# ESET research

ESET Threat Research is ESET's cybersecurity research operation focused on threat and software-vulnerability research.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## ESET Threat Report H1 2026

DevFeed: [ESET Threat Report H1 2026](<https://devfeed.tech/articles/eset-threat-report-h1-2026-8365.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/>)

Author: Jiří Kropáč

Published: 2026-07-08T08:45:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [ESET research](<https://devfeed.tech/topics/eset-research.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Generative AI](<https://devfeed.tech/topics/generative-ai.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Android](<https://devfeed.tech/topics/android.md>), [ClickFix](<https://devfeed.tech/topics/clickfix.md>), [QR Code](<https://devfeed.tech/topics/qrcode.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [android](<https://devfeed.tech/tags/android.md>), [clickfix](<https://devfeed.tech/tags/clickfix.md>), [code](<https://devfeed.tech/tags/code.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [generative-ai](<https://devfeed.tech/tags/generative-ai.md>), [malware](<https://devfeed.tech/tags/malware.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [threat-report](<https://devfeed.tech/tags/threat-report.md>)

### AI overview

ESET's H1 2026 threat report describes attackers adapting established techniques across new platforms and behaviors. It highlights the expanding abuse of AI skills, PromptSpy Android malware using Google Gemini, the spread of ClickFix and QR-code phishing, and continued ransomware activity involving EDR killers.

### Source excerpt

A view of the H1 2026 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts.

## ESET takes part in Operation Endgame to disrupt Amadey and Stealc

DevFeed: [ESET takes part in Operation Endgame to disrupt Amadey and Stealc](<https://devfeed.tech/articles/eset-takes-part-in-operation-endgame-to-disrupt-amadey-and-stealc-8364.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/eset-takes-part-operation-endgame-disrupt-amadey-stealc/>)

Author: Jakub Tomanek Tomáš Procházka

Published: 2026-06-24T12:35:24Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [ESET research](<https://devfeed.tech/topics/eset-research.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [C2](<https://devfeed.tech/topics/c2.md>), [High Profile Threats](<https://devfeed.tech/topics/high-profile-threats.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [data](<https://devfeed.tech/topics/data.md>), [Statistics](<https://devfeed.tech/topics/statistics.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [data](<https://devfeed.tech/tags/data.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [maas](<https://devfeed.tech/tags/maas.md>), [malware](<https://devfeed.tech/tags/malware.md>), [network](<https://devfeed.tech/tags/network.md>), [research](<https://devfeed.tech/tags/research.md>)

### AI overview

ESET Research describes its contribution to Operation Endgame, a coordinated global effort that disrupted the Amadey botnet and Stealc infostealer. The article covers infrastructure tracking, technical and statistical analysis, malware configuration data, command-and-control servers, encryption keys, campaign identifiers, and affiliate-level activity within the malware-as-a-service ecosystem.

### Source excerpt

ESET researchers assisted in the global disruption of the Amadey botnet and Stealc infostealer, providing technical analysis, infrastructure tracking, and affiliate-level insights

## Killing me gently: Inside Gentlemen's EDR killer framework

DevFeed: [Killing me gently: Inside Gentlemen's EDR killer framework](<https://devfeed.tech/articles/killing-me-gently-inside-gentlemen-s-edr-killer-framework-8373.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/killing-me-gently-inside-gentlemens-edr-killer-framework/>)

Author: Jakub Souček

Published: 2026-06-18T09:46:32Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [ESET research](<https://devfeed.tech/topics/eset-research.md>), [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [Software](<https://devfeed.tech/topics/software.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [europe](<https://devfeed.tech/tags/europe.md>), [insights](<https://devfeed.tech/tags/insights.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>), [software](<https://devfeed.tech/tags/software.md>), [southeast-asia](<https://devfeed.tech/tags/southeast-asia.md>), [techniques](<https://devfeed.tech/tags/techniques.md>)

### AI overview

ESET Research analyzes Gentlemen's ransomware-as-a-service operation and its portfolio of EDR-killing tools. The article examines the in-house GentleKiller framework, third-party tools, shared defense-evasion techniques, and the group's rapid adoption of BYOVD exploits, using incident-level visibility and leaked internal data.

### Source excerpt

ESET Research shares the results of a months-long investigation into the suite of EDR killers maintained by the RaaS gang Gentlemen

## New NGate variant hides in a trojanized NFC payment app

DevFeed: [New NGate variant hides in a trojanized NFC payment app](<https://devfeed.tech/articles/new-ngate-variant-hides-in-a-trojanized-nfc-payment-app-8377.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/new-ngate-variant-hides-in-a-trojanized-nfc-payment-app/>)

Author: Lukas Stefanko

Published: 2026-04-21T08:55:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [Android](<https://devfeed.tech/topics/android.md>), [ESET research](<https://devfeed.tech/topics/eset-research.md>), [genai](<https://devfeed.tech/topics/genai.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [App](<https://devfeed.tech/topics/app.md>), [servers](<https://devfeed.tech/topics/servers.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [brazil](<https://devfeed.tech/tags/brazil.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [genai](<https://devfeed.tech/tags/genai.md>), [malware](<https://devfeed.tech/tags/malware.md>), [payment](<https://devfeed.tech/tags/payment.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [threat-report](<https://devfeed.tech/tags/threat-report.md>)

### AI overview

ESET Research reports a new NGate malware variant hidden in a trojanized Android NFC payment app called HandyPay. The malware relays payment-card NFC data, steals card PINs, and exfiltrates them to an operator-controlled server. The active campaign, targeting users in Brazil since around November 2025, distributes the app through fake lottery and Google Play websites; the code may have been assisted by GenAI.

### Source excerpt

ESET researchers discover another iteration of NGate malware, this time possibly developed with the assistance of AI

## ESET Research: Sandworm behind cyberattack on Poland's power grid in late 2025

DevFeed: [ESET Research: Sandworm behind cyberattack on Poland's power grid in late 2025](<https://devfeed.tech/articles/eset-research-sandworm-behind-cyberattack-on-poland-s-power-grid-in-late-2025-8363.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/eset-research-sandworm-cyberattack-poland-power-grid-late-2025/>)

Author: ESET Research

Published: 2026-01-23T16:58:26Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [ESET research](<https://devfeed.tech/topics/eset-research.md>), [Critical Infrastructure](<https://devfeed.tech/topics/critical-infrastructure.md>), [apt](<https://devfeed.tech/topics/apt.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [apt](<https://devfeed.tech/tags/apt.md>), [critical-infrastructure](<https://devfeed.tech/tags/critical-infrastructure.md>), [energy](<https://devfeed.tech/tags/energy.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [history](<https://devfeed.tech/tags/history.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [malware](<https://devfeed.tech/tags/malware.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

ESET Research attributes a late-2025 cyberattack on Poland's power grid to the Russia-aligned Sandworm APT group with medium confidence. The attack used data-wiping malware named DynoWiper, although no successful disruption has been identified. The article places the incident in the context of Sandworm's history of attacks on critical infrastructure, including the 2015 Ukrainian power-grid blackout.

### Source excerpt

The attack involved data-wiping malware that ESET researchers have now analyzed and named DynoWiper

## ESET Threat Report H2 2025

DevFeed: [ESET Threat Report H2 2025](<https://devfeed.tech/articles/eset-threat-report-h2-2025-8366.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/eset-threat-report-h2-2025/>)

Author: Jiří Kropáč

Published: 2025-12-16T09:50:45Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [ESET research](<https://devfeed.tech/topics/eset-research.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Android](<https://devfeed.tech/topics/android.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [ClickFix](<https://devfeed.tech/topics/clickfix.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [ai](<https://devfeed.tech/tags/ai.md>), [android](<https://devfeed.tech/tags/android.md>), [clickfix](<https://devfeed.tech/tags/clickfix.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [malware](<https://devfeed.tech/tags/malware.md>), [nfc](<https://devfeed.tech/tags/nfc.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [research](<https://devfeed.tech/tags/research.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>), [threat-report](<https://devfeed.tech/tags/threat-report.md>)

### AI overview

ESET's H2 2025 threat report describes rapid changes in the threat landscape, including the emergence of AI-driven malware such as PromptLock, major shifts in malware distribution, growth in ransomware activity, and increasingly sophisticated Android NFC threats.

### Source excerpt

A view of the H2 2025 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts