# ESET research

Published articles for ESET research.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Forgotten UEFI shims undermining Secure Boot

DevFeed: [Forgotten UEFI shims undermining Secure Boot](<https://devfeed.tech/articles/forgotten-uefi-shims-undermining-secure-boot-8369.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/>)

Author: Martin Smolár

Published: 2026-07-14T08:53:00Z

Content type: news

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [applications](<https://devfeed.tech/tags/applications.md>), [boot](<https://devfeed.tech/tags/boot.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [linux](<https://devfeed.tech/tags/linux.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [os](<https://devfeed.tech/tags/os.md>), [patch-tuesday](<https://devfeed.tech/tags/patch-tuesday.md>), [software](<https://devfeed.tech/tags/software.md>), [systems](<https://devfeed.tech/tags/systems.md>), [update](<https://devfeed.tech/tags/update.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

ESET reported 11 outdated UEFI shim bootloaders that can bypass Secure Boot on systems trusting Microsoft's third-party UEFI certificate. Microsoft revoked the reported shim hashes in its June 2026 Patch Tuesday dbx update.

### Source excerpt

ESET researchers discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass UEFI Secure Boot by exploiting decade-old vulnerabilities

## ESET Threat Report H1 2026

DevFeed: [ESET Threat Report H1 2026](<https://devfeed.tech/articles/eset-threat-report-h1-2026-8365.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/>)

Author: Jiří Kropáč

Published: 2026-07-08T08:45:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [ESET research](<https://devfeed.tech/topics/eset-research.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Generative AI](<https://devfeed.tech/topics/generative-ai.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Android](<https://devfeed.tech/topics/android.md>), [ClickFix](<https://devfeed.tech/topics/clickfix.md>), [QR Code](<https://devfeed.tech/topics/qrcode.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [android](<https://devfeed.tech/tags/android.md>), [clickfix](<https://devfeed.tech/tags/clickfix.md>), [code](<https://devfeed.tech/tags/code.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [generative-ai](<https://devfeed.tech/tags/generative-ai.md>), [malware](<https://devfeed.tech/tags/malware.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [threat-report](<https://devfeed.tech/tags/threat-report.md>)

### AI overview

ESET's H1 2026 threat report describes attackers adapting established techniques across new platforms and behaviors. It highlights the expanding abuse of AI skills, PromptSpy Android malware using Google Gemini, the spread of ClickFix and QR-code phishing, and continued ransomware activity involving EDR killers.

### Source excerpt

A view of the H1 2026 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts.

## Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances

DevFeed: [Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances](<https://devfeed.tech/articles/gamaredon-in-2025-leveraging-tunnels-workers-dead-drops-and-new-alliances-8371.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/gamaredon-2025-leveraging-tunnels-workers-dead-drops-new-alliances/>)

Author: Zoltán Rusnák

Published: 2026-06-25T08:45:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Security Attacks](<https://devfeed.tech/topics/security-attacks.md>)

Tags: [apt](<https://devfeed.tech/tags/apt.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [dns](<https://devfeed.tech/tags/dns.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [messaging](<https://devfeed.tech/tags/messaging.md>), [powershell](<https://devfeed.tech/tags/powershell.md>), [social-media](<https://devfeed.tech/tags/social-media.md>), [storage](<https://devfeed.tech/tags/storage.md>)

### AI overview

ESET Research analyzes Gamaredon's 2025 cyberespionage activity against Ukrainian governmental and military institutions, including spearphishing, new malicious PowerShell tools, cloud-based data exfiltration, and concealed C&C infrastructure.

### Source excerpt

ESET Research analyzes Gamaredon's new toolset and the group's growing reliance on legitimate online services to hide its C&C infrastructure and exfiltrate stolen data

## ESET takes part in Operation Endgame to disrupt Amadey and Stealc

DevFeed: [ESET takes part in Operation Endgame to disrupt Amadey and Stealc](<https://devfeed.tech/articles/eset-takes-part-in-operation-endgame-to-disrupt-amadey-and-stealc-8364.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/eset-takes-part-operation-endgame-disrupt-amadey-stealc/>)

Author: Jakub Tomanek Tomáš Procházka

Published: 2026-06-24T12:35:24Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [ESET research](<https://devfeed.tech/topics/eset-research.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [C2](<https://devfeed.tech/topics/c2.md>), [High Profile Threats](<https://devfeed.tech/topics/high-profile-threats.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [data](<https://devfeed.tech/topics/data.md>), [Statistics](<https://devfeed.tech/topics/statistics.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [data](<https://devfeed.tech/tags/data.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [maas](<https://devfeed.tech/tags/maas.md>), [malware](<https://devfeed.tech/tags/malware.md>), [network](<https://devfeed.tech/tags/network.md>), [research](<https://devfeed.tech/tags/research.md>)

### AI overview

ESET Research describes its contribution to Operation Endgame, a coordinated global effort that disrupted the Amadey botnet and Stealc infostealer. The article covers infrastructure tracking, technical and statistical analysis, malware configuration data, command-and-control servers, encryption keys, campaign identifiers, and affiliate-level activity within the malware-as-a-service ecosystem.

### Source excerpt

ESET researchers assisted in the global disruption of the Amadey botnet and Stealc infostealer, providing technical analysis, infrastructure tracking, and affiliate-level insights

## Killing me gently: Inside Gentlemen's EDR killer framework

DevFeed: [Killing me gently: Inside Gentlemen's EDR killer framework](<https://devfeed.tech/articles/killing-me-gently-inside-gentlemen-s-edr-killer-framework-8373.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/killing-me-gently-inside-gentlemens-edr-killer-framework/>)

Author: Jakub Souček

Published: 2026-06-18T09:46:32Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [ESET research](<https://devfeed.tech/topics/eset-research.md>), [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [Software](<https://devfeed.tech/topics/software.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [europe](<https://devfeed.tech/tags/europe.md>), [insights](<https://devfeed.tech/tags/insights.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>), [software](<https://devfeed.tech/tags/software.md>), [southeast-asia](<https://devfeed.tech/tags/southeast-asia.md>), [techniques](<https://devfeed.tech/tags/techniques.md>)

### AI overview

ESET Research analyzes Gentlemen's ransomware-as-a-service operation and its portfolio of EDR-killing tools. The article examines the in-house GentleKiller framework, third-party tools, shared defense-evasion techniques, and the group's rapid adoption of BYOVD exploits, using incident-level visibility and leaked internal data.

### Source excerpt

ESET Research shares the results of a months-long investigation into the suite of EDR killers maintained by the RaaS gang Gentlemen

## FishMonger's arsenal upgraded: SprySOCKS for Windows

DevFeed: [FishMonger's arsenal upgraded: SprySOCKS for Windows](<https://devfeed.tech/articles/fishmonger-s-arsenal-upgraded-sprysocks-for-windows-8368.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/>)

Author: ESET Research

Published: 2026-06-16T08:54:04Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [backdoor](<https://devfeed.tech/topics/backdoor.md>), [Processes](<https://devfeed.tech/topics/processes.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [apt](<https://devfeed.tech/tags/apt.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [china](<https://devfeed.tech/tags/china.md>), [communication](<https://devfeed.tech/tags/communication.md>), [drivers](<https://devfeed.tech/tags/drivers.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [government](<https://devfeed.tech/tags/government.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [linux](<https://devfeed.tech/tags/linux.md>), [malware](<https://devfeed.tech/tags/malware.md>), [process](<https://devfeed.tech/tags/process.md>), [processes](<https://devfeed.tech/tags/processes.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [virustotal](<https://devfeed.tech/tags/virustotal.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

ESET reports two previously undocumented Windows variants of the SprySOCKS backdoor attributed to FishMonger. The variants use TCP, UDP, and WebSocket communications; WIN_DRV uses a kernel driver to conceal artifacts and redirect specially crafted TCP traffic.

### Source excerpt

ESET researchers have discovered SprySOCKS for Windows, FishMonger's backdoor weaponizing a kernel driver for advanced stealthiness

## OceanLotus: From external espionage to domestic targeting

DevFeed: [OceanLotus: From external espionage to domestic targeting](<https://devfeed.tech/articles/oceanlotus-from-external-espionage-to-domestic-targeting-8378.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/>)

Author: ESET Research

Published: 2026-06-11T08:45:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [backdoor](<https://devfeed.tech/topics/backdoor.md>), [networking](<https://devfeed.tech/topics/networking.md>)

Tags: [apt](<https://devfeed.tech/tags/apt.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [dns](<https://devfeed.tech/tags/dns.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [linux](<https://devfeed.tech/tags/linux.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>)

### AI overview

The article analyzes OceanLotus's shift toward domestic espionage and two SPECTRALVIPER campaigns in Vietnam: a targeted supply-chain compromise of investor software and a prolonged intrusion against a construction corporation.

### Source excerpt

A shift in operational pattern of the infamous Vietnam-aligned APT group

## ESET APT Activity Report Q4 2025-Q1 2026

DevFeed: [ESET APT Activity Report Q4 2025-Q1 2026](<https://devfeed.tech/articles/eset-apt-activity-report-q4-2025-q1-2026-8362.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/eset-apt-activity-report-q4-2025-q1-2026/>)

Author: Jean-Ian Boutin

Published: 2026-05-28T08:45:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [High Profile Threats](<https://devfeed.tech/topics/high-profile-threats.md>)

Tags: [apt](<https://devfeed.tech/tags/apt.md>), [china](<https://devfeed.tech/tags/china.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [iran](<https://devfeed.tech/tags/iran.md>), [virustotal](<https://devfeed.tech/tags/virustotal.md>)

### AI overview

ESET's report summarizes selected APT activity from October 2025 through March 2026, including China-aligned espionage, activity targeting government and strategic-technology entities, and changes in Iran-aligned activity during the war in Iran.

### Source excerpt

An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q4 2025 and Q1 2026

## Webworm: New burrowing techniques

DevFeed: [Webworm: New burrowing techniques](<https://devfeed.tech/articles/webworm-new-burrowing-techniques-8383.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/>)

Author: Eric Howard

Published: 2026-05-20T08:40:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>), [Reconnaissance](<https://devfeed.tech/topics/recon.md>), [Discord](<https://devfeed.tech/topics/discord.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [API](<https://devfeed.tech/topics/api.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>), [Bash](<https://devfeed.tech/topics/bash.md>), [Virtual Private Network](<https://devfeed.tech/topics/vpn.md>), [Amazon S3](<https://devfeed.tech/topics/amazon-s3.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [apt](<https://devfeed.tech/tags/apt.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [bash](<https://devfeed.tech/tags/bash.md>), [china](<https://devfeed.tech/tags/china.md>), [discord](<https://devfeed.tech/tags/discord.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [europe](<https://devfeed.tech/tags/europe.md>), [github](<https://devfeed.tech/tags/github.md>), [ip](<https://devfeed.tech/tags/ip.md>), [malware](<https://devfeed.tech/tags/malware.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [s3](<https://devfeed.tech/tags/s3.md>), [server](<https://devfeed.tech/tags/server.md>), [techniques](<https://devfeed.tech/tags/techniques.md>), [tools](<https://devfeed.tech/tags/tools.md>)

### AI overview

ESET researchers analyze Webworm's 2025 activity, including its shift toward Europe, new Discord- and Microsoft Graph API-based backdoors, proxy tools, reconnaissance activity, and GitHub-hosted malware staging.

### Source excerpt

ESET researchers describe new tools and techniques that the Webworm APT group recently added to its arsenal

## FrostyNeighbor: Fresh mischief and digital shenanigans

DevFeed: [FrostyNeighbor: Fresh mischief and digital shenanigans](<https://devfeed.tech/articles/frostyneighbor-fresh-mischief-and-digital-shenanigans-8370.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/>)

Author: Damien Schaeffer

Published: 2026-05-14T08:50:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [payload](<https://devfeed.tech/topics/payload.md>), [C++](<https://devfeed.tech/topics/c-plus-plus.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [.NET](<https://devfeed.tech/topics/net.md>), [PowerShell](<https://devfeed.tech/topics/powershell.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [CSS](<https://devfeed.tech/topics/css.md>), [SVG](<https://devfeed.tech/topics/svg.md>)

Tags: [c-plus-plus](<https://devfeed.tech/tags/c-plus-plus.md>), [css](<https://devfeed.tech/tags/css.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [malware](<https://devfeed.tech/tags/malware.md>), [net](<https://devfeed.tech/tags/net.md>), [payload](<https://devfeed.tech/tags/payload.md>), [powershell](<https://devfeed.tech/tags/powershell.md>), [svg](<https://devfeed.tech/tags/svg.md>), [techniques](<https://devfeed.tech/tags/techniques.md>)

### AI overview

ESET researchers document new FrostyNeighbor cyberespionage activity targeting governmental, military, and key-sector organizations in Eastern Europe, especially Ukraine. The group continually evolves its compromise chains and tooling, using server-side victim validation and PicassoLoader variants written in .NET, PowerShell, JavaScript, and C++.

### Source excerpt

ESET researchers uncovered new activities attributed to FrostyNeighbor, updating its compromise chain to support the group's continual cyberespionage operations

## Fake call logs, real payments: How CallPhantom tricks Android users

DevFeed: [Fake call logs, real payments: How CallPhantom tricks Android users](<https://devfeed.tech/articles/fake-call-logs-real-payments-how-callphantom-tricks-android-users-8367.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/fake-call-logs-real-payments-how-callphantom-tricks-android-users/>)

Author: Lukas Stefanko

Published: 2026-05-07T08:51:19Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Android](<https://devfeed.tech/topics/android.md>), [Google](<https://devfeed.tech/topics/google.md>), [App](<https://devfeed.tech/topics/app.md>), [Reddit](<https://devfeed.tech/topics/reddit.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [apps](<https://devfeed.tech/tags/apps.md>), [data](<https://devfeed.tech/tags/data.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [google](<https://devfeed.tech/tags/google.md>), [payments](<https://devfeed.tech/tags/payments.md>), [scam](<https://devfeed.tech/tags/scam.md>), [subscriptions](<https://devfeed.tech/tags/subscriptions.md>), [whatsapp](<https://devfeed.tech/tags/whatsapp.md>)

### AI overview

ESET researchers investigated 28 fraudulent Android apps called CallPhantom that claimed to reveal call histories, SMS records, and WhatsApp call logs for any phone number. After users paid for subscriptions, the apps returned randomly generated data. The apps had more than 7.3 million cumulative downloads and were reported to Google, which removed them from Google Play.

### Source excerpt

ESET researchers uncovered fraudulent apps on Google Play that claim to provide the call history "for any number" and had been downloaded more than seven million times before being taken down

## A rigged game: ScarCruft compromises gaming platform in a supply-chain attack

DevFeed: [A rigged game: ScarCruft compromises gaming platform in a supply-chain attack](<https://devfeed.tech/articles/a-rigged-game-scarcruft-compromises-gaming-platform-in-a-supply-chain-attack-8381.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/rigged-game-scarcruft-compromises-gaming-platform-supply-chain-attack/>)

Author: Filip Jurčacko

Published: 2026-05-05T08:55:27Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>), [LineageOS](<https://devfeed.tech/topics/lineageos.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [High Profile Threats](<https://devfeed.tech/topics/high-profile-threats.md>), [C++](<https://devfeed.tech/topics/c-plus-plus.md>), [Shell](<https://devfeed.tech/topics/shell.md>), [Python](<https://devfeed.tech/topics/python.md>), [Ruby](<https://devfeed.tech/topics/ruby.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [android](<https://devfeed.tech/tags/android.md>), [china](<https://devfeed.tech/tags/china.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [data](<https://devfeed.tech/tags/data.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [gaming](<https://devfeed.tech/tags/gaming.md>), [government](<https://devfeed.tech/tags/government.md>), [logging](<https://devfeed.tech/tags/logging.md>), [platform](<https://devfeed.tech/tags/platform.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [voice](<https://devfeed.tech/tags/voice.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

ESET researchers describe a ScarCruft supply-chain attack that trojanized Windows and Android components of a Yanbian-themed gaming platform. The BirdCall backdoor supports espionage capabilities including collecting data and documents, screenshots, and voice recordings.

### Source excerpt

ESET researchers have investigated an ongoing attack by the ScarCruft APT group that targets the Yanbian region via backdoor-laced Windows and Android games

## GopherWhisper: A burrow full of malware

DevFeed: [GopherWhisper: A burrow full of malware](<https://devfeed.tech/articles/gopherwhisper-a-burrow-full-of-malware-8372.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/gopherwhisper-burrow-full-malware/>)

Author: Eric Howard

Published: 2026-04-23T08:59:18Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [backdoor](<https://devfeed.tech/topics/backdoor.md>), [Go Language](<https://devfeed.tech/topics/go-language.md>), [C++](<https://devfeed.tech/topics/c-plus-plus.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [apt](<https://devfeed.tech/tags/apt.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [c-plus-plus](<https://devfeed.tech/tags/c-plus-plus.md>), [china](<https://devfeed.tech/tags/china.md>), [discord](<https://devfeed.tech/tags/discord.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [go](<https://devfeed.tech/tags/go.md>), [malware](<https://devfeed.tech/tags/malware.md>), [microsoft-365](<https://devfeed.tech/tags/microsoft-365.md>), [slack](<https://devfeed.tech/tags/slack.md>)

### AI overview

ESET Research describes GopherWhisper, a China-aligned APT group targeting a Mongolian government entity. Its largely Go-based malware toolset uses backdoors, injectors, loaders, and legitimate services including Discord, Slack, Microsoft 365 Outlook, and file.io for command-and-control and exfiltration.

### Source excerpt

ESET Research has discovered a new China-aligned APT group that we've named GopherWhisper, which targets Mongolian governmental institutions

## New NGate variant hides in a trojanized NFC payment app

DevFeed: [New NGate variant hides in a trojanized NFC payment app](<https://devfeed.tech/articles/new-ngate-variant-hides-in-a-trojanized-nfc-payment-app-8377.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/new-ngate-variant-hides-in-a-trojanized-nfc-payment-app/>)

Author: Lukas Stefanko

Published: 2026-04-21T08:55:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [Android](<https://devfeed.tech/topics/android.md>), [ESET research](<https://devfeed.tech/topics/eset-research.md>), [genai](<https://devfeed.tech/topics/genai.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [App](<https://devfeed.tech/topics/app.md>), [servers](<https://devfeed.tech/topics/servers.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [brazil](<https://devfeed.tech/tags/brazil.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [genai](<https://devfeed.tech/tags/genai.md>), [malware](<https://devfeed.tech/tags/malware.md>), [payment](<https://devfeed.tech/tags/payment.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [threat-report](<https://devfeed.tech/tags/threat-report.md>)

### AI overview

ESET Research reports a new NGate malware variant hidden in a trojanized Android NFC payment app called HandyPay. The malware relays payment-card NFC data, steals card PINs, and exfiltrates them to an operator-controlled server. The active campaign, targeting users in Brazil since around November 2025, distributes the app through fake lottery and Google Play websites; the code may have been assisted by GenAI.

### Source excerpt

ESET researchers discover another iteration of NGate malware, this time possibly developed with the assistance of AI

## EDR killers explained: Beyond the drivers

DevFeed: [EDR killers explained: Beyond the drivers](<https://devfeed.tech/articles/edr-killers-explained-beyond-the-drivers-8361.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/edr-killers-explained-beyond-the-drivers/>)

Author: Jakub Souček

Published: 2026-03-19T09:55:08Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [1Password in the browser](<https://devfeed.tech/topics/1password-in-the-browser.md>)

Tags: [development](<https://devfeed.tech/tags/development.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [research](<https://devfeed.tech/tags/research.md>), [techniques](<https://devfeed.tech/tags/techniques.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>)

### AI overview

ESET researchers analyze nearly 90 EDR killers used in real ransomware intrusions, examining vulnerable-driver, anti-rootkit, script-based, and driverless approaches to disabling endpoint protection. The article explains how affiliates select and adapt these tools, why driver-based attribution can mislead, and how commercialized kits increase defense complexity.

### Source excerpt

ESET researchers dive deeper into the EDR killer ecosystem, disclosing how attackers abuse vulnerable drivers

## Sednit reloaded: Back in the trenches

DevFeed: [Sednit reloaded: Back in the trenches](<https://devfeed.tech/articles/sednit-reloaded-back-in-the-trenches-8382.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/sednit-reloaded-back-trenches/>)

Author: ESET Research

Published: 2026-03-10T09:58:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [apt](<https://devfeed.tech/topics/apt.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [obfuscation](<https://devfeed.tech/topics/obfuscation.md>), [PowerShell](<https://devfeed.tech/topics/powershell.md>), [Code](<https://devfeed.tech/topics/code.md>), [Network](<https://devfeed.tech/topics/network.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [apt](<https://devfeed.tech/tags/apt.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [code](<https://devfeed.tech/tags/code.md>), [department-of-justice](<https://devfeed.tech/tags/department-of-justice.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [network](<https://devfeed.tech/tags/network.md>), [obfuscation](<https://devfeed.tech/tags/obfuscation.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [powershell](<https://devfeed.tech/tags/powershell.md>), [us](<https://devfeed.tech/tags/us.md>)

### AI overview

This article examines the resurgence of Sednit, also known as APT28, and its modern espionage toolkit. It describes the BeardShell and Covenant implants, their use of legitimate cloud providers for command and control and resilience, PowerShell execution, obfuscation, and links to Sednit's earlier tools and operations.

### Source excerpt

The resurgence of one of Russia's most notorious APT groups

## PromptSpy ushers in the era of Android threats using GenAI

DevFeed: [PromptSpy ushers in the era of Android threats using GenAI](<https://devfeed.tech/articles/promptspy-ushers-in-the-era-of-android-threats-using-genai-8379.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/promptspy-ushers-in-era-android-threats-using-genai/>)

Author: Lukas Stefanko

Published: 2026-02-19T10:30:20Z

Content type: news

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Android](<https://devfeed.tech/topics/android.md>), [Generative AI](<https://devfeed.tech/topics/generative-ai.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [genai](<https://devfeed.tech/topics/genai.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [Persistence](<https://devfeed.tech/topics/persistence.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Google](<https://devfeed.tech/topics/google.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [android](<https://devfeed.tech/tags/android.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [genai](<https://devfeed.tech/tags/genai.md>), [generative-ai](<https://devfeed.tech/tags/generative-ai.md>), [google](<https://devfeed.tech/tags/google.md>), [malware](<https://devfeed.tech/tags/malware.md>), [persistence](<https://devfeed.tech/tags/persistence.md>), [server](<https://devfeed.tech/tags/server.md>), [video](<https://devfeed.tech/tags/video.md>)

### AI overview

ESET researchers report PromptSpy, an Android malware family that uses Google Gemini and generative AI to analyze the device screen and adapt malicious user-interface manipulation. The malware uses this capability to maintain persistence, while also providing remote access, blocking uninstallation, capturing lockscreen data, and recording video.

### Source excerpt

ESET researchers discover PromptSpy, the first known Android malware to abuse generative AI in its execution flow

## DynoWiper update: Technical analysis and attribution

DevFeed: [DynoWiper update: Technical analysis and attribution](<https://devfeed.tech/articles/dynowiper-update-technical-analysis-and-attribution-8360.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/dynowiper-update-technical-analysis-attribution/>)

Author: ESET Research

Published: 2026-01-30T10:28:38Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [Security](<https://devfeed.tech/topics/security.md>), [incident](<https://devfeed.tech/topics/incident.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [blog](<https://devfeed.tech/tags/blog.md>), [energy](<https://devfeed.tech/tags/energy.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [incident](<https://devfeed.tech/tags/incident.md>), [malware](<https://devfeed.tech/tags/malware.md>), [post](<https://devfeed.tech/tags/post.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

ESET provides a technical analysis of DynoWiper, a data-wiping malware used against an energy company in Poland. The article compares the incident with the earlier ZOV wiper attack in Ukraine and attributes DynoWiper to the Sandworm threat group with medium confidence.

### Source excerpt

ESET researchers present technical details on a recent data destruction incident affecting a company in Poland's energy sector

## Love? Actually: Fake dating app used as lure in targeted spyware campaign in Pakistan

DevFeed: [Love? Actually: Fake dating app used as lure in targeted spyware campaign in Pakistan](<https://devfeed.tech/articles/love-actually-fake-dating-app-used-as-lure-in-targeted-spyware-campaign-in-pakistan-8375.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/love-actually-fake-dating-app-used-lure-targeted-spyware-campaign-pakistan/>)

Author: Lukas Stefanko

Published: 2026-01-28T09:59:00Z

Content type: news

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [App](<https://devfeed.tech/topics/app.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [app](<https://devfeed.tech/tags/app.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [clickfix](<https://devfeed.tech/tags/clickfix.md>), [data](<https://devfeed.tech/tags/data.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [monitor](<https://devfeed.tech/tags/monitor.md>), [pakistan](<https://devfeed.tech/tags/pakistan.md>), [scam](<https://devfeed.tech/tags/scam.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [whatsapp](<https://devfeed.tech/tags/whatsapp.md>)

### AI overview

ESET describes GhostChat, an Android spyware app that poses as a dating chat platform to target people in Pakistan. Its hardcoded profile passcodes create a false sense of exclusivity while the app surveils devices and exfiltrates data; the investigation also links the activity to ClickFix and WhatsApp account-compromise attacks.

### Source excerpt

ESET researchers discover an Android spyware campaign targeting users in Pakistan via romance scam tactics, revealing links to a broader spy operation

## ESET Research: Sandworm behind cyberattack on Poland's power grid in late 2025

DevFeed: [ESET Research: Sandworm behind cyberattack on Poland's power grid in late 2025](<https://devfeed.tech/articles/eset-research-sandworm-behind-cyberattack-on-poland-s-power-grid-in-late-2025-8363.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/eset-research-sandworm-cyberattack-poland-power-grid-late-2025/>)

Author: ESET Research

Published: 2026-01-23T16:58:26Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [ESET research](<https://devfeed.tech/topics/eset-research.md>), [Critical Infrastructure](<https://devfeed.tech/topics/critical-infrastructure.md>), [apt](<https://devfeed.tech/topics/apt.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [apt](<https://devfeed.tech/tags/apt.md>), [critical-infrastructure](<https://devfeed.tech/tags/critical-infrastructure.md>), [energy](<https://devfeed.tech/tags/energy.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [history](<https://devfeed.tech/tags/history.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [malware](<https://devfeed.tech/tags/malware.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

ESET Research attributes a late-2025 cyberattack on Poland's power grid to the Russia-aligned Sandworm APT group with medium confidence. The attack used data-wiping malware named DynoWiper, although no successful disruption has been identified. The article places the incident in the context of Sandworm's history of attacks on critical infrastructure, including the 2015 Ukrainian power-grid blackout.

### Source excerpt

The attack involved data-wiping malware that ESET researchers have now analyzed and named DynoWiper

## Revisiting CVE-2025-50165: A critical flaw in Windows Imaging Component

DevFeed: [Revisiting CVE-2025-50165: A critical flaw in Windows Imaging Component](<https://devfeed.tech/articles/revisiting-cve-2025-50165-a-critical-flaw-in-windows-imaging-component-8380.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/revisiting-cve-2025-50165-critical-flaw-windows-imaging-component/>)

Author: Romain Dumont

Published: 2025-12-22T09:55:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Code](<https://devfeed.tech/topics/code.md>), [Library](<https://devfeed.tech/topics/library.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [cve](<https://devfeed.tech/tags/cve.md>), [deep-dive](<https://devfeed.tech/tags/deep-dive.md>), [encoding](<https://devfeed.tech/tags/encoding.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [jpeg](<https://devfeed.tech/tags/jpeg.md>), [library](<https://devfeed.tech/tags/library.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [root-cause-analysis](<https://devfeed.tech/tags/root-cause-analysis.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

ESET analyzes CVE-2025-50165, a critical Windows Imaging Component vulnerability in WindowsCodecs.dll. The flaw involves an uninitialized function-pointer dereference during JPG compression and re-encoding, and the article reassesses how difficult the vulnerability is to exploit.

### Source excerpt

A comprehensive analysis and assessment of a critical severity vulnerability with low likelihood of mass exploitation

## LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan

DevFeed: [LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan](<https://devfeed.tech/articles/longnosedgoblin-tries-to-sniff-out-governmental-affairs-in-southeast-asia-and-japan-8374.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/longnosedgoblin-tries-sniff-out-governmental-affairs-southeast-asia-japan/>)

Author: Anton Cherepanov Peter Strýček

Published: 2025-12-18T10:00:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [backdoor](<https://devfeed.tech/topics/backdoor.md>), [.NET](<https://devfeed.tech/topics/net.md>), [enterprise deployment](<https://devfeed.tech/topics/enterprise-deployment.md>)

Tags: [apt](<https://devfeed.tech/tags/apt.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [browser](<https://devfeed.tech/tags/browser.md>), [c-sharp](<https://devfeed.tech/tags/c-sharp.md>), [china](<https://devfeed.tech/tags/china.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-services](<https://devfeed.tech/tags/cloud-services.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [google](<https://devfeed.tech/tags/google.md>), [japan](<https://devfeed.tech/tags/japan.md>), [malware](<https://devfeed.tech/tags/malware.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [net](<https://devfeed.tech/tags/net.md>), [policy](<https://devfeed.tech/tags/policy.md>), [techniques](<https://devfeed.tech/tags/techniques.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

ESET describes LongNosedGoblin, a China-aligned APT group conducting cyberespionage against governmental entities in Southeast Asia and Japan. The group deploys malware through Group Policy and uses tools including the NosyDoor backdoor and the C#/.NET NosyHistorian application.

### Source excerpt

ESET researchers discovered a China-aligned APT group, LongNosedGoblin, which uses Group Policy to deploy cyberespionage tools across networks of governmental institutions

## ESET Threat Report H2 2025

DevFeed: [ESET Threat Report H2 2025](<https://devfeed.tech/articles/eset-threat-report-h2-2025-8366.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/eset-threat-report-h2-2025/>)

Author: Jiří Kropáč

Published: 2025-12-16T09:50:45Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [ESET research](<https://devfeed.tech/topics/eset-research.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Android](<https://devfeed.tech/topics/android.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [ClickFix](<https://devfeed.tech/topics/clickfix.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [ai](<https://devfeed.tech/tags/ai.md>), [android](<https://devfeed.tech/tags/android.md>), [clickfix](<https://devfeed.tech/tags/clickfix.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [malware](<https://devfeed.tech/tags/malware.md>), [nfc](<https://devfeed.tech/tags/nfc.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [research](<https://devfeed.tech/tags/research.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>), [threat-report](<https://devfeed.tech/tags/threat-report.md>)

### AI overview

ESET's H2 2025 threat report describes rapid changes in the threat landscape, including the emergence of AI-driven malware such as PromptLock, major shifts in malware distribution, growth in ransomware activity, and increasingly sophisticated Android NFC threats.

### Source excerpt

A view of the H2 2025 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts

## MuddyWater: Snakes by the riverbank

DevFeed: [MuddyWater: Snakes by the riverbank](<https://devfeed.tech/articles/muddywater-snakes-by-the-riverbank-8376.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/muddywater-snakes-riverbank/>)

Author: ESET Research

Published: 2025-12-02T10:00:15Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [backdoor](<https://devfeed.tech/topics/backdoor.md>), [C++](<https://devfeed.tech/topics/c-plus-plus.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [api](<https://devfeed.tech/tags/api.md>), [apt](<https://devfeed.tech/tags/apt.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [c](<https://devfeed.tech/tags/c.md>), [c-c-plus-plus](<https://devfeed.tech/tags/c-c-plus-plus.md>), [c-plus-plus](<https://devfeed.tech/tags/c-plus-plus.md>), [critical-infrastructure](<https://devfeed.tech/tags/critical-infrastructure.md>), [cryptographic](<https://devfeed.tech/tags/cryptographic.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [iran](<https://devfeed.tech/tags/iran.md>), [malware](<https://devfeed.tech/tags/malware.md>), [memory](<https://devfeed.tech/tags/memory.md>), [persistence](<https://devfeed.tech/tags/persistence.md>), [socks5](<https://devfeed.tech/tags/socks5.md>), [techniques](<https://devfeed.tech/tags/techniques.md>), [tools](<https://devfeed.tech/tags/tools.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

ESET analyzes a MuddyWater campaign targeting organizations in Israel and Egypt that uses custom loaders, credential stealers, reverse tunnels, and the MuddyViper backdoor to evade defenses and maintain access.

### Source excerpt

MuddyWater targets critical infrastructure in Israel and Egypt, relying on custom malware, improved tactics, and a predictable playbook