Thursday, February 27, 2025
HomeCyber Security NewsHackers Mimic as ESET to Deliver Wiper Malware

Hackers Mimic as ESET to Deliver Wiper Malware

Published on

SIEM as a Service

Follow Us on Google News

Hackers impersonated the cybersecurity firm ESET to distribute destructive wiper malware. The campaign, which began on October 8, 2024, utilized phishing emails that appeared to originate from ESET’s legitimate domain.

The malicious emails, purportedly from “ESET’s Advanced Threat Defense Team,” warned recipients that state-backed attackers were targeting their devices.

The emails offered a download link for a fictitious “ESET Unleashed” program to combat this alleged threat.

ESET Warned Recipients (source: DoublePulsar)
ESET Warned Recipients (source: DoublePulsar)

Upon clicking the link, victims were directed to a ZIP file hosted on ESET Israel’s legitimate domain. The archive contained several legitimate ESET DLL files and a malicious Setup.exe, identified as a wiper malware.

Join ANY.RUN's FREE webinar on How to Improve Threat Investigations on Oct 23 - Register Here 

According to the DoublePulsar report, Security researcher Kevin Beaumont, who analyzed the attack, noted that the malware required a physical PC to activate and exhibited evasion techniques.

The wiper was also connected to a legitimate Israeli news organization’s website, possibly to avoid detection.

ESET acknowledged the incident, stating it affected their partner company in Israel, Comsecure.

The company emphasized that their systems were not compromised and that the malicious email campaign was blocked within ten minutes.

ESET Acknowledged
ESET Acknowledged (Source: Doublepulsar)

The attack targeted cybersecurity personnel within Israeli organizations, suggesting a strategic attempt to disrupt the country’s digital defense.

While the perpetrators remain unidentified, the tactics employed bear similarities to those used by pro-Palestinian groups like Handala, which has been linked to sophisticated attacks against Israeli targets.

It underscores the importance of verifying the authenticity of security-related communications, even when they appear to come from trusted sources.

How to Choose an ultimate Managed SIEM solution for Your Security Team -> Download Free Guide (PDF)

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Latest articles

VS Code Extension with 9 Million Installs Attacks Developers with Malicious Code

Microsoft has removed two widely-used Visual Studio Code (VS Code) extensions, “Material Theme Free”...

New Anubis Ransomware Targets Windows, Linux, NAS, and ESXi x64/x32 Environments

A new ransomware group, dubbed Anubis, has emerged as a significant threat in the...

WordPress Admins Warned of Fake Plugins Injecting Malicious Links into Websites

A new wave of cyberattacks targeting WordPress websites has been uncovered, with attackers leveraging...

LARVA-208 Hackers Compromise 618 Organizations Stealing Logins and Deploying Ransomware

A newly identified cybercriminal group, LARVA-208, also known as EncryptHub, has successfully infiltrated 618...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

VS Code Extension with 9 Million Installs Attacks Developers with Malicious Code

Microsoft has removed two widely-used Visual Studio Code (VS Code) extensions, “Material Theme Free”...

New Anubis Ransomware Targets Windows, Linux, NAS, and ESXi x64/x32 Environments

A new ransomware group, dubbed Anubis, has emerged as a significant threat in the...

WordPress Admins Warned of Fake Plugins Injecting Malicious Links into Websites

A new wave of cyberattacks targeting WordPress websites has been uncovered, with attackers leveraging...