ESET releases latest Q2 2024–Q3 2024 APT report: APT groups expand targeting and diplomatic espionage

An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q2 2024 and Q3 2024. ESET APT Activity Report Q2 2024–Q3 2024 summarizes notable activities of selected advanced persistent threat (APT) groups that were documented by ESET researchers from April 2024 until the end of September 2024. The highlighted … More ESET releases latest Q2 2024–Q3 2024 APT report: APT groups expand targeting and diplomatic espionage

ESET Research: GoldenJackal APT group, with air-gap-capable tools, targets systems in Europe to steal confidential data

ESET researchers have discovered a series of attacks that took place in Europe from May 2022 to March 2024, where the attackers used a toolset capable of targeting air-gapped systems, in a governmental organization of a European Union country. GoldenJackal, an advanced persistent threat (APT) group, used a custom toolset to target air-gapped systems at … More ESET Research: GoldenJackal APT group, with air-gap-capable tools, targets systems in Europe to steal confidential data

The complexities of attack attribution

Attributing a cyberattack to a specific threat actor is a complex affair, as evidenced by new ESET research published recently. Attributing a cyberattack to a specific threat actor is no easy task, as highlighted by new ESET research published this week. ESET experts recently uncovered a new APT group that they named CeranaKeeper and that … More The complexities of attack attribution

ESET Research discovers new government-attacking APT group

ESET researchers have discovered several targeted campaigns against governmental institutions in Thailand, starting in 2023, where massive amounts of data have been exfiltrated. ESET researchers discovered a new advanced persistence threat (APT) group, CeranaKeeper, targeting governmental institutions in Thailand. Some of its tools were previously attributed to Mustang Panda by other researchers. Massive amounts of … More ESET Research discovers new government-attacking APT group

ESET Research: Spy group exploits WPS Office zero day; analysis uncovers a second vulnerability

ESET researchers discovered a remote code execution vulnerability in WPS Office for Windows (CVE-2024-7262). Advanced persistent threat group APT-C-60 weaponized a remote code execution vulnerability in WPS Office for Windows (CVE-2024-7262) in order to target East Asian countries. ESET Research discovered the vulnerability and provides a root cause analysis, along with a description of its … More ESET Research: Spy group exploits WPS Office zero day; analysis uncovers a second vulnerability