#BREAKNG#ESETresearch identified the wiper #DynoWiper used in an attempted disruptive cyberattack against the 🇵🇱 Polish energy sector on Dec 29, 2025. At this point, no successful disruption is known, but the malware’s design clearly indicates destructive intent. 1/5
#ESETresearch’s Robert Lipovský will present at Labscon 2025 @labscon_io: “ The Curse of Salt Typhoon: FamousSparrow goes after the US financial sector“. Join him in Scottsdale, AZ, September 19 at 12:00 PM MST 1/5
New today from @Mandiant detailing a new class of cyber physical attack from Sandworm to disrupt Ukraine's grid
This attack departs from the group’s history of using OT-specific malware, instead opting for a harder to detect living off the land approach
https://t.co/reqGJSQxmt
#ESETResearch discovered a zero-day XSS vulnerability (#CVE-2023-5631) in Roundcube Webmail servers. It is actively used in the wild by #WinterVivern to target governments and a think tank in Europe. The exploit was contained in a legitimate-looking email about Outlook. 1/4
#ESETresearch discovered a #cyberespionage campaign against a governmental entity in 🇬🇾 Guyana, which we named #Operation Jacana. To gain initial access, the attackers used #spearphishing emails referencing the political affairs of the country. https://t.co/Ysh7skylez 1/4
#ESETresearch document two #OilRig cyberespionage campaigns targeting Israeli organizations in 2021 and 2022: Outer Space and Juicy Mix https://t.co/iswkPkZtCj @zuzana_hromcova 1/5
#ESETresearch’s Filip Jurčacko and @zuzana_hromcova will be presenting at @labscon_io this week. Join them in Arizona to hear about #Deadglyph, a new, sophisticated backdoor active in the Middle East, and #OilRig’s persistent attacks on Israeli healthcare & local governments. 1/2
#ESETResearch publishes new findings about #AsylumAmbuscade, a threat actor at the border between cybercrime and cyberespionage. https://t.co/sxseRKw5sk 1/4
@ESETresearch took a closer look at #AceCryptor, a massively prevalent cryptor-as-a-service using its multistage approach to protect tens of malware families from static and dynamic detection. In 2021–2022 alone, ESET telemetry documented its activity in over 80,000 cases. 1/10
#ESETResearch analyze first in-the-wild UEFI bootkit bypassing UEFI Secure Boot even on fully updated Windows 11 systems. Its functionality indicates it is the #BlackLotus UEFI bootkit, for sale on hacking forums since at least Oct 6, 2022. @smolar_m https://t.co/mXSXksRisG 1/11
Today, we mark the one year anniversary of Russia's unprovoked invasion of #Ukraine 🇺🇦. #ESETResearch has put together a timeline of the disruptive wiper attacks we have observed in Ukraine since the beginning of 2022, shortly before the war started. https://t.co/mwPxVqa5hJ
Ahead of the 1 year anniversary of the war in Ukraine, @WIRED’s @a_greenberg featured ESET researchers @cherepanov74 & @Robert_lipovsky in a story highlighting the increasing threat of wiper malware & its devastating impact on critical infrastructure. https://t.co/Jn0R0H1MeB
#BREAKING On January 25th #ESETResearch discovered a new cyberattack in 🇺🇦 Ukraine. Attackers deployed a new wiper we named #SwiftSlicer using Active Directory Group Policy. The #SwiftSlicer wiper is written in Go programing language. We attribute this attack to #Sandworm. 1/3
#ESETesearch discovered Dolphin, a sophisticated backdoor extending the arsenal of the #ScarCruft APT group. Dolphin has a wide range of spying capabilities and is deployed on selected targets only.
https://t.co/M2LmS5bW7w 1/6
Today's newsletter is now available as a podcast, with an appearance today from ESET's @Robert_Lipovsky and the company's work on tracking Polonium APT campaigns in Israel
https://t.co/t46rQVCW38
#Emotet’s operators were busy updating their systeminfo module, with changes that enable malware operators to improve the targeting of specific victims and distinguish tracking bots from real users. #ESETresearch 1/7