ESET discovers new APT group and its supply chain attack on South Korean VPN service

ESET researchers have discovered a supply-chain attack against a VPN provider in South Korea by a newly discovered and previously undetected China-aligned APT group that ESET has named PlushDaemon. ESET Research has discovered a previously undetected China-aligned Advanced Persistent Threat (APT) group, PlushDaemon, engaged in cyberespionage operations. PlushDaemon’s main initial access vector is hijacking legitimate … More ESET discovers new APT group and its supply chain attack on South Korean VPN service

ESET Research discovers Mozilla and Windows zero day & zero click vulnerabilities exploited by RomCom APT group

ESET Research details the analysis of a previously unknown vulnerability in Mozilla products exploited in the wild and another previously unknown Microsoft Windows vulnerability, combined in a zero-click exploit. ESET researchers discovered two previously unknown vulnerabilities, one in Mozilla and the other in Windows, being exploited by the RomCom Advanced persistent threat (APT) group. Analysis … More ESET Research discovers Mozilla and Windows zero day & zero click vulnerabilities exploited by RomCom APT group

ESET Research discovers WolfsBane, new Linux cyberespionage backdoor by Gelsemium APT

ESET researchers have identified multiple samples of a Linux backdoor, which they named WolfsBane and attribute with high confidence to Gelsemium advanced persistent threat (APT) group. ESET researchers have identified multiple samples of the Linux backdoor WolfsBane and attribute it with high confidence to Gelsemium APT group The goal of the discovered backdoors and tools … More ESET Research discovers WolfsBane, new Linux cyberespionage backdoor by Gelsemium APT

Cyberespionage the Gamaredon way

ESET researchers introduce the Gamaredon APT group, detailing its typical modus operandi, unique victim profile, vast collection of tools and social engineering tactics. When describing state-backed threat actors, one would probably expect a super sophisticated, stealthy group capable of avoiding all alarms and defenses with surgical precision. With Gamaredon, most of that goes out the … More Cyberespionage the Gamaredon way

ESET Research: Spy group exploits WPS Office zero day; analysis uncovers a second vulnerability

ESET researchers discovered a remote code execution vulnerability in WPS Office for Windows (CVE-2024-7262). Advanced persistent threat group APT-C-60 weaponized a remote code execution vulnerability in WPS Office for Windows (CVE-2024-7262) in order to target East Asian countries. ESET Research discovered the vulnerability and provides a root cause analysis, along with a description of its … More ESET Research: Spy group exploits WPS Office zero day; analysis uncovers a second vulnerability