Archive for ESET

Guest Post – ESET Research uncovers Operation RoundPress: Russia-aligned Sednit targets entities linked to the Ukraine war to steal confidential data

Posted in Commentary with tags on May 15, 2025 by itnerd

ESET researchers have uncovered a Russia-aligned espionage operation, which ESET named RoundPress, targeting webmail servers via XSS vulnerabilities. Behind it is most likely the Russia-aligned Sednit (also known as Fancy Bear or APT28) cyberespionage group, holding the ultimate goal of stealing confidential data from specific email accounts. Most of the targets are related to the current war in Ukraine; they are either Ukrainian governmental entities or defense companies in Bulgaria and Romania. Notably, some of these defense companies are producing Soviet-era weapons to be sent to Ukraine. Other targets include African, EU, and South American governments.

“Last year, we observed different XSS vulnerabilities being used to target additional webmail software: Horde, MDaemon, and Zimbra. Sednit also started to use a more recent vulnerability in Roundcube, CVE-2023-43770. The MDaemon vulnerability — CVE-2024-11182, now patched — was a zero day, most likely discovered by Sednit, while the ones for Horde, Roundcube, and Zimbra were already known and patched,” says ESET researcher Matthieu Faou, who discovered and investigated Operation RoundPress.

Sednit sends these XSS exploits by email; the exploits lead to the execution of malicious JavaScript code in the context of the webmail client web page running in a browser window. Therefore, only data accessible from the target’s account can be read and exfiltrated.

In order for the exploit to work, the target must be convinced to open the email message in the vulnerable webmail portal. This means that the email needs to bypass any spam filtering, and the subject line needs to be convincing enough to entice the target into reading the email message — abusing well-known news media such as Ukrainian news outlet Kyiv Post or Bulgarian news portal News.bg. Among the headlines used as spearphishing were: “SBU arrested a banker who worked for enemy military intelligence in Kharkiv” and “Putin seeks Trump’s acceptance of Russian conditions in bilateral relations”.

The attackers unleash JavaScript payloads SpyPress.HORDE, SpyPress.MDAEMON, SpyPress.ROUNDCUBE, and SpyPress.ZIMBRA upon the targets. Those are capable of credential stealing; exfiltration of the address book, contacts, and log-in history; and exfiltration of email messages. SpyPress.MDAEMON is able to set up a bypass for two-factor authentication protection; it exfiltrates the two-factor authentication secret and creates an app password, which enables the attackers to access the mailbox from a mail application.

“Over the past two years, webmail servers such as Roundcube and Zimbra have been a major target for several espionage groups, including Sednit, GreenCube, and Winter Vivern. Because many organizations don’t keep their webmail servers up to date, and because the vulnerabilities can be triggered remotely by sending an email message, it is very convenient for attackers to target such servers for email theft,” explains Faou.

The Sednit group — also known as APT28, Fancy Bear, Forest Blizzard, or Sofacy — has been operating since at least 2004. The U.S. Department of Justice named the group as one of those responsible for the Democratic National Committee (DNC) hack just before the 2016 U.S. elections and linked the group to the GRU. The group is also presumed to be behind the hacking of global television network TV5Monde, the World Anti-Doping Agency (WADA) email leak, and many other incidents.

For a more detailed analysis and technical breakdown of Sednit’s tools used in Operation RoundPress, check out the latest ESET Research blogpost “Operation RoundPress” on WeLiveSecurity.com. Make sure to follow ESET Research on Twitter (today known as X), BlueSky, and Mastodon for the latest news from ESET Research.

EDR Killers: What They Are, Why They Matter, and How Organizations Can Stay Protected 

Posted in Commentary with tags on April 24, 2025 by itnerd

ESET is warning organizations to stay alert as “EDR killers” – tools designed to disable Endpoint Detection and Response (EDR) solutions- grow more accessible and more widely used by ransomware affiliates. While not a new threat, these tools are becoming easier to deploy, making them relevant for enterprises and mid-sized organizations alike. 

An EDR killer works by disabling or impairing EDR agents on compromised machines, blinding defenders and paving the way for attackers to move stealthily and deliver malicious payloads. These tools are typically deployed after initial access has already been achieved, a process that itself should set off multiple alarms in a well-defended environment. 

Once used only by highly skilled threat actors, EDR killers are now distributed by ransomware-as-a-service (RaaS) operators like RansomHub, lowering the technical bar for attackers. Variants range from basic script-based tools to more advanced versions that exploit vulnerable drivers or repurpose legitimate software, like rootkit removal tools, to disable security systems. 

Despite these developments, ESET stresses that EDR killers aren’t cause for panic, but they are a reminder of the importance of strong, layered security. Organizations with solid defences, good detection practices, and well-trained staff remain in a strong position to detect and disrupt these tools before they cause severe damage. 

ESET recommends the following best practices to reduce exposure: 

  • Use a hardened, updated EDR solution: Leading tools already detect many known EDR killer behaviours. 
  • Restrict user permissions: Prevent users without admin rights from modifying or disabling security controls. 
  • Monitor for suspicious downloads and file transfers: Watch for scripts, drivers, or tools commonly used in these attacks. 
  • Block Potentially Unsafe Applications (PUSA): Review app control policies to minimize exposure to misused software. 
  • Invest in staff training: Phishing awareness and safe file handling are still your first line of defence. 

The rise of EDR killers reflects an evolving cybercrime landscape, where increasingly advanced tools are being commercialized and shared. As attackers adapt their tactics, defenders must do the same. A resilient, multi-layered approach, backed by regular reviews and user education, remains the best strategy for staying ahead. 

ESET continues to track the development of EDR killer tools and their use in real-world attacks. For further insights and technical analysis, visit ESET’s threat research blog, WeLiveSecurity. 

Fraudsters Abuse Google Forms via Phishing to Steal Logins

Posted in Commentary with tags , , on April 23, 2025 by itnerd

According to researchers, fraudsters are abusing Google Forms via phishing campaigns that steal email logins. You can read more here: https://www.welivesecurity.com/en/scams/how-fraudsters-abuse-google-forms-spread-scams/

Here’s the TL:DR:

Malicious actors are always looking for ways to add legitimacy to scams and evade email security filters. Google Forms offers a great opportunity to do both. It is favored by cybercriminals because it is:

  • Free, meaning threat actors can launch campaigns at scale with a potentially lucrative return on their investment
  • Trusted by users, which increases the chances of victims believing that the Google Form they’re being sent or redirected to is legitimate
  • A legitimate service, meaning that malicious Google Forms and links to malicious forms are often waved through by traditional email security tools
  • Easy to use, which is good for users but also handy for cybercriminals – meaning they can launch convincing phishing campaigns with very little effort or prior knowledge of the tool
  • Cybercriminals also take advantage of the fact that Google Forms communications are encrypted with TLS, which may make it harder for security tools to peer in and check for any malicious activity. Similarly, the solution often uses dynamic URLs, which may make it challenging for some email security filters to spot malicious forms.

Roger Grimes, data-driven defense evangelist at KnowBe4, commented:

“All public services like Google Forms, need to be better at defeating phishing attempts that use their product. I think most people can easily come up with a dozen signs that they can easily see in a message that indicates a scam. These services need to be doing more to fight cybercriminals using their products to conduct scams. Because they don’t, it causes trust issues and lessens the value of those products. Each of these services will tell you that they are already spending a bazillion dollars and lots of resources to fight scammers, but they simply aren’t doing enough. They are letting the revenue they are making by being bad at spotting cybercriminals get in the way of them better detecting and spotting scammers. It’s a business decision. One that isn’t being made correctly by many service providers and it’s unfortunate.”

This isn’t the first time that I’ve seen Google Forms used for nefarious purposes. And to Google’s credit, when I’ve reported a dodgy form, they’ve been quick to take it down. But it often pops up again in hours or days. I am not sure how Google addresses this, but they do need to address it.

ESET Launches Ransomware Remediation and AI Advisor Updates at ESET World 2025

Posted in Commentary with tags on March 31, 2025 by itnerd

ESET, a global leader in cybersecurity solutions, today released new updates for the ESET PROTECT Platform, including Ransomware Remediation, a new way to prevent ransomware encryption from causing long-term business disruption, as well as new functionalities for ESET Cloud Office Security and the ESET AI Advisor. These new cybersecurity features were launched at ESET World 2025, taking place in Las Vegas from March 24 to 26, 2025, at the ARIA Resort & Casino.

As ransomware attacks increase in sophistication, threat actors seek to undermine nearly all areas of business security and stability. One well-known and -used attack is encryption, which prevents you from accessing your device and the data stored on it. Causing costly process disruption, and ultimately forcing firms to pay to decrypt their systems, threat actors often target system backups, such as Volume Shadow Copy, by immediately deleting or corrupting them. This makes recovery nearly impossible and drives up remediation costs.

Building on ESET LiveSense, ESET’s next-gen Ransomware Remediation feature works in concert with Ransomware Shield to immediately create backups until the system confirms whether the suspicious activity is malicious or benign. If malicious, Ransomware Shield will kill the process and roll back the files from the newly created secure backups. If benign, the backups created can be discarded. Unlike other solutions, Ransomware Remediation has its own protected storage section on the drive, where files cannot be modified, corrupted, or deleted by the attacker. This differentiator actively solves one of the most common failings of regular backups during a ransomware attack. As a free addition for customers signed up for the ESET PROTECT Advanced tier and above, Ransomware Remediation is available for Windows-based systems.

Email Security and AI Advisor Updates

ESET has added anti-spoofing and homoglyph protection to its ESET Cloud Office Security module, preventing attackers from pretending to be trusted sources while also identifying their efforts to disguise malicious domains or URLs through letter substitution from other alphabets. Moreover, ESET Cloud Office Security now also has an email clawback feature, enabling swift recall and quarantine of any delivered emails deemed suspicious. New dashboards are visually enhanced and include fully customizable tabs and components that fit a user’s specific needs.

ESET has also expanded the availability of AI Advisor to its EDR/XDR customers, including those with ESET PROTECT Enterprise, ESET PROTECT Elite, and ESET PROTECT MDR subscriptions – while making performance updates. By investing in AI, businesses are able to access SOC-level advisory, enabling enhanced security analyst workflows. Unlike other vendor offerings and typical generative AI assistants that focus on soft features like administration or device management, ESET AI Advisor seamlessly integrates into the day-to-day operations of security analysts. This is a gamechanger for companies with limited IT resources that want to utilize the advantages of advanced XDR solutions and threat intelligence feeds.

For more information about the ESET LiveSense technologies used by the ESET PROTECT Platform, please visit here.

For more information about the ESET PROTECT Platform, please visit their dedicated webpage.

For more information about ESET Cloud Office Security and the ESET AI Advisor, please visit their webpage and their AI blog.

To discover how ESET has been handling ransomware, please read ESET MDR success stories and ESET Inspect’s preventive power.

ESET Canada Announces 2024 Partner of the Year Awards

Posted in Commentary with tags on March 12, 2025 by itnerd

 ESET Canada is proud to announce the winners of its 2024 Canadian Partner of the Year Awards, recognizing the outstanding achievements and contributions of our reseller ecosystem, which contributed to our above-market SMB growth and success in the past year. 

2024 Highlights:

  • Services Growth: ESET Canada saw a remarkable 70% increase in services over the previous year, driven by the adoption of ESET Managed Detection and Response (MDR), providing 24/7 threat monitoring, detection, and incident response.
  • MSP Business: Their MSP business thrived with double-digit growth as they onboarded new partners, and as more partners looked to standardize on their most robust cloud offerings, thanks to the opening of their Canadian data centre.  
  • Customer loyalty: ESET Canada achieved it’s target benchmark for renewals, which highlights their strong customer loyalty and satisfaction among the more than 10,000 Canadian businesses they protect. 

2024 Partner of the Year Awards: ESET Canada is thrilled to present the winners of this year’s Partner of the Year Awards:

  • SMB Partner of the Year: GB Micro
  • Enterprise Partner of the Year: Insight Canada
  • Services Partner of the Year: SOS Computer Experts
  • MSP Partner of the Year: GAM Tech
  • Rising Star Partner of the Year: IO SECURE

Congratulations to all the winners.

Resellers can uncover more growth opportunities at ESET World 2025 in Las Vegas. Secure your spot virtually, today! 

ESET Celebrates Tenth Anniversary of Women in Cybersecurity Scholarship, Expands 2025 Canadian Awards

Posted in Commentary with tags on March 8, 2025 by itnerd

ESET, a global leader in cybersecurity, today announced the anniversary of its Women in Cybersecurity North American Scholarship, launched in 2016 to support and empower women pursuing careers in cybersecurity. As part of its ongoing commitment to fostering diverse talent, ESET is expanding the program in Canada, increasing both the number and value of scholarships available to Canadian applicants.

For a decade, ESET North America has encouraged and uplifted women to pursue careers in cybersecurity, offering financial assistance to help achieve their aspirations. In solidarity with the 2025 International Women’s Day’s #AccelerateAction theme, the Women in Cybersecurity North American Scholarship program is expanding its scope this year with additional awards, enhanced evaluation criteria and a renewed focus on recognizing both technical excellence and emerging potential.

As a long-time advocate for cybersecurity and talent development in Canada, ESET has built strong relationships with key technology hubs, including the city of Markham. Over the years, ESET has received a wealth of strong candidates from Markham and the Greater Toronto Area, reinforcing the region’s reputation as a growing center for cybersecurity innovation. By investing in opportunities for aspiring cybersecurity professionals, ESET aims to support both local talent and the broader cybersecurity workforce.

Pioneering one of the first scholarships of its kind, Celeste Blodgett, Vice President of Human Resources at ESET North America, originated the program at the North American headquarters in San Diego to support women who want to go into technology fields. Bolstered by Celeste’s passion, the program has since awarded scholarships to more than 25 recipients in the U.S. and Canada, and has expanded globally to Australia, the United Kingdom and Singapore.

According to the 2024 Cybersecurity Workforce Study conducted by (ISC), women account for only 14.4% of the cybersecurity workforce, while men make up 79.6%. This stark imbalance underscores the critical need to bring more women into the profession, particularly as emerging technologies like generative AI continue to evolve. ESET is committed to fostering opportunities for women to lead in cybersecurity and AI, helping to bridge this gap and build a more balanced, innovative and equitable future. Diversity in AI development is essential to ensure these tools are ethical, secure and inclusive.

In 2025, ESET North America will award $45,000 in scholarships to support the next generation of cybersecurity professionals. Canadian students will have access to new and expanded awards, including two $5,000 Cybersecurity Trailblazer awards for applicants who demonstrate exceptional technical proficiency and a strong focus on cybersecurity. To mark the tenth anniversary, five new $1,000 Future Leader Awards will be introduced in Canada to recognize emerging talent with great potential in cybersecurity. In the U.S., three $10,000 scholarships will be awarded in the Cybersecurity Trailblazer Award Tier, including one dedicated to a recipient in San Diego, honouring the program’s origins.

The scholarship has already helped many women pursue careers in cybersecurity.

DETAILS AND HOW TO APPLY
Applications are now being accepted for the 2025 round, and submissions must be received by 11:59 p.m. PT on April 8, 2025. Applicants can learn more about the scholarships and submit their application by visiting our dedicated web pages. If you’re a Canadian student, apply here; if you’re a US student, you can apply here.

Questions? Email us at CA-scholarship@eset.com [Canada-only inquiries] or US-scholarship@eset.com [US-only inquiries] with any questions.

Patch or Perish: Why Vulnerability Management Can’t Wait According To ESET

Posted in Commentary with tags on February 10, 2025 by itnerd

ESET has put up a blog post titled, “Patch or perish: How organizations can master vulnerability management” that I think those who are responsible for patching all the things should read.

Cybercriminals are moving faster than ever, with vulnerability exploitation now a leading cause of ransomware attacks and data breaches. A recent report found that observed cases of vulnerability exploitation tripled in 2023 alone. Yet, with record-high CVEs and shrinking patching windows, many organizations are struggling to keep up. 

ESET’s latest blog post insights dive into: 

  • Why organizations are overwhelmed by a relentless surge in software vulnerabilities 
  • The rise of zero-day exploits and perimeter-based attacks 
  • How AI-driven threat actors are making patching even more urgent 
  • Actionable steps to automate and prioritize vulnerability management 

You can read the blog post here.

ESET Bulks Up its ESET HOME Security Offerings to Protect Against AI-Driven Threats

Posted in Commentary with tags on October 23, 2024 by itnerd

 ESET today announced its upgraded consumer offering, ESET HOME Security, with new features, such as ESET Folder Guard, Multithread Scanning, and Identity Protection featuring Dark Web Monitoring. These enhancements to ESET HOME Security, as an all-in-one solution for consumers, correspond to the increasing number of advanced, automated, and AI-driven threats targeting individuals and address growing concerns about data privacy, ransomware attacks, phishing, and scams.  

ESET HOME Security is available across all major operating systems—Windows, macOS, Android, iOS—and covers all typical smart home devices. Improvements have been made to enhance the existing layers of protection, including upgrades to the Link Scanner and Password Manager. Security for Mac users has been improved with a new unified Firewall offering both basic and advanced setup options in the main Graphical User Interface (GUI).  

Some of the top new and improved features include:  

New Dark Web Monitoring — ESET Identity Protection is now available in Canada, providing users with advanced tools to safeguard their personal information. This feature scours the dark web, black market chat rooms, blogs, and other data sources for the illegal trading and selling of personal data. ESET’s cutting-edge technology delivers prompt alerts, enabling users to take immediate action and mitigate potential identity theft risks. 

New ESET Folder Guard — This technology helps protect Windows users’ valuable data from malicious apps and threats, such as ransomware, worms, and wipers (malware that can damage users’ data). Users can create a list of protected folders — files in these folders can’t be modified or deleted by untrusted applications.   

New Multithread Scanning — Improves scanning performance for multi-core processor devices using Windows by distributing scanning requests among available CPU cores. There can be as many scanning threads as the machine has processor cores. 

Improved Gamer Mode — This feature is for users who demand uninterrupted usage of their software without pop-up windows and want to minimize CPU usage. The improved version allows users to create a list of apps automatically starting gamer mode. For cautious players, there is also a new option to display interactive alerts while gamer mode is running.  

This robust all-in-one security product is an ideal solution for all who have concerns beyond general cybersecurity, and it includes privacy protection, identity protection, performance optimization, device protection, and smart home protection. Because in a world of advanced cyberthreats, quality matters. 

More information about the consumer offering and subscription tiers can be found here. 

Canadian Winners of the Ninth Annual Women in Cybersecurity Scholarship Honoured at ESET Canada Head Office

Posted in Commentary with tags on July 18, 2024 by itnerd

ESET North America proudly celebrated the Canadian winners of the Ninth Annual Women in Cybersecurity Scholarship at an event held at the ESET Canada office. The winners, Aidan Gurung from Gloucester, Ontario, and Lauren Hendley from Carp, Ontario, were recognized for their outstanding achievements and contributions to the field of cybersecurity.

Although Aidan could not be in attendance, the event highlighted the exceptional accomplishments of these two young women and featured a series of special recognitions:

  • Meet and Greet with the ESET Team:  The ESET Canada team, including members of the head office in Markham and Jean-Ian Boutin, Director of Threat Research at the ESET Research Centre of Montreal,personally congratulated Lauren, several finalists, as well as previous winners, acknowledging their dedication to cybersecurity and STEM education.
  • Video Message from local MP: Melissa Lantsman, Member of Parliament, Thornhill, Ontario, sent a heartfelt video message congratulating Aidan and Lauren and emphasizing the importance of their accomplishments in the male-dominated field of cybersecurity.
  • Certificates from local MPP: Laura Smith, Member of the Provincial Parliament and Parliamentary Assistant to the Minister of Children, Community, and Social Services, sent congratulatory certificates on behalf of the Province of Ontario, recognizing the winners’ exceptional achievements and extending best wishes for their future endeavours.

Lauren Hendley was influenced by her father’s industry involvement and early programming experiences, Lauren’s passion for technology and cybersecurity was ignited in grade 12 when she co-founded her school’s Computer Science Club and competed in CyberPatriot. Lauren has been accepted to the University of Ottawa for an Honours Bachelor of Science in Computer Science (COOP Program), with a focus on cybersecurity and Artificial Intelligence. Lauren emphasized the importance of showing women they are necessary and capable in a male-dominated field.

Through her experiences growing up in Nepal, Aidan Gurung, witnessed the importance of education and ethical standards in technological innovation. Her passion for EdTech and cybersecurity education has led her to pursue a master’s degree at the University of Cambridge. Aidan expressed her gratitude to ESET for supporting students like herself who aim to improve the technology landscape with a focus on ethics.

This scholarship is an annual initiative, and interested women should keep an eye on the WICS site for updates in 2025. Find out more here.

Tony Anscombe to EMCEE Collision Conference 2024’s Developer Track: FullSTK

Posted in Commentary with tags on June 11, 2024 by itnerd

ESET today announced that Tony Anscombe,  Cyber Security Evangelist at ESET, will be the emcee for the Developer Track: FullSTK at this year’s Collision Conference. With topics ranging from AI and privacy to future tech, Anscombe will introduce and shed light on a range of critical technology topics during the event, which brings together the product managers, data scientists, coders and engineers programming the future to talk tech. 

Tony Anscombe brings a wealth of experience to the stage as Cyber Security Evangelist at ESET, having spoken at renowned industry conferences such as RSA, Black Hat, Infosec, Gartner Risk and Security Summit, and the Child Internet Safety Summit. Most recently, Anscombe presented on cyber risk insurance, and published an industry whitepaper on the topic, for ESET World 2024, an annual event where global cybersecurity professionals, analysts and decision-makers come together to discuss technological advancements.  

During the FullSTK Developer Track, the following topics will be highlighted: 

  • Future Tech: Explore the potential of superpositions and DNA enzymes in processing data at unprecedented speeds, the impact of identity orchestration on development, the future of ambient computing, and advances in AI and machine learning. 
  • Security and Compliance: With the escalation of cyberwarfare and increasingly stringent legislation, discover new security tools and tactics. Learn what companies and nation-states can do to thwart sophisticated cyberattacks and stay ahead of technological advancements. 
  • Privacy and Diversity in Data: Address the pressing ethics of AI technology, including opaque terms and conditions and algorithmic biases. Discuss how technology companies are advancing data privacy and fostering diversity to design complex AI systems free from bias. 
  • The Role of the Engineer: Analyze how DevOps teams have led the way in remote work and the ongoing influence of engineers on the future of work. Investigate the challenges companies face in acquiring technically skilled workers and the implications of nearshoring talent. 

As a speaker, author, and recognized expert in the current threat landscape, security technologies, data protection, privacy, and internet safety, Anscombe’s insights are highly sought after and respected globally. He is regularly quoted in leading security, technology, and business publications such as BBC, The Guardian, The New York Times, and USA Today. Additionally, he has made broadcast appearances on Bloomberg, BBC, CTV, CBC, CP24, Global News, and CBS, establishing himself as a trusted voice in the cybersecurity domain. 

Don’t miss the opportunity to engage with Tony Anscombe and gain valuable insights during the FullSTK sessions at Collision Conference 2024. For more details, visit here: LINK.