our GitHub repo: https://github.com/eset/malware-ioc/tree/master/frostyneighbor

Infosec Exchange

5
0
10
0
Open post
ESET Research @ESETresearch@infosec.exchange
· 6mo ago

#ESETresearch has analyzed the resurgence of Sednit – one of the most long‑running Russia‑aligned APT groups – now using a modern toolkit built around paired implants, BeardShell and Covenant, each using a different cloud provider for resilience. https://www.welivesecurity.com/en/eset-research/sednit-reloaded-back-trenches/
ESET researchers tied Sednit’s advanced implant team reboot to a 2024 case in Ukraine, where SlimAgent emerged – a keylogger built on the codebase of the infamous Xagent, Sednit’s flagship 2010-era backdoor.
Sednit also deployed BeardShell, an implant that executes PowerShell commands via a legitimate cloud service and uses a distinctive obfuscation technique also found in Xtunnel, Sednit’s network pivoting tool from the 2010s.
Across 2025–2026, Sednit paired BeardShell with Covenant, the final block of its modern toolkit – a heavily reworked open-source implant built for long‑term espionage with a new protocol riding on another legitimate cloud provider.
Detailed analysis of Sednit’s modern toolkits is available at https://www.welivesecurity.com/en/eset-research/sednit-reloaded-back-trenches/

Infosec Exchange

10
0
6
0
Open post
ESET Research @ESETresearch@infosec.exchange
· 3mo ago

#ESETresearch has discovered a supply-chain attack targeting stock investors in Vietnam, distributing SPECTRALVIPER through the update mechanism of the FireAnt Metakit stock investment platform. https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/
ESET telemetry suggests that the attack started around October 2025 and ended in March 2026. In our investigation, only a small subset of exposed users received the final backdoor, SPECTRALVIPER, suggesting selective targeting.
Detailed analysis of the supply chain, the contour of OceanLotus’s victimology in recent years, and the architecture of its signature backdoor, SPECTRALVIPER, is available at:
https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/
IoCs available in our GitHub repo: https://github.com/eset/malware-ioc/tree/master/oceanlotus

Infosec Exchange

3
0
2
0
Open post
ESET Research @ESETresearch@infosec.exchange
· 7mo ago

#BREAKING #ESETresearch identified the wiper #DynoWiper used in an attempted disruptive cyberattack against the Polish energy sector on Dec 29, 2025. At this point, no successful disruption is known, but the malware’s design clearly indicates destructive intent.
#ESETresearch attributes the attack to the Russia‑aligned #Sandworm APT group with medium confidence, based on strong overlaps in behavior and TTPs with multiple earlier Sandworm-linked wiper operations investigated by our team.
The attack struck during peak winter and the 10‑year anniversary of Sandworm’s 2015 attack on Ukraine’s power grid - the first malware-driven blackout, leaving ~230,000 people without electricity.
#ESET detects DynoWiper as Win32/KillFiles.NMO. Customers of our private ESET Threat Intelligence APT reports have already received additional technical details and IOCs to support rapid detection and response. IoC: 4EC3C90846AF6B79EE1A5188EEFA3FD21F6D4CF6
We continue to investigate the incident and broader implications. As new evidence or links to additional Sandworm activity emerge, we will share further updates to help defenders protect critical sectors.

13
2
17
0
Open post
ESET Research @ESETresearch@infosec.exchange
· 3mo ago

#ESETresearch has observed DeadLock ransomware expanding its use of Polygon blockchain smart contracts. Previously used only for chat proxy server address rotation, DeadLock has now added a new contract with the gang's DLS entries - a first of its kind we are aware of.
DeadLock’s HTML ransom notes are interactive, providing access to a Session-style messaging client and now also the DLS, that is displayed to victims directly embedded in the HTML ransom note, fetched on the fly from the smart contracts.
The "Blog" smart contract, containing the DLS, had its first transaction on 2026-02-08 and has since accumulated 75 victims. ESET researchers first saw the contract used in a ransom note in March 2026. The older chat proxy contract has been active since August 2025.
On top of the on-chain DLS, DeadLock recently registered a clearweb domain deadlock.liveblog365[.]com. The site works the same way as their HTML ransom notes - both query the Blog smart contract for victim data, combining blockchain resilience with clearweb accessibility.
For prior analysis of DeadLock's Polygon smart contract infrastructure, see:
@ThreatScene: threatscene.com/blog-update/ransomware-over-webchat-deadlock/
@GroupIB_TI: group-ib.com/blog/deadlock-ransomware-polygon-smart-contracts
H/T @ecrime_ch@infosec.exchange for indexing the clearweb DLS.
DLS smart contract: 0x757984507c82c8dA1d3969c535dB5706eEE6426C
Chat proxy smart contract: 0x8EF7c3e531d871D3B9D559722DE77EB1dEc19dAe

Infosec Exchange

2
0
1
0
Open post
ESET Research @ESETresearch@infosec.exchange
· 4mo ago

#ESETresearch analyzed 2025 activity of the 🇨🇳-aligned Webworm APT group, focusing on its evolving toolset and techniques. https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/
Webworm’s latest campaigns mark a shift in its targeting away from Asia toward Europe and Africa. In 2025, it attacked governmental entities in 🇧🇪 Belgium, 🇮🇹 Italy, 🇷🇸 Serbia, 🇪🇸 Spain and 🇵🇱 Poland, as well as a university in 🇿🇦 South Africa.
The group seems to have stopped deploying the Trochilus and McRat backdoors; instead, it introduced new, custom-made backdoors: EchoCreep, which uses Discord for C&C communication, and GraphWorm, which uses Microsoft Graph API for the same purpose.
On an operator server, we discovered a directory listing with open-source utilities used to scrape victim web server files and directories, and to search for vulnerabilities within. One directory contained reconnaissance commands used against more than 50 unique targets.
While going over EchoCreep’s Discord messages, we uncovered a GitHub repository that was a direct fork of the legitimate WordPress repository. Webworm uses it as a file stager for its tools and malware.
The group also continues to employ various proxy utilities. In 2025, it added four custom-made ones to its arsenal: WormFrp, ChainWorm, SmuxProxy, and WormSocket.
We presented these findings at #ESETWorld2026 in a talk titled: China-aligned Webworm targets EU countries, abuses Discord and government-hosted public apps.
IoCs available in our GitHub repo: https://github.com/eset/malware-ioc/tree/master/webworm

Infosec Exchange

3
0
3
0
Open post
ESET Research @ESETresearch@infosec.exchange
· 6mo ago

#ESETresearch detected a recent intrusion at a University of Warsaw consistent with #Interlock ransomware gang. Thanks to early warning from our experts and the university's swift cooperation, the attack was disrupted before encryptors could be deployed. https://www.eset.com/pl/about/newsroom/press-releases/news/to-analitycy-eset-zidentyfikowali-atak-na-uniwersytet-warszawski/
According to our investigation, the artifacts and infrastructure overlap with Interlock activity. We observed the use of #NodeSnake RAT and Interlock RAT, both of which are referenced in CISA’s #StopRansomware advisory. https://www.cisa.gov/sites/default/files/2025-07/aa25-203a-stopransomware-interlock-072225.pdf
The intrusion is a continuation of the threat actor’s campaign described in the April 2025 QorumCyber report, using an updated toolset. Our telemetry shows the actor targeted the education vertical in additional regions as well. https://www.quorumcyber.com/wp-content/uploads/2025/04/20250416-Higher-Education-Sector-RAT-MP.pdf
New in this campaign, we saw an updated, more-heavily-obfuscated NodeSnake RAT build. The updated version leverages WebSocket instead of the previously used HTTP. C&C infrastructure remains proxied mostly over Cloudflare’s *.trycloudflare[.]com infrastructure.
NodeSnake RAT was used to deliver its own updates and additional payloads including the legitimate tool AzCopy (for exfiltration), a PowerShell SystemBC proxy and a ConnectWise MSI installer (RMM).
Interlock RAT (adobe.log) is executed via a scheduled task Microsoft\Windows\Defrag\ScheduledDefrg, masquerading as a defragmentation task.
IoCs:
Interlock RAT
CEB69DFDD768AA08B86F1D5628BD3A38C1FE8C1F
Interlock RAT C&Cs:
172.86.68[.]64
23.227.203[.]123
77.42.75[.]119
NodeSnake C&Cs:
deserve-coordinated-fairy-tier.trycloudflare[.]com
survey-tennessee-blind-corners.trycloudflare[.]com
dvd-diagnostic-oakland-signals.trycloudflare[.]com
practitioners-ons-boom-utc.trycloudflare[.]com
donnellykilbakk[.]cc
PowerShell SystemBC C&C:
91.99.97[.]247
ConnectWise C&C:
partyglacierhip[.]top

Infosec Exchange

5
0
4
0
Open post
ESET Research @ESETresearch@infosec.exchange
· 2mo ago
ESET Threat Report H1 2026: thousands of malicious Agentic AI skills identified, first AI-powered Android malware appears, and ClickFix expands beyond fake CAPTCHA prompts. Attackers are rapidly adapting to new platforms and technologies . Full report: https://web-assets.esetstatic.com/wls/en/papers/threat-reports/eset-threat-report-h12026.pdf
1
0
1
0
Open post
ESET Research @ESETresearch@infosec.exchange
· 3mo ago

#ESETresearch released its latest APT Activity Report (Oct 2025–Mar 2026): 🇨🇳China-aligned groups focused on Venezuela, Gulf states, and AI & robotics industry in 🇰🇷South Korea, while 🇰🇵North Korea-aligned APTs targeted the nuclear sector. Full report: https://web-assets.esetstatic.com/wls/en/papers/threat-reports/eset-apt-activity-report-q4-2025-q1-2026.pdf

Infosec Exchange

2
0
2
0
Open post
ESET Research @ESETresearch@infosec.exchange
· 5mo ago

#ESETresearch has identified an Akira lookalike ransomware campaign targeting South America. The threat actor is using a Babukbased encryptor that appends the .akira extension and drops a ransom note that mimics Akira both in Tor URLs and the overall content.
The ransom note is almost identical to Akira’s with some parts omitted. The crucial difference is the planted Tor link that is not under Akira’s control. The ransom note is also named ___________akira_readme.txt (the leading underscores is another difference to real Akira).
The ransom note also references the official Akira leak sites (Dedicated Leak Sites - DLSs), but plants a custom Tor link for the ransom payment negotiation. The link is currently not working. Notably, Akira itself warns about potential copycats on their DLS.
Aside from the encryptor, the threat actor utilized Mimikatz and exfiltrated sensitive data using rclone. Copycat attempts like this one are rare, but not unheard of. Victims should never trust threat actors based solely on their claims.
IoCs: 9B484760D563B3768EAA93802AFD4EA9C3F92780 (win.exe)
https://akirad2pbdhjlczfbunj4jbbv7ox4ixdti3xq35mqxsl3yzjqhg3lmqd[.]onion

Infosec Exchange

4
0
6
1
Open post
ESET Research @ESETresearch@infosec.exchange
· 5mo ago

#ESETresearch has identified a Silver Fox campaign that actively takes advantage of the current annual tax filing and organizational change season in Japan, a period when companies generate a high volume of legitimate financial and HRrelated communications. https://www.welivesecurity.com/en/business-security/cunning-predator-how-silver-fox-preys-japanese-firms-tax-season/
In this operation, Silver Fox sends tailored spearphishing emails crafted to look like one of such communication. To make the emails appear authentic, the attackers often include the name of the targeted company directly in the subject line.
The sender fields often impersonate employees at the targeted companies. This indicates Silver Fox performs reconnaissance before attacking. Using names that the targets are likely to recognize, makes it more difficult to distinguish the messages from real internal notifications.
The emails typically contain either a malicious attachment or a link leading to a malicious file. The files are named to resemble common HR, financial, or tax-related documents.
Opening the malicious files drops ValleyRAT, a remote access trojan that Silver Fox has used across multiple campaigns. Once deployed, it enables the actor to take remote control of the machine and harvest sensitive information. ESET products detect this malware as Win64/Valley.
Note that even though ESET observes the most activity in Japan, Silver Fox also currently operates in Taiwan, India, Indonesia, Australia, the United Kingdom, and Brazil. IoCs available in our GitHub repo: https://github.com/eset/malware-ioc/tree/master/silver_fox

Infosec Exchange

4
0
5
0
Open post
ESET Research @ESETresearch@infosec.exchange
· 5mo ago

Cisco Talos recently published an analysis of an EDR killer used by the #Qilin #ransomware gang. #ESETresearch tracks this threat as #CardSpaceKiller and we recently provided additional insights in our blog https://www.welivesecurity.com/en/eset-research/edr-killers-explained-beyond-the-drivers/
While we didn’t obtain direct evidence, we strongly believe that CardSpaceKiller is offered as a product on the darknet for reasons covered in the blog. We’ve detected it used by #Akira, #Medusa, and #MedusaLocker affiliates too.
The packer (identified as VX Crypt by Sophos) is not unique to this killer; it’s a PaaS used with other malware like #BumbleBee. But it is the single choice for the killer’s developer; unprotected samples were used only in 2025-02 https://www.sophos.com/en-us/blog/inside-shanya-a-packer-as-a-service-fueling-modern-attacks/
Beyond msimg32.dll mentioned in the Talos‘ blog, VX Crypt also names the payloads rtworkq.dll and version.dll, all abusing DLL side-loading for evasion. We’ve also observed an EXE variant in the wild, named 0th3r_av5.exe https://blog.talosintelligence.com/qilin-edr-killer/
Additional IoCs: 127B50C8185986A52AE66BF6E7E67A6FD787C4FC (version.dll)

22640D48F2E2A56C7A0708356B2B6990676B58B3 (version.dll)

3030DF03F36EC4C96B36B2E328FE3D7D9082811A (0th3r_av5.exe)

52D0358FF84295D231BC180CEDFDAF96631D67B4 (rtworkq.dll)
5D3CF785A440133A899412B800742716287D0B06 (msimg32.dll)

A3BDB419703A70157F2B7BD1DC2E4C9227DD9FE8 (0th3r_av5.exe)

3
0
3
0
Open post
ESET Research @ESETresearch@infosec.exchange
· 5mo ago

#ESETresearch's Eric Howard will be presenting at Botconf. Join him in Reims, France to hear about “GopherWhisper, Uncovering an APT’s secrets through its own words” on Apr 15 at 17.15 CEST. For more information, check out https://www.botconf.eu/botconf-2026/#id_schedule
New China‑aligned APT GopherWhisper: first seen in 2025 deploying backdoor LaxGopher inside a Mongolian government institution. The group’s backdoors abuse legit services for C2 (Slack, Discord, Microsoft Graph). Hardcoded tokens let us peek into ops and post‑compromise activity.
We recovered 5K+ C2 messages (activity since 2023‑11), mapped tools (LaxGopher, RatGopher, BoxOfFriends, JabGopher, FriendDelivery, CompactGopher, SSLORDoor), and saw exfil via file.io, presentation will provide defender tips. Full research will be later released on WeLiveSecurity.com

Infosec Exchange

3
0
2
0
Open post
ESET Research @ESETresearch@infosec.exchange
· 4mo ago

Approximately a month ago, F5 published advisory on malware deployed to BIG-IP systems vulnerable to CVE-2025-53521. #ESETresearch discovered two related malware components on VirusTotal and named the threat #PoisonedRefresh.
https://my.f5.com/manage/s/article/K000160486
First, umount infects /usr/sbin/httpd by prepending a malicious ELF binary to the legitimate binary, as long as the first command-line argument is /mnt/tm_install/. The sample is expected to be run as root and will disable SELinux.
Interestingly, for /mnt/tm_install/usr, the sample also infects umount, httpd, and rc.local files located within the tm_install directory. This is presumably done to infect the installation media, allowing the malware to persist and spread to other BIG-IP systems.
Although attribution is still undecided, the initial access vector and deployed malware suggest a sophisticated threat actor. Note that benign functionality is preserved. Therefore, follow F5's security advisory to identify potential compromise.
IoC:
🚨PoisonedRefresh
E5066C2490197FFBE0E916BC232114A61CB09A16
7A2FC3510B502D8FDC2548F907AF08308840851C
E2D6C74E815A07F555CD678F7AD0EFEDEAE98ECD

Infosec Exchange

2
0
1
0
Open post
ESET Research @ESETresearch@infosec.exchange
· 5mo ago

#BREAKING #ESETresearch uncovered an active NGate Android malware campaign targeting Spanish speaking users, combining fake app distribution, NFC relay abuse, PIN harvesting, and a shared Devil NFC MaaS backend. The operation is tied to the Devil NFC infrastructure used in 🇪🇸 Spain since January 2026
Distribution: We identified a domain distributing NGate malware targeting Spanish speaking users, with sample uploaded to VirusTotal.
The malware is disguised as a NFC Security app called “Seguridad NFC – Bloqueador de Cargos” and delivered through a fake Google Play website:
https://piaystore.it[.]com
Domain was registered on 2026 04 18, resolving to 65.109.108[.]183
Shared infrastructure & MaaS:
The same IP (65.109.108[.]183) also hosts:
https://devilxclusive[.]lol
This domain exposes an admin panel branded “Devil NFC”, which appears to provide NGate as NFC MaaS, linking distribution and backend operations.
NGate functionality:
The app can exfiltrate SMS messages and load a phishing screen from its hardcoded C&C server, mimicking generic account lock warning and instructing victims to hold their payment card against the back of the smartphone and then enter the card’s PIN.
Both NFC data and PINs are exfiltrated to the C&C server.
Bank‑branded NFC phishing:
NGate supports custom bank‑branded NFC phishing templates, embedded at build time by the operator.
In this campaign, we observed templates impersonating Santander Bank, shifting from generic warnings to targeted bank abuse.
NFC relay:
The NFC relay server – to transfer NFC data - is dynamically returned via C&C and decrypted as 65.109.108[.]183:5568 — the same IP used for hosting and distribution.
Session & victim tracking:
NGate requests a session ID from C&C, receiving an incrementing value representing number of connections (e.g., "conexion_id": 854).
This appears to track successful C&C connections, not completed fraud.
Separately, when a victim submits their card PIN, the server returns another incrementing ID — 40 at analysis time — representing confirmed cases where victims tapped a card and entered their PIN.
Historical connection
We have identified that this activity targeteing Spanish speaking users directly connects to earlier Devil NFC MaaS campaigns impersonating:
• Jan 2026: Shein app
• Feb 2026: CaixaBank and Santander Protect, and Seguridad Integral
• Mar 2026: Unicaja Key distributed via SMS links and Dispositivo Seguro
• Apr 2026: Unicaja Protect, Seguridad NFC
Unicaja publicly warned customers about this campaign https://x.com/UnicajaBanco/status/2033877029234377163
Victimology:
We detected Caixabank Protect, Seguridad Integral, and Unicaja Key malicious apps in Feb and Mar 2026 on Android devices in Spain
IoCs:
IoCs are available in our GitHub repo: https://github.com/eset/malware-ioc/tree/master/ngate

2
0
5
0
Open post
ESET Research @ESETresearch@infosec.exchange
· 7mo ago

#BREAKING #ESETresearch provides technical details on #DynoWiper, a data‑wiping malware used in a data‑destruction incident on December 29, 2025, affecting a company in Poland’s energy sector.
https://www.welivesecurity.com/en/eset-research/dynowiper-update-technical-analysis-attribution/
@CERT_Polska_en did an excellent job investigating the incident and published a detailed analysis in a report:
https://cert.pl/en/posts/2026/01/incident-report-energy-sector-2025/
#ESETresearch attributes the attack to the 🇷🇺 Russia‑aligned #Sandworm APT group with medium confidence, based on strong overlaps in behavior and TTPs with multiple earlier Sandworm attacks. Specifically, DynoWiper operates in a broadly similar fashion to the ZOV wiper, which we attribute to Sandworm with high confidence.
IoCs available in our GitHub repo: https://github.com/eset/malware-ioc/tree/master/dynowiper

4
1
6
1
Open post
ESET Research @ESETresearch@infosec.exchange
· 7mo ago

#ESETresearch has uncovered a new #Android spyware campaign using novel romance scam tactics to target individuals in 🇵🇰 Pakistan, with an added social engineering element previously unseen in similar schemes. https://www.welivesecurity.com/en/eset-research/love-actually-fake-dating-app-used-lure-targeted-spyware-campaign-pakistan/
The spyware used in the campaign, which we named #GhostChat, uses the icon of a legitimate chat app. After installation from unknown sources, login credentials and unlock codes are required to access the app and individual chat profiles, respectively.
The credentials and codes are not processed by any server and are hardcoded in the app, implying that they are probably distributed along with the app by the threat actor.
This impression of personalization and exclusive access is rarely seen in mobile threat campaigns and suggests a highly targeted social engineering effort. Under its façade lies the true purpose of the app: data exfiltration.
Upon installation, GhostChat immediately requests permissions and begins exfiltrating data – even before login. It continuously monitors new images, scans for documents every five minutes, and exfiltrates sensitive information from the device.
The GhostChat campaign is part of a broader, multiplatform, spy operation. In related activity, victims are lured into scanning QR codes on websites impersonating Pakistan’s Ministry of Defence, thereby giving the threat actors access to private #WhatsApp communications.
The same domain (buildthenations[.]info), also used to impersonate the Ministry of Defence website, mimics Pakistan’s Emergency Response Team and delivers a payload via #ClickFix, targeting desktop devices.
The operation blends mobile spyware, social engineering, and desktop exploitation, targeting users in 🇵🇰 Pakistan. Despite its specific targeting, there are insufficient similarities in TTPs to attribute this campaign to any known threat actor at this point.
IoCs available in our GitHub repo: https://github.com/eset/malware-ioc/tree/master/ghostchat
Read the full analysis on WeLiveSecurity: https://www.welivesecurity.com/en/eset-research/love-actually-fake-dating-app-used-lure-targeted-spyware-campaign-pakistan/

Infosec Exchange

4
0
2
0
Open post
ESET Research @ESETresearch@infosec.exchange
· 9mo ago

#ESETresearch has revisited CVE 2025 50165, a critical remote code execution vulnerability in the WindowsCodecs.dll library when processing JPG images, one of the most widely used image format s. https://www.welivesecurity.com/en/eset-research/revisiting-cve-2025-50165-critical-flaw-windows-imaging-component/
The vulnerability, found by Zscaler in May 2025, stems from an uninitialized pointer dereference during the compression process of 12-bit precision JPG streams.
Our deep dive analysis took us on a journey inside the JPG file format and Windows Imaging Component internals, allowing us to reproduce the crash and find an alternative vulnerable code path, stemming from the same problem but for 16-bit precision JPG streams.
Our investigation revealed that the vulnerable component uses the open-source library libjpeg-turbo, in which similar issues were found and resolved in December 2024.
Studying libjpeg-turbo commits enabled us to explore other potentially vulnerable code paths and reassess exploitability: the flaw, although ranked critical by Microsoft, is likely unexploitable.
Finally, while we studied the immediate patch, we also looked at newer versions of WindowsCodecs.dll and observed that additional mitigations were subsequently implemented. Time to patch!

Infosec Exchange

4
0
1
0
Open post
ESET Research @ESETresearch@infosec.exchange
· 9mo ago

#ESETresearch has detected a new MSIL loader, named #BlackHawk, protected by three layers of obfuscation, all of which show strong signs of being AI-generated.
The first layer is a VBS script. It stands out due to its clean formatting, overly complex implementation, meaningful function and variable names, and clear comments and sectioning, features typical for AI-generated code.
The second layer is a PowerShell script that begins with comments accurately describing its functionality, and multiple implementations of the same decryption function, along with multiple execution methods – another potential residue of AI fine-tunning.
The third layer is another PowerShell script containing a base64-encoded BlackHawk loader and the final payload. AI-generated artifacts are evident in this stage too, similar to those observed in the earlier layers.
ESET researchers have observed BlackHawk being used in spearphishing campaigns to deliver #AgentTesla, targeting hundreds of endpoints in Romanian small and medium-sized companies.
The name BlackHawk is based on the main class name of the loader (BLACKHAWK.DOWN), version information, and a PDB file (blackhawk.pdb), all indicating the developer also using this naming.
Researchers at K7 have also observed #BlackHawk being deployed in another campaign, with only slight variations in the obfuscation layers across different samples. This offers further evidence of prompt engineering techniques used to optimize stealth. https://labs.k7computing.com/index.php/phantom-3-5-initial-vector-analysis-forensics/
This discovery illustrates another area that attackers can potentially improve by using generative AI - namely code protection. In the case of BlackHawk, however, the deployment of these techniques was rather heavy-handed.
IoCs: 39C2E88D3F8E5EB5F2829420861209C5B33F26A1 The first layer of BlackHawk 86B55EFF8EE238161EF34A99086F6D1E482595E4 BlackHawk loader

Infosec Exchange

4
0
0
0
Open post
ESET Research @ESETresearch@infosec.exchange
· 9mo ago

#ESETresearch has discovered a new 🇨🇳-aligned APT group, #LongNosedGoblin. This group focuses on cyberespionage and targets mainly governmental entities in Southeast Asia and Japan. https://www.welivesecurity.com/en/eset-research/longnosedgoblin-tries-sniff-out-governmental-affairs-southeast-asia-japan/
LongNosedGoblin uses Group Policy to deploy malware and move laterally across the compromised network. Its toolset consists mainly of malicious C#/.NET applications.
One of them is NosyHistorian, used to gather the victim’s browser history and decide where to deploy further malware. This includes NosyDoor, a backdoor that uses cloud services for C&C. NosyDoor also employs living-off-the-land techniques in its execution chain.
Our blogpost describes the discovery of LongNosedGoblin, goes over its known campaigns, and provides a detailed analysis of the group’s toolset.
We also recently presented these findings at #AVAR2025 in a talk titled Sniffing Around: Unmasking the LongNosedGoblin operation in Southeast Asia and Japan.
https://events.aavar.org/cybersecurity-conference/index.php/sniffing-around-unmasking-the-longnosedgoblin-operation-in-southeast-asia-and-japan/
IoCs available in our GitHub repo: https://github.com/eset/malware-ioc/tree/master/longnosedgoblin

Infosec Exchange

4
0
7
0
Open post
ESET Research @ESETresearch@infosec.exchange
· 4mo ago

#ESETresearch has uncovered CallPhantom scam apps, previously available on Google Play, that claim to provide call history data for any phone number, in exchange for payment. That’s impossible – and the data is entirely fabricated. @lukasstefanko@bird.makeup https://www.welivesecurity.com/en/eset-research/fake-call-logs-real-payments-how-callphantom-tricks-android-users/
We identified 28 CallPhantom apps on Google Play, collectively downloaded 7.3+ million times before we reported them to Google. After victims had paid, the apps generated random phone numbers and matched them with hardcoded names, call times, and durations.
The CallPhantom apps we analyzed mainly targeted Android users in 🇮🇳 India and the broader Asia-Pacific region – many came with India’s +91 country code preselected and support UPI, a payment system used primarily in India.
While some apps requested payment in the form of Google Play subscriptions, others redirected users to third party payment apps or requested card details directly in the app – complicating refund efforts and exposing victims to financial risk.
IoCs are available in our GitHub repo: https://github.com/eset/malware-ioc/tree/master/callphantom
Read the full analysis on WeLiveSecurity: https://www.welivesecurity.com/en/eset-research/fake-call-logs-real-payments-how-callphantom-tricks-android-users/

Infosec Exchange

1
0
2
0
Open post
ESET Research @ESETresearch@infosec.exchange
· 4mo ago

#ESETresearch uncovered a multiplatform supply-chain attack by the 🇰🇵 #ScarCruft APT group targeting the Yanbian region via backdoor-laced Windows and Android games. https://www.welivesecurity.com/en/eset-research/rigged-game-scarcruft-compromises-gaming-platform-supply-chain-attack/
In the attack, likely ongoing since late 2024, ScarCruft compromised sqgame, a video game platform used by ethnic Koreans living in the #Yanbian region in China – home to ethnic Koreans and a crossing point for North Korean refugees and defectors.
The sqgame Windows client was compromised through a malicious update serving the #RokRAT backdoor, which deployed ScarCruft’s more advanced #BirdCall backdoor. Android games were trojanized with the Android version of BirdCall – a new tool in ScarCruft’s arsenal.
The Android version of BirdCall implements a subset of the capabilities of its Windows counterpart – it collects contacts, SMS messages, call logs, and various documents, media files, and private keys. It can also take screenshots and record surrounding audio.
We believe that this campaign is probably aimed at collecting information on individuals in the Yanbian region and deemed of interest to the 🇰🇵 regime.
IoCs available in our GitHub repo: https://github.com/eset/malware-ioc/tree/master/scarcruft

Read the full analysis on WeLiveSecurity: https://www.welivesecurity.com/en/eset-research/rigged-game-scarcruft-compromises-gaming-platform-supply-chain-attack/#article-2

Infosec Exchange

1
0
3
0
Open post
ESET Research @ESETresearch@infosec.exchange
· 8mo ago

In 2025, #ESETresearch analyzed hundreds of hands-on-keyboard ransomware attacks, mostly hitting manufacturing, construction, retail, technology, and healthcare. Most of these were seen in the US (17%), Spain (5%), and France, Italy, and Canada (4% each).
Publicly reported victim numbers grew by almost 40% YoY (acc to ecrime.ch), and we expect to see that growth continue in 2026. #Qilin and #Akira gangs were, and probably will remain, the leading RaaS, but we think #Warlock gang is the one to watch closely.
Warlock, a newcomer operating as a closed group, stands out for its technical skill, with quick adoption of new intrusion techniques and novel attack chains, such as the abuse of vulnerable #Velociraptor chained with VS Code to establish a stealthy remote connection.
Headline-producing vectors such as SIM swaps, vishing, and 0-days will grab media attention in 2026, but most incidents will still start by exploiting weak passwords, unpatched systems, open RDP ports, and edge device vulnerabilities. EDR killers will keep surfacing.
For additional predictions, the most expensive ransomware attack of 2025, or the good news corner, read the whole ransomware section in #ESETThreatReport https://web-assets.esetstatic.com/wls/en/papers/threat-reports/eset-threat-report-h22025.pdf

Infosec Exchange

3
0
2
0
Open post
ESET Research @ESETresearch@infosec.exchange
· 5mo ago

#ESETresearch discovered #GopherWhisper, a new China-aligned APT group that targeted a governmental entity in Mongolia. https://www.welivesecurity.com/en/eset-research/gopherwhisper-burrow-full-malware/
The group wields a wide array of tools mostly written in Go, using injectors and loaders to deploy and execute various backdoors in its arsenal.
Of the seven tools we discovered, four are backdoors – LaxGopher, RatGopher, and BoxOfFriends are written in Go, and SSLORDoor in C++. The rest comprise the injector JabGopher, the Go-based exfiltration tool CompactGopher, and the loader FriendDelivery.
GopherWhisper abuses legitimate services, notably #Discord, #Outlook, #Slack, and file.io for C&C communication and exfiltration. We managed to extract thousands of Slack and Discord C&C messages, gaining insight into the inner workings of the group.
Timestamp inspection of the messages showed that the bulk were sent during working hours in the UTC+8 time zone, which aligns with China. We also discovered that the group’s Slack and Discord servers were being used as C&Cs for LaxGopher and RatGopher.
We presented these findings on April 15th, at the #Botconf2026 conference in a talk titled Meet GopherWhisper: Uncovering an APT’s secrets through its own words.
Our detailed analysis of GopherWhisper’s toolset and C&C traffic is also available in our latest white paper: https://web-assets.esetstatic.com/wls/en/papers/white-papers/gopherwhisper-burrow-full-malware.pdf IoCs can be found there, as well as in our GitHub repo: https://github.com/eset/malware-ioc/tree/master/gopherwhisper

Infosec Exchange

1
0
2
0
Open post
ESET Research @ESETresearch@infosec.exchange
· 5mo ago

#ESETresearch discovered a new #NGate malware variant that abuses the legitimate #HandyPay app, which has been patched with possibly AI-generated malicious code. The campaign is ongoing and targets Android users in Brazil. https://www.welivesecurity.com/en/eset-research/new-ngate-variant-hides-in-a-trojanized-nfc-payment-app/ @lukasstefanko@bird.makeup
HandyPay is an Android app that enables relaying #NFC data from one device to another. Using the trojanized version, attackers can transfer victim’s payment card data to their own device and use it for unauthorized payments. The code can also capture payment card PINs.
Since HandyPay is significantly cheaper compared to paying for established #MaaS offerings with similar NFC relay functionality, the threat actors most probably decided on trojanizing the app as a cost-cutting measure.
We found two NGate samples being used in the campaign: one distributed via a website impersonating a 🇧🇷 lottery, the other via a fake Google Play page for a supposed card protection app. The trojanized HandyPay has never been available on the official Google Play store.
The code inside the maliciously patched HandyPay appears to have been developed with the assistance of #AI, as the logs contain emoji that are typical of AI-generated text, although definitive proof remains elusive.
IoCs are available in our GitHub repo: https://github.com/eset/malware-ioc/tree/master/ngate

Infosec Exchange

1
0
1
0
Open post
ESET Research @ESETresearch@infosec.exchange
· 8mo ago

According to ESET telemetry, threat actors keep finding new ways to exploit #NFC technology: detections surged by 78% compared to H1 2025; however, overall numbers remain low.
#NGate has demonstrated its relevance and is now enhanced with contact-stealing functionality. ESET researchers believe that this feature is designed to lay the groundwork for future attacks.
An NGate-based malware adapted for Brazil, #PhantomCard, targets banking clients via fake #Android apps that claim to improve security and privacy, distributed on pages featuring fabricated positive reviews.
And #RatOn combines RAT-like features with relay functionality, showcasing the determination of threat actors to evolve the methods of compromise. It’s distributed via fraudulent ads and apps, with the language targeting Czech and Slovak users.
Attackers remain faithful to tried-and-tested methods like #phishing calls and messages, while increasingly relying on psychological manipulation and #social engineering rather than exploiting just the technological aspect of NFC.
Read more about the evolution of NFC threat landscape in the latest #ESETThreatReport https://web-assets.esetstatic.com/wls/en/papers/threat-reports/eset-threat-report-h22025.pdf

2
0
0
0
Open post
ESET Research @ESETresearch@infosec.exchange
· 8mo ago

In 2025, #ESETresearch saw a 62% year-over-year increase in detections of fake investment and snake oil scams – tracked as HTML/Nomani – amounting to hundreds of thousands of detections and over 64,000 unique URLs blocked.
The highest activity was reported from Czechia, Japan, Slovakia, Spain, and Poland. But there’s a silver lining to the yearly detection trend: H2 2025 saw a 37% drop compared to H1, hinting at possible improvement.
New trends seen in Nomani scams include spread to other platforms such as YouTube, better resolution and audio-video sync of deepfakes, and ads and phishing content mirroring trending news and personalities.
Scammers have also shortened campaign lifespans and leveraged user tracking to redirect non-targets to benign cloaking pages. Phishing page templates show signs of AI-generated content – such as checkbox emojis in code comments.
For more insight into these scams, read the dedicated section in the latest #ESETThreatReport https://web-assets.esetstatic.com/wls/en/papers/threat-reports/eset-threat-report-h22025.pdf

Infosec Exchange

2
0
1
0
Open post
ESET Research @ESETresearch@infosec.exchange
· 8mo ago

In H2 2025, #ESETresearch saw a thirtyfold increase in #CloudEyE detections, amounting to more than 100,000 hits over the course of six months. CloudEyE is a #MaaS downloader and cryptor used to conceal and deploy other malware, such as #Rescoms, #Formbook, and #Agent Tesla.
CloudEyE’s intital stage is a downloader that spreads via #PowerShell scripts, #JavaScript files, and #NSIS executables . These download the next stage – the cryptor component – with the final payload packed within. All of the CloudEyE stages are heavily obfuscated.
Most of CloudEyE attack attempts we registered in H2 2025 targeted Poland (32%). These attacks were part of a wave of email campaigns in Central and Eastern Europe ESET observed in September and October 2025.
In order to appear legitimate, the emails deployed in the campaign were often sent from compromised legitimate accounts and localized to the language of the targeted country. They were usually inquiries about invoice payments, package tracking, and purchase orders.
For further information on CloudEyE, cryptors, and more, head on over to the latest #ESETThreatReport: https://web-assets.esetstatic.com/wls/en/papers/threat-reports/eset-threat-report-h22025.pdf

Infosec Exchange

2
0
1
0
Open post
ESET Research @ESETresearch@infosec.exchange
· 6mo ago

#ESETresearch is hiring! Passionate about geopolitics, cyberespionage and cyber threat intelligence? We have a new opening for a strategic threat intelligence analyst at our Montréal office. Come join the team!
https://eset.wd3.myworkdayjobs.com/ESET_External/job/Montreal/Analyste-du-renseignement-stratgique-sur-les-menaces---Cyberespionnage---Strategic-Threat-Intelligence-Analyst---Cyberespionage_JR-05715

Infosec Exchange

1
0
4
0
Open post
ESET Research @ESETresearch@infosec.exchange
· 20mo ago

With cryptocurrencies reaching record values in H2 2024, cryptocurrency wallet data was one of the prime targets of cybercriminals. In ESET telemetry, this was reflected in a rise in #cryptostealer detections across multiple platforms, specifically Windows, macOS, Android.

The increase was most dramatic on macOS, where Password Stealing Ware targeting cryptocurrency wallets more than doubled. Windows #cryptostealers grew by 56%, and Android financial threats, targeting banking apps and wallets, grew by 20%.

Read more about threats targeting cryptocurrency wallets on various platforms in the latest #ESETThreatReport from #ESETresearch: https://web-assets.esetstatic.com/wls/en/papers/threat-reports/eset-threat-report-h22024.pdf

8
0
8
0
Open post
ESET Research @ESETresearch@infosec.exchange
· 8mo ago

#ESETresearch’s @LukasStefanko will speak at Ransomware Resilience 2026 on Monday, Jan 19 in Kuala Lumpur at 4pm local time!
Discover how Android NFC threats evolved to enable unauthorized ATM withdrawals. Learn about NGate - the first Android malware to execute an NFC relay attack for remote ATM cash-outs. #RR2026

Infosec Exchange

1
0
0
0
Open post
ESET Research @ESETresearch@infosec.exchange
· 6mo ago

In cybersecurity, labels can distract from what really matters. At #RSAC2026, #ESETresearch’s Robert Lipovský will break down recent campaigns linked to state-sponsored actors and explore how hybrid threat tactics are evolving. The session focuses on practical defender takeaways - understanding behaviors, improving detection, and strengthening preparedness.

Infosec Exchange

0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)
  • Source code

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 14:34:53 UTC