ESET Research
@esetresearch
Security research and breaking news straight from ESET Research Labs. welivesecurity.com/research/
At #DEFCON34, @LukasStefanko explores the real-world attack techniques targeting mobile devices and what defenders need to know to stay ahead. 1/3
One skill, labeled by ESET as suspicious, was instructed to create a persistence mechanism via a JSON file and a tool for self-modification in Python. While this can improve the skill, it can also lead to unpredictable agent behavior or abuse by an attacker. 4/6
Their instructions referenced external offensive security tools and platforms such as Impacket, Mimikatz, or BloodHound. In other words, some AI skills do not just “help” an agent – they can steer it toward offensive behavior. 3/6
The report also details #ESETresearch findings from the Gentlemen leak. We found the gang uses a shared defense-evasion layer across its EDR killer suite – spanning in-house GentleKiller, third-party, and leaked tools – and can operationalize new BYOVD PoCs within days. 3/5
The emails seen in H1 2026 commonly posed as corporate HR communication, especially related to pay and benefits – a topic likely to raise recipients’ curiosity. Much like in most phishing attacks, the messages were often personalized and introduced a sense of urgency. 3/5
11% of all phishing emails detected in H1 2026 utilized[BB1.1] QR codes[KK2.1]. On average, we saw [BB3.1]100,000 QRCode/Phishing detections per month, with the highest levels recorded in April. Most detections came from the US (19%), Spain (17%), and Mexico (6%). 2/5
QR code phishing – also known as #quishing – reached record levels in ESET telemetry in H1 2026 as attackers exploit the widespread adoption of QR codes in everyday life. The technique is evolving rapidly in terms of automation, scalability, and detection evasion. 1/5
Another ClickFix evolution, CrashFix, operates in the browser environment through a fake ad blocker, causing fake browser crashes and displaying warnings of data loss to pressure victims into following malicious "quick fix" instructions. 3/5
In AI-fix attacks, attackers craft web pages that impersonate legitimate AI services, including #Anthropic Artifacts, #OpenAI Canvas, and Microsoft #Copilot Pages. The web pages display fake troubleshooting content designed to trick users into executing malicious commands. 2/5
ESET detections of #ClickFix doubled (+108%) between H2 2025 and H1 2026 as attackers expanded beyond fake CAPTCHAs to AI platforms (#AI-fix), browser extensions (#CrashFix), and cloud authentication workflows (#ConsentFix). 1/5
ESET Threat Report H1 2026: thousands of malicious Agentic AI skills identified, first AI-powered Android malware appears, and ClickFix expands beyond fake CAPTCHA prompts. Attackers are rapidly adapting to new platforms and technologies . Full report: web-assets.esetstatic.com/wls/en/paper...
In 2025, #Gamaredon exclusively targeted Ukrainian governmental and military institutions. We observed 35 distinct #spearphishing campaigns, with activity significantly increasing in the second half of the year, as shown in the graph. 2/8
The WIN_DRV variant creates a stealthy passive TCP backdoor and uses a kernel driver to redirect traffic to the backdoor’s hidden TCP port whenever specially crafted data is detected inside a received TCP packet. 3/4
On top of the on-chain DLS, DeadLock recently registered a clearweb domain deadlock.liveblog365[.]com. The site works the same way as their HTML ransom notes - both query the Blog smart contract for victim data, combining blockchain resilience with clearweb accessibility. 4/6
DeadLock’s HTML ransom notes are interactive, providing access to a Session-style messaging client and now also the DLS, that is displayed to victims directly embedded in the HTML ransom note, fetched on the fly from the smart contracts. 2/6
Both newly discovered Windows variants, named WIN_PLUS and WIN_DRV by their authors, support communication over TCP, UDP, and WebSocket protocols, while WIN_DRV weaponizes a kernel driver for enhanced stealth. 2/4
#ESETresearch has discovered a supply-chain attack targeting stock investors in Vietnam, distributing SPECTRALVIPER through the update mechanism of the FireAnt Metakit stock investment platform. www.welivesecurity.com/en/eset-rese... 1/4
#ESETresearch released its latest APT Activity Report (Oct 2025–Mar 2026): 🇨🇳China-aligned groups focused on Venezuela, Gulf states, and AI & robotics industry in 🇰🇷South Korea, while 🇰🇵North Korea-aligned APTs targeted the nuclear sector. Full report: web-assets.esetstatic.com/wls/en/paper...
While going over EchoCreep’s Discord messages, we uncovered a GitHub repository that was a direct fork of the legitimate WordPress repository. Webworm uses it as a file stager for its tools and malware. 5/8
On an operator server, we discovered a directory listing with open-source utilities used to scrape victim web server files and directories, and to search for vulnerabilities within. One directory contained reconnaissance commands used against more than 50 unique targets. 4/8
#ESETresearch uncovered a new compromise that we attribute to #FrostyNeighbor, using links in malicious PDFs sent via spearphishing attachments to target governmental organizations in Ukraine. @dmnsch welivesecurity.com/en/eset-rese... 1/5
While some apps requested payment in the form of Google Play subscriptions, others redirected users to third party payment apps or requested card details directly in the app – complicating refund efforts and exposing victims to financial risk. 4/5
We identified 28 CallPhantom apps on Google Play, collectively downloaded 7.3+ million times before we reported them to Google. After victims had paid, the apps generated random phone numbers and matched them with hardcoded names, call times, and durations. 2/5
#ESETresearch has uncovered CallPhantom scam apps, previously available on Google Play, that claim to provide call history data for any phone number, in exchange for payment. That’s impossible – and the data is entirely fabricated. www.welivesecurity.com/en/eset-rese... 1/5
The malicious httpd process patches functions apr_so_load and apr_time_now in libphp, and also close, open, __fxstat and mmap. The former triggers bind shell and webshell deployment, while the latter ensures webshell content is visible only for the malicious httpd process. 4/6
Interestingly, for /mnt/tm_install/usr, the sample also infects umount, httpd, and rc.local files located within the tm_install directory. This is presumably done to infect the installation media, allowing the malware to persist and spread to other BIG-IP systems. 3/6
First, umount infects /usr/sbin/httpd by prepending a malicious ELF binary to the legitimate binary, as long as the first command-line argument is /mnt/tm_install/<dir>. The sample is expected to be run as root and will disable SELinux. 2/6
Historical connection: We have identified that this activity targeteing Spanish speaking users directly connects to earlier Devil NFC MaaS campaigns impersonating: Shein, CaixaBank, Santander Protect, Seguridad Integral, Unicaja Key, Dispositivo Seguro, Unicaja Protect, Seguridad NFC 8/10
Bank‑branded NFC phishing: NGate supports custom bank‑branded NFC phishing templates, embedded at build time by the operator. In this campaign, we observed templates impersonating Santander Bank, shifting from generic warnings to targeted bank abuse. 5/10