ESET discovers new APT group and its supply chain attack on South Korean VPN service

ESET researchers have discovered a supply-chain attack against a VPN provider in South Korea by a newly discovered and previously undetected China-aligned APT group that ESET has named PlushDaemon. In this cyberespionage operation, the attackers replaced the legitimate installer with one that also deployed the group’s signature implant, which ESET has named SlowStepper — a … More ESET discovers new APT group and its supply chain attack on South Korean VPN service

ESET Research discovers new government-attacking APT group

ESET researchers have discovered several targeted campaigns against governmental institutions in Thailand, starting in 2023, where massive amounts of data have been exfiltrated. The campaigns misused legitimate file-sharing services such as Dropbox, PixelDrain, GitHub, and OneDrive in the process. Based on the findings, ESET researchers decided to track this activity cluster as the work of … More ESET Research discovers new government-attacking APT group

ESET Research Podcast: HotPage

ESET researchers discuss HotPage, a recently discovered adware armed with a highest-privilege, yet vulnerable, Microsoft-signed driver. Usually when someone mentions adware, people think of low-quality half-baked malicious code used to spam victims with sketchy ads. But as we explain in this episode of our podcast, not all adware is created equal. HotPage is a recently … More ESET Research Podcast: HotPage

Chinese bank in US hit by ransomware attack

The Industrial and Commercial Bank of China’s (ICBC) U.S. arm was hit by a ransomware attack that disrupted trades in the U.S. Treasury market on Thursday, the latest in a string of victims ransom-demanding hackers have claimed this year. According to Reuters*, ICBC Financial Services, the U.S. unit of China’s largest commercial lender by assets, … More Chinese bank in US hit by ransomware attack

USB drive malware attacks spiking again in first half of 2023

According to the Bleeping Computer*, what’s old is new again, with researchers seeing a threefold increase in malware distributed through USB drives in the first half of 2023. A new report by Mandiant outlines how two USB-delivered malware campaigns have been observed this year; one named ‘Sogu,’ attributed to a hacker group ‘TEMP.HEX,’ and another … More USB drive malware attacks spiking again in first half of 2023