ESET discovers new APT group and its supply chain attack on South Korean VPN service

ESET researchers have discovered a supply-chain attack against a VPN provider in South Korea by a newly discovered and previously undetected China-aligned APT group that ESET has named PlushDaemon. ESET Research has discovered a previously undetected China-aligned Advanced Persistent Threat (APT) group, PlushDaemon, engaged in cyberespionage operations. PlushDaemon’s main initial access vector is hijacking legitimate … More ESET discovers new APT group and its supply chain attack on South Korean VPN service

ESET Research discovers new government-attacking APT group

ESET researchers have discovered several targeted campaigns against governmental institutions in Thailand, starting in 2023, where massive amounts of data have been exfiltrated. ESET researchers discovered a new advanced persistence threat (APT) group, CeranaKeeper, targeting governmental institutions in Thailand. Some of its tools were previously attributed to Mustang Panda by other researchers. Massive amounts of … More ESET Research discovers new government-attacking APT group

ESET Research Podcast: HotPage

ESET researchers discuss HotPage, a recently discovered adware armed with a highest-privilege, yet vulnerable, Microsoft-signed driver. Usually when someone mentions adware, people think of low-quality half-baked malicious code used to spam victims with sketchy ads. But as we explain in this episode of our podcast, not all adware is created equal. HotPage is a recently … More ESET Research Podcast: HotPage

Chinese bank in US hit by ransomware attack

The Industrial and Commercial Bank of China’s (ICBC) U.S. arm was hit by a ransomware attack that disrupted trades in the U.S. Treasury market on Thursday, the latest in a string of victims ransom-demanding hackers have claimed this year. According to Reuters*, ICBC Financial Services, the U.S. unit of China’s largest commercial lender by assets, … More Chinese bank in US hit by ransomware attack

USB drive malware attacks spiking again in first half of 2023

According to the Bleeping Computer*, what’s old is new again, with researchers seeing a threefold increase in malware distributed through USB drives in the first half of 2023. A new report by Mandiant outlines how two USB-delivered malware campaigns have been observed this year; one named ‘Sogu,’ attributed to a hacker group ‘TEMP.HEX,’ and another … More USB drive malware attacks spiking again in first half of 2023