At #DEFCON34, @LukasStefanko explores the real-world attack techniques targeting mobile devices and what defenders need to know to stay ahead. 1/3
ESET Research
@esetresearch.bsky.social
Security research and breaking news straight from ESET Research Labs. welivesecurity.com/research/
In H1 2026, #ESETresearch analyzed 900,000 agentic AI skills – add-ons providing instructions that teach agents how to perform specific tasks – and found 25,000 suspicious ones and more than 3,000 outright malicious. 1/6
In H1 2026, #ESETresearch continued tracking a growing number of #EDR killers, currently counting 100+ such tools. The dominant approach is still BYOVD, with 60+ of the EDR killers abusing legitimate yet vulnerable drivers. 1/5
QR code phishing – also known as #quishing – reached record levels in ESET telemetry in H1 2026 as attackers exploit the widespread adoption of QR codes in everyday life. The technique is evolving rapidly in terms of automation, scalability, and detection evasion. 1/5
ESET detections of #ClickFix doubled (+108%) between H2 2025 and H1 2026 as attackers expanded beyond fake CAPTCHAs to AI platforms (#AI-fix), browser extensions (#CrashFix), and cloud authentication workflows (#ConsentFix). 1/5
#ESETresearch discovered and reported to @certcc 11 old Microsoft-signed UEFI shim bootloaders that allow bypassing UEFI Secure Boot on most UEFI systems. Read about it at www.welivesecurity.com/en/eset-rese... 1/5
Forgotten UEFI shims undermining Secure Boot
ESET researchers discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass UEFI Secure Boot by exploiting decade-old vulnerabilities.
welivesecurity.com
ESET Threat Report H1 2026: thousands of malicious Agentic AI skills identified, first AI-powered Android malware appears, and ClickFix expands beyond fake CAPTCHA prompts. Attackers are rapidly adapting to new platforms and technologies . Full report: web-assets.esetstatic.com/wls/en/paper...
#ESETresearch has published a technical analysis of new malicious tools and major infrastructure changes observed in 2025 in the arsenal of the Russia-aligned #Gamaredon #APTgroup targeting Ukraine 🇺🇦. Blogpost: www.welivesecurity.com/en/eset-rese... 1/8
Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances
ESET Research analyzes Gamaredon’s new toolset and the group’s growing reliance on legitimate online services to hide its C&C infrastructure and exfiltrate stolen data.
welivesecurity.com
#ESETresearch analyzed the robust EDR-killer toolset of the RaaS gang Gentlemen. Thanks to our continued incident-level visibility, we could provide a uniquely deep view into the group’s EDR-killer development practices. www.welivesecurity.com/en/eset-rese... 1/6
welivesecurity.com
#ESETresearch has observed DeadLock ransomware expanding its use of Polygon blockchain smart contracts. Previously used only for chat proxy server address rotation, DeadLock has now added a new contract with the gang's DLS entries - a first of its kind we are aware of. 1/6
#ESETresearch discovered two as-yet undocumented Windows variants of #SprySOCKS, a previously Linux-only backdoor reportedly used by #FishMonger. We attribute the new Windows variants to #FishMonger with high confidence. www.welivesecurity.com/en/eset-rese... 1/4
FishMonger’s arsenal upgraded: SprySOCKS for Windows
ESET researchers have discovered SprySOCKS for Windows, FishMonger’s backdoor weaponizing a kernel driver for advanced stealthiness.
welivesecurity.com
#ESETresearch has discovered a supply-chain attack targeting stock investors in Vietnam, distributing SPECTRALVIPER through the update mechanism of the FireAnt Metakit stock investment platform. www.welivesecurity.com/en/eset-rese... 1/4
#ESETresearch released its latest APT Activity Report (Oct 2025–Mar 2026): 🇨🇳China-aligned groups focused on Venezuela, Gulf states, and AI & robotics industry in 🇰🇷South Korea, while 🇰🇵North Korea-aligned APTs targeted the nuclear sector. Full report: web-assets.esetstatic.com/wls/en/paper...
#ESETresearch analyzed 2025 activity of the China -aligned Webworm APT group, focusing on its evolving toolset and techniques. www.welivesecurity.com/en/eset-rese... 1/8
Webworm: New burrowing techniques
ESET researchers describe new tools and techniques that the Webworm APT group recently added to its arsenal.
welivesecurity.com
#ESETresearch uncovered a new compromise that we attribute to #FrostyNeighbor, using links in malicious PDFs sent via spearphishing attachments to target governmental organizations in Ukraine. @dmnsch welivesecurity.com/en/eset-rese... 1/5
#ESETresearch has uncovered CallPhantom scam apps, previously available on Google Play, that claim to provide call history data for any phone number, in exchange for payment. That’s impossible – and the data is entirely fabricated. www.welivesecurity.com/en/eset-rese... 1/5
#ESETresearch uncovered a multiplatform supply-chain attack by the North Korean #ScarCruft APT group targeting the Yanbian region via backdoor-laced Windows and Android games. www.welivesecurity.com/en/eset-rese... 1/6
Approximately a month ago, F5 published advisory on malware deployed to BIG-IP systems vulnerable to CVE-2025-53521. #ESETresearch discovered two related malware components on VirusTotal and named the threat #PoisonedRefresh. 1/6 my.f5.com/manage/s/art...
myF5
my.f5.com
#BREAKING #ESETresearch uncovered an active NGate Android malware campaign targeting Spanish speaking users, combining fake app distribution, NFC relay abuse, PIN harvesting, and a shared Devil NFC MaaS backend. The operation is tied to the Devil NFC infrastructure used in Spain since Jan 2026 1/10
#ESETresearch discovered #GopherWhisper, a new China-aligned APT group that targeted a governmental entity in Mongolia. www.welivesecurity.com/en/eset-rese... 1/7
welivesecurity.com
#ESETresearch discovered a new #NGate malware variant that abuses the legitimate #HandyPay app, which has been patched with possibly AI-generated malicious code. The campaign is ongoing and targets Android users in Brazil. www.welivesecurity.com/en/eset-rese... 1/6
welivesecurity.com
Cisco Talos recently published an analysis of an EDR killer used by the #Qilin #ransomware gang. #ESETresearch tracks this threat as #CardSpaceKiller and we recently provided additional insights in our blog www.welivesecurity.com/en/eset-rese... 1/6
EDR killers explained: Beyond the drivers
ESET researchers dive deeper into the EDR killer ecosystem, disclosing how attackers abuse vulnerable drivers.
welivesecurity.com
#ESETresearch's Eric Howard will be presenting at Botconf. Join him in Reims, France to hear about “GopherWhisper, Uncovering an APT’s secrets through its own words” on Apr 15 at 17.15 CEST. For more information, check out www.botconf.eu/botconf-2026... 1/3
#ESETresearch has identified an Akira lookalike ransomware campaign targeting South America. The threat actor is using a Babukbased encryptor that appends the .akira extension and drops a ransom note that mimics Akira both in Tor URLs and the overall content. 1/5
#ESETresearch has identified a Silver Fox campaign that actively takes advantage of the current annual tax filing and organizational change season in Japan, a period when companies generate a high volume of legitimate financial and HRrelated comms. www.welivesecurity.com/en/business-... 1/8
A cunning predator: How Silver Fox preys on Japanese firms this tax season
Silver Fox is back in Japan, spoofing tax and HR emails timed to the one season when many people don’t think twice about opening them
welivesecurity.com
#ESETresearch detected a recent intrusion at a University of Warsaw consistent with #Interlock ransomware gang. Thanks to early warning from our experts and the university's swift cooperation, the attack was disrupted before encryptors could be deployed. www.eset.com/pl/about/new... 1/8
To analitycy ESET zidentyfikowali atak na Uniwersytet Warszawski
News about ESET's events and conferences, directly from the maker of legendary NOD32 technology.
eset.com
In cybersecurity, labels can distract from what really matters. At #RSAC2026, #ESETresearch’s Robert Lipovský will break down recent campaigns linked to state-sponsored actors and explore how hybrid threat tactics are evolving. The session focuses on practical defender takeaways.
#ESETresearch is hiring! Passionate about geopolitics, cyberespionage and cyber threat intelligence? We have a new opening for a strategic threat intelligence analyst at our Montréal office. Come join the team! eset.wd3.myworkdayjobs.com/ESET_Externa...
Analyste du renseignement stratégique sur les menaces – Cyberespionnage / Strategic Threat Intelligence Analyst – Cyberespionage
Résumé du poste / Summary English version follows ------------------------------------------------------------------------------------------------------------------------------- Nous sommes à la reche...
eset.wd3.myworkdayjobs.com
#ESETresearch analyzed more than 80 EDR killers, seen across real-world intrusions, and used ESET telemetry to document how these tools operate, who uses them, and how they evolve beyond simple driver abuse. www.welivesecurity.com/en/eset-rese... 1/6
#ESETresearch has analyzed the resurgence of Sednit – one of the most long‑running Russia‑aligned APT groups – now using a modern toolkit built around paired implants, BeardShell and Covenant, each using a different cloud provider for resilience. www.welivesecurity.com/en/eset-rese... 1/5
Sednit reloaded: Back in the trenches
ESET researchers document how the Sednit APT group has reemerged with a modern toolkit centered on two paired implants – BeardShell and Covenant.
welivesecurity.com