Menu

Category Archives: Security Advisory

Auto Added by WPeMatico

You will always remember this as the day you finally caught FamousSparrow

ESET researchers uncover the toolset used by the FamousSparrow APT group, including two undocumented versions of the group’s signature backdoor, SparrowDoor

Operation FishMedley

ESET researchers detail a global espionage operation by FishMonger, the APT group run by I‑SOON

MirrorFace updates toolset, expands targeting to Europe

The group’s Operation AkaiRyū begins with targeted spearphishing emails that use the upcoming World Expo 2025 in Osaka, Japan, as a lure

AI’s biggest surprises of 2024 | Unlocked 403 cybersecurity podcast (S2E1)

Here’s what’s been hot on the AI scene over the past 12 months, how it’s changing the face of warfare, and how you can fight AI-powered scams

Shifting the sands of RansomHub’s EDRKillShifter

ESET researchers discover new ties between affiliates of RansomHub and of rival gangs Medusa, BianLian, and Play

When IT meets OT: Cybersecurity for the physical world

While relatively rare, real-world incidents impacting operational technology highlight that organizations in critical infrastructure can’t afford to dismiss the OT threat

Don’t let cybercriminals steal your Spotify account

Listen up, this is sure to be music to your ears – a few minutes spent securing your account today can save you a ton of trouble tomorrow

AI-driven deception: A new face of corporate fraud

Malicious use of AI is reshaping the fraud landscape, creating major new risks for businesses

Operation AkaiRyū: MirrorFace invites Europe to Expo 2025 and revives ANEL backdoor

ESET researchers uncovered MirrorFace activity that expanded beyond its usual focus on Japan and targeted a Central European diplomatic institute with the ANEL backdoor

Kids behaving badly online? Here’s what parents can do

By taking time to understand and communicate the impact of undesirable online behavior, you can teach your kids an invaluable set of life lessons for a new digital age

Threat Report H2 2024: Infostealer shakeup, new attack vector for mobile, and Nomani

Big shifts in the infostealer scene, novel attack vector against iOS and Android, and a massive surge in investment scams on social media

Martin Rees: Post-human intelligence – a cosmic perspective | Starmus highlights

Take a moment to think beyond our current capabilities and consider what might come next in the grand story of evolution

Bernhard Schölkopf: Is AI intelligent? | Starmus highlights

With AI’s pattern recognition capabilities well-established, Mr. Schölkopf’s talk shifts the focus to a pressing question: what will be the next great leap for AI?

This month in security with Tony Anscombe – February 2025 edition

Ransomware payments trending down, the cyber-resilience gap facing SMBs, and APT groups embracing generative AI – it’s a wrap on another month filled with impactful security news

Watch out for these traps lurking in search results

Here’s how to avoid being hit by fraudulent websites that scammers can catapult directly to the top of your search results

Sednit Espionage Group Attacking Air-Gapped Networks

The Sednit espionage group, also known as the Sofacy group, APT28 or “Fancy Bear”, has been targeting various institutions for many years. We recently discovered a component the group employed to reach physically isolated computer networks — “air-gapped” networks — and exfiltrate sensitive files from them through removable drives.

Korplug military targeted attacks: Afghanistan & Tajikistan

After taking a look at recent Korplug (PlugX) detections, we identified two larger scale campaigns employing this well-known Remote Access Trojan. This blog gives an overview of the first one

.NET goes open source and cross-platform

Microsoft’s .NET framework, which is used to build millions of websites and online applications, is taking further steps to go completely open-source, Microsoft has announced at the Connect() virtual development event. The company also stated its commitment to eventually ensure the free code runs on Mac OS and Linux too, Wired reports.

IT Pros also guilty of risqué selfies on mobiles

ESET study reveals many IT professionals are guilty of storing indecent material on their mobile phones, which would leave them embarrassed if lost.

G20 2014 Summit Lure used to target Tibetan activists

APT actors trying to use big events as a lure to compromise their targets is nothing new. Tibetan NGOs being targeted by APT actors is also nothing new. Thus, surrounding the upcoming G20 2014 summit that is held in Brisbane, Australia, we were expecting to see G20 themed threats targeted at Tibetan NGOs. A Win32/Farfli […]

Public Wi-Fi hotspots – know the risks

For ordinary laptop and smartphone users, Wi-Fi is not ideal – but it’s sometimes near-inescapable.

Apple Pay and security – what you need to know

Mobile payments look set to be one of the defining technologies of 2015, as the launch of Apple Pay catalyses a boom in cardless payments – both from Apple’s own system, and rivals playing catch-up.

First exploitation of Internet Explorer ‘Unicorn bug’ in-the-wild

Microsoft released a patch last week for a critical vulnerability allowing remote code execution in Internet Explorer. This vulnerability is significant because it exploits an old bug present in Internet Explorer versions 3 through 11.

Smart home security – how not to be dumb with your devices

It’s easy to imagine that ALL connected devices – from fridges to CCTV cameras – are a security nightmare, but there are simple, sensible steps you can take to lock these risks down.

Driverless cars ‘could be hacked’ warns Institute of Engineering and Technology

Self-driving cars are just around the corner, with the UK government putting up £10 million (around $15.6 million) for cities to pilot trials as soon as next year, but the country’s Institute of Engineering and Technology (IET) today issued stern warnings about the security of the technology.

Privacy and security post-Snowden: Pew Research parallels ESET findings

Privacy and security online are hot button topics in America today, as a new survey by the Pew Research Center confirms, mirroring similar results from two different privacy and security surveys conducted by ESET.

Do I need to worry about state-sponsored threats like Regin?

Since the discovery of Stuxnet several years ago, there has been a parade of targeted malware that may have been created or sponsored by nation states. Does an average person or business really need to worry about these things?

Cyber Monday – 12 tips to help you shop safely online

Technology might evolve, but cyber gangs rely on tried-and-tested tactics. With a bit of care and attention, it’s easy to sort the genuine bargains from the too-good-to-be-true fakes.

Can e-cigarettes give you malware?

The long-term health effects of electronic cigarettes – or E-cigarettes – are still open for discussion – but the devices could harm your computer, at least if one report is to be believed.

Firefox 34 disables SSL 3.0 and tackles eight security fixes

Firefox 34, the latest version of the Mozilla’s popular web browser has disabled support for SSL 3.0 in reaction to the POODLE exploit, reported by We Live Security back in October.

Android scam: Firms fined over $500,000 for malicious apps’ hidden subscriptions

Three UK firms have been fined over $500,000 for a scam that involved Android apps signing up to a subscription service, and suppressing notifications informing the victim they were being charged, according to The Guardian.

Identity theft – six tips to help keep yours safe

Private data such as addresses and social security numbers can be just as valuable to cybercriminals as valid credit card details can be to thieves – if not more so. Lock yours down with our tips.

TorrentLocker: Racketeering ransomware disassembled by ESET experts

Security experts at ESET have released their latest research into the notorious TorrentLocker malware, which has infected thousands of computer systems around the world, taking data hostage and demanding a ransom be paid to ensure its safe return.

Cybercrime Trends & Predictions for 2015

As regular readers will know, every year we publish our predictions on cybercrime attacks for the year ahead. Well, our South American research team has spent the last few weeks putting together our predictions for 2015.

TorrentLocker — Ransomware in a country near you

Today, we are publishing research on ransomware that emerged in 2014. We have posted blog articles about this threat before, to raise awareness when we realized the criminals were targeting the United Kingdom and Spain.

ICANN computers compromised by hackers

The nonprofit organization that looks after name and internet domains has been hit by a spear phishing hack that has compromised company data, reports The Register.

Mobile security: flaw allows hackers to read texts and listen to calls

Hackers can eavesdrop on your phone calls and text messages even with cell networks using “the most advanced encryption available” according to The Washington Post.

Virlock: First Self-Reproducing Ransomware is also a Shape Shifter

Win32/VirLock is ransomware that locks victims’ screens but also acts as parasitic virus, infecting existing files on their computers. The virus is also polymorphic, which makes it an interesting piece of malware to analyze. This is the first time such combination of malware features has been observed.

Madonna thinks her computer was hacked

Turns out that the Material Girl has had her material stolen, and she’s blaming hackers!

North Korea falls off the internet – is the United States to blame?

Barack Obama promises that the United States will respond to the Sony hack, and North Korea drops off the internet. Is there a connection?

Biometrics – can your fingerprint be ‘copied’ from a normal photo?

Fingerprint biometrics are entering the mainstream as a security measure, with both Apple and Samsung relying on readers to secure their flagship phones – but biometrics may not be as secure as many believe.

Hobbit-inspired sword can help you find unsecured WiFi hotspots

Like many others, I was enchanted by The Hobbit (and later Lord of the Rings) at a young age – long before Peter Jackson turned J R R Tolkien’s middle-earth fantasy books into a series of blockbuster movies.

Unpatched security hole has left millions of Moonpig customers at risk for 17 months

Moonpig, the online personalised card company, has been accused of a shockingly sloppy attitude to security, after apparently leaving a serious hole in its security unpatched.

Bitstamp hacked for $5 million in Bitcoin

19,000 Bitcoin – valued at around $275 each, so $5 million together – have been stolen from a majour European Bitcoin exchange, reports RT.

CES 2015 in Las Vegas: first impressions, 5 hot topics

With nearly 160,000 lust-ridden techies, corporate denizens and a few of us security types descending on a slightly crisp wintery Las Vegas to see what all the fuss is about at CES 2015, here are a few things to keep an eye out for this year at the show.

Windows exploitation in 2014

Today, we published our research about Windows exploitation in 2014. This report contains interesting information about vulnerabilities in Microsoft Windows and Office patched over the course of the year, drive-by download attacks and mitigation techniques.

Microsoft warns of banking malware targeting German speakers

Microsoft has warned of a new variant of a banking malware that appears to be targeting German speakers, according to PC World.

AOL blocks malicious ads from its advertising platform

AOL has taken steps to stop a set of malicious advertisements being served through their sites, including The Huffington Post, Computer Business Review reports.

Digital Invasion: 3 things we learned from CES 2015

Ever lost a kid somewhere? Not anymore if the gadget vendors have anything to say about it. Now you can digitally strap your kid to your tablet and keep track of them. Kids not running enough to stay trim? There’s an app for that that works the same way. Got high blood sugar? You can […]

Facebook privacy – why statements about copyright don’t do anything

Facebook users around the world have reported the return of the network’s longer-lasting hoaxes – a legal disclaimer which allows users to regain copyright over their images and other content. Here’s why it doesn’t work.

‘Critical Security Updates’ cancelled for 939 million Android users

Google has revealed that Android smartphones and tablets running versions of the software released before 4.3 (Jellybean) will no longer be given official updates to an important part of the software

5 reasons not to “hack back”

Are hacking victims “hacking back”? That question was recently posed in headlines like this one from Bloomberg: FBI Investigating Whether Companies Are Engaged in Revenge Hacking. The Marketplace reporter, Ben Johnson, speculated that 2015 might be the year of “hacking back” when he asked me about revenge hacking.

Hacked routers used for paid DDoS attacks

The rent-a-DDoS service that knocked out Xbox Live and Playstation Network is powered by thousands of hacked residential internet routers.

British Prime Minister wants access to messaging apps

British Prime Minister David Cameron has stated his belief that encrypted messaging services must have backdoor access to government agencies

Obama to propose legislation that protects firms sharing cyberthreat data

President Barack Obama is planning to push legislation which would protect companies from lawsuits for sharing cyberthreat data with the government, reports the Washington Post.

Swiss bank data released by hackers

The Swiss state owned Banque Cantonale de Geneve has confirmed that hackers have released confidential customer correspondences after the bank refused to pay the ransom demanded by the attackers

Phish Allergy – Recognizing Phishing Messages

While phishing-related malware is still mostly Windows targeting, attacks that rely purely on social engineering and fake web sites might be delivered by any platform, including smartphones and tablets. The more cautious you are, the better informed you are, and the more you think before you click, the more chance you have of leaving phishing […]

Do you really need antivirus software for Linux desktops?

It started, innocently enough, as a question asked in the ESET Security Forum titled “Eset – Do I Really Need Antivirus On My Linux Distros?” However, the answer to that seemingly simple question on Linux antivirus is more complex than a simple yes-or-no response.

Lizard Squad DDoS-for-hire service hacked – users’ details revealed

Lizard Squad failed to encrypt its database of LizardStresser’s registered users – storing details of their usernames and passwords in plaintext. A schoolboy error if ever I heard one.

Cybercrime deterrence: 6 important steps

Cybercrime: there’s too much of it, and we need to do more to deter it. With the President of the United States now making frequent references to “doing more about cybercrime” now is a good time to look at what steps must be taken.

1800 Minecraft logins leak online

More than 1,800 Minecraft login details have been leaked online, German news site Heise.de has revealed.

Facebook will highlight hoaxes in users’ newsfeeds

Facebook has announced plans to crack down on spam and hoaxes in the newsfeed, with a note highlighting ‘false information’ when enough people flag the link as a hoax.

How can businesses save money on internet security in 2015?

A recent report from Piper Jaffray found that 75% of companies expected to increase their IT security spending in 2015, following a year of high-profile hacks and data breaches in 2014.

Edward Snowden doesn’t use an iPhone for privacy reasons

NSA whistleblower Edward Snowden has claimed he doesn’t use an iPhone for fear of surveillance technology in the smartphone, reports The Independent.

Google reveals trio of security vulnerabilities in OS X

Google’s Project Zero has released information on three as yet unpatched vulnerabilities in Apple’s OS X operating system, reports Ars Technica.

Android Wi-Fi Direct bug means hackers can reboot your device

A vulnerability in Android’s Wi-Fi Direct functionality has been uncovered by security researchers.

MSIL/Agent.PYO: Have botnet, will travel

ESET’s researchers recently encountered a piece of malware targeting the filling of the forms belonging to the Consulate of Poland. To understand why it is first necessary to have a brief look at the application process for visas.

Taylor Swift hacked, but denies naked pictures will be leaked

Singer Taylor Swift has had her Twitter and Instagram accounts hacked, but laughed off claims that the hackers will release nude photographs of her.

Blackhat: Lessons from the Michael Mann, Chris Hemsworth movie?

Blackhat, the hacker movie directed by Michael Mann and starring Chris Hemsworth, could spread awareness of digital threats. If it is a learning opportunity, what are the lessons?

6 WhatsApp Security Tips

Even though WhatsApp now encrypts all of its messages and data, it pays to be secure with your chats. Here are our top WhatsApp security tips.

The New Hacker’s List and an Old Debate: Would you Hire a Hacker?

The recent opening of the Hacker List portal brings to mind the age-old question: Would you hire a hacker?

Facebook porn scam infects 110k users in 48 hours

A new porn scam is spreading startlingly quickly through Facebook – one that has managed to spread malware to over 110,000 users in 48 hours, reports The Guardian.

White House seeks 10% increase in cybersecurity spend

President Obama’s budget proposal for the 2016 fiscal year includes a projected 10 percent increase in cybersecurity spend, reports Reuters.

Internet Explorer exploit could let phishers steal logins

A vulnerability in the latest patched version of Microsoft Internet Explorer that could allow hackers to launch “highly credible phishing attacks” has been uncovered, according to PC World.

Facebook turns 11 – what you need to know, and what do your likes say about you?

Facebook updated its privacy settings at the end of January. As Facebook turns 11 today, here’s what you need to know about the new settings and how they could affect you.

The utterly crazy story of the death threat hacker (involves a cat)

A cat leads to a notorious death threat hacker finally being caught and jailed in Japan.

What are the alternatives to passwords?

Is it time for big companies – at the very least – to abandon weak password security? If so, what password alternatives are there?

Common eBay scams and how to avoid them

Buying and selling on eBay can be great, but it can also be fraught with risk. Here are some of the most common eBay scams and how they can be avoided.

It’s Safer Internet Day. So where is our Internet of Secure Things?

It’s Safer Internet Day. But millions of devices which have not been designed with security in mind are connecting to the internet. Shouldn’t we be able to tell the manufacturers that enough is enough?

WhatsApp privacy is ‘broken,’ reveals proof-of-concept hack

WhatsApp’s privacy settings are “broken” and can be bypassed by downloading a simple bit of software, claims the Dutch developer behind proof-of-concept tool WhatsSpy Public.

Facebook launches ThreatExchange for companies to share security threats

Facebook has officially launched ThreatExchange – a collaborative social network where companies can share information on cybersecurity threats, in an effort to neuter potential damage.

Facebook exploit allowed attackers to remotely delete photos

A Facebook hack that allowed attackers to remotely delete any photo they wanted to from the social network has been patched by the company.

Is your valentine for real? Six signs you might be falling for an online dating scam

With Valentine’s Day nearly upon us, millions will be looking for love online. Here’s six online dating scams to look out for.

Jamie Oliver website serves up a side of malware

Jamie Oliver’s website was affected by a malware issue, a spokesperson for the British celebrity chef has told the BBC.

Lenovo and Superfish? Don’t panic, you may not be affected

Lenovo’s installation of a security-breaking app called Superfish on some computers has customers justifiably angry, but some folks are now unnecessarily confused by false positive detection.

Top 10 breaches of 2014 attacked ‘old vulnerabilities’, says HP

A report by HP has found that 44 percent of all of the breaches in 2014 were caused by known vulnerabilities, between two and four years old.

Security terms explained: What does Zero Day mean?

One of the terms I’m most often asked to explain is what a “zero day” vulnerability or exploit is; let’s look at what that phrase entails.

Europol shuts down Ramnit botnet used to steal bank details

The Ramnit botnet that is said to have affected 3.2 million computers has been shut down by European police.

Electronic health records and data abuse: it’s about more than medical info

After the Anthem mega-breach, questions abound about possible abuses of medical data. Here is a breakdown that offers some context.

Blu-ray exploits could allow computer malware infection

A pair of possible exploits in hardware and software used for playing Blu-ray discs have come to light, reports PC World.

FREAK attack: security vulnerability breaks HTTPS protection

A widespread, long-standing security flaw that allows attackers to decrypt HTTPS-protected traffic between certain device and potentially millions of websites has been uncovered by security researchers, reports Ars Technica.

Casper Malware: After Babar and Bunny, Another Espionage Cartoon

In this post, we lift the veil on Casper – another piece of software that we believe to have been created by the same organization that is behind Babar and Bunny.

Lysa Myers: “There are still only a handful of women in the security field”

There are many female researchers and computer experts who contribute to the field, helping everyone enjoy safer technology. We spoke to one of the most prominent: Lysa Myers, a member of our research team in the US.

DDoS attack on feminist blog backfires on International Women’s Day

An attempt to silence feminism blog Femsplain backfires on DDoS attackers, as they only help to raise its profile.

FBI investigating apparent ISIS attacks on Western websites

A number of seemingly unconnected Western websites were hacked over the weekend, with messages claiming Islamic State as the perpetrator.

Operating System Vulnerabilities, Exploits and Insecurity

iOS and OS X the most vulnerable operating systems? Don’t confuse vulnerabilities with exploits, or patch frequency with insecurity.

CryptoFortress mimics TorrentLocker but is a different ransomware

ESET assess the differences between CryptoFortress and TorrentLocker: two very different strains of ransomware.

Will Windows 10 leave enterprises vulnerable to zero-days?

One thing Microsoft has been very public about is Windows 10’s new strategy of releasing patches to update the operating system at different times for consumer and enterprise versions.

Hackers phish for data with fake Apple Watch giveaway

Apple fans keen to get their hands on the Apple Watch are advised to think before they click, after hackers exploited a wave of enthusiasm around the launch with a phishing scam linked to a fake giveaway.

7 tasks that waste your IT team’s time

IT teams’ time is always limited, and it doesn’t help when other things get in the way. Here’s seven things that waste your IT team’s time.