What does $5,000 buy you on a hacking forum?

For a mere $5,000, you can buy a UEFI bootkit called BlackLotus that can run even on fully up-to-date Windows 11 systems with UEFI Secure Boot enabled. This week, ESET researchers published their analysis of BlackLotus that caused them to conclude that the bootkit they had discovered in the wild is indeed the BlackLotus bootkit … More What does $5,000 buy you on a hacking forum?

Major new crypto wallet phishing campaign targets Trezor users

Techradar reports A new phishing campaign has been discovered targeting cryptocurrency hardware wallet firm Trezor. These wallets allow crypto users to store their funds offline, rather than in a “hot wallet” (a mobile or desktop app), or with a third party (an exchange, a custodial service, or a lending/borrowing firm). Hardware wallets, also known as … More Major new crypto wallet phishing campaign targets Trezor users

ESET Research: Mustang Panda’s latest backdoor targets Europe, Asia, and Australia

ESET researchers have analyzed MQsTTang, a new custom backdoor that we attribute to the Mustang Panda APT group. ESET researchers have just analyzed MQsTTang, a new custom backdoor that we attribute to the Mustang Panda APT group. This backdoor is part of an ongoing campaign that ESET can trace back to early January 2023. ESET … More ESET Research: Mustang Panda’s latest backdoor targets Europe, Asia, and Australia

ESET Research analyzes BlackLotus: A UEFI bootkit that can bypass UEFI Secure Boot on fully patched systems

ESET researchers are the first to publish an analysis of BlackLotus, the first in-the-wild UEFI bootkit that is capable of bypassing an essential platform security feature — UEFI Secure Boot. ESET researchers are the first to publish an analysis of a UEFI bootkit that is capable of bypassing an essential platform security feature – UEFI … More ESET Research analyzes BlackLotus: A UEFI bootkit that can bypass UEFI Secure Boot on fully patched systems

ESET Podcast: Ransomware trashed data, Android threats soared in T3 2022

And that’s just the tip of the iceberg when it comes to the trends that defined the cyberthreat landscape in the final four months of 2022. Data from the latest ESET Threat Report, which provides an in-depth look at the threat landscape from September to December 2022, confirmed several previously observed trends. The key of them … More ESET Podcast: Ransomware trashed data, Android threats soared in T3 2022