pwshub.com

ESET denies Israel branch compromised amid targeted attacks

ESET denies being compromised after an infosec researcher highlighted a wiper campaign that appeared to victims as if it was launched using the Slovak security shop's infrastructure.

Kevin Beaumont blogged about an Israeli biz that said it was infected with a wiper after a staffer clicked a link in an email seemingly sent from the ESET Advanced Threat Defense Team in Israel.

The email itself passed DKIM and SPF checks against ESET's domain, said Beaumont, although according to a screenshot of it shared by one security pro, Google Workspace flagged it as malicious.

It appears the email was first sent on October 8, targeting cybersecurity professionals in Israel, with the .ZIP download hosted on ESET servers.

Targets were informed their devices were being aimed at by "a state-backed threat actor" and were invited to ESET's Unleashed program – which doesn't appear to exist as a standalone program, but Beaumont noted the branding is sometimes used by the vendor.

The download contains various ESET DLLs, the researcher said, as well as a malicious setup.exe. Beaumont described it as a fake ransomware, making calls to things like Mutex from Yanluowang's ransomware payload, for example.

It also made innocuous calls to an organization promoting the Iron Swords War memorial day, established to remember those who died when Hamas troops attacked Israel on October 7, 2023. The observation, combined with the day of infection, raises questions about whether this was a hacktivist at work.

"Email targeting seen so far is cybersecurity people within organizations across Israel," said Beaumont. "It appears there is no way to actually recover. It's a wiper."

ESET responded to the situation via X on Friday, denying Beaumont's claim that ESET Israel was itself compromised.

The security org said: "We are aware of a security incident which affected our partner company in Israel last week. Based on our initial investigation, a limited malicious email campaign was blocked within ten minutes. ESET technology is blocking the threat and our customers are secure. ESET was not compromised and is working closely with its partner to further investigate and we continue to monitor the situation."

  • Intel lightly hits back at China's accusations it bakes in NSA backdoors
  • Biz hired, and fired, a fake North Korean IT worker – then the ransom demands began
  • Uncle Sam puts $10M bounty on Russian troll farm Rybar
  • Troubled US insurance giant hit by extortion after data leak

The source of the malicious activity isn't known, but the MO aligns neatly with that of the pro-Palestine Handala group, which for the past few months has attacked Israeli organizations and figureheads.

Trellix researchers noted in July that Handala has a propensity for wiper attacks in Israel, noting at the time that hundreds of the strikes targeted Israeli organizations in just a few weeks. The Israeli government published an urgent warning about the incidents in response.

More recently, Handala has been leaking what it claims to be private files, emails, and photos from the likes of Israeli politician Benjamin Gantz, former prime minister Ehud Barak, and diplomat to Germany Ron Prosor. All appear to be compromises of personal accounts.

Organizations that were recently singled out by the group include podcasting platform Doscast, Soreq Nuclear Research Center, point of sale vendor Max Shop, and firearms exporter Silver Shadow. ®

Source: theregister.com

Related stories
1 week ago - USB sticks help, but it's unclear how tools that suck malware from them are delivered A cyberespionage APT crew named GoldenJackal hacked air-gapped PCs belonging to government and diplomatic entities at least twice using two sets of...
3 weeks ago - PLUS: Payer of $75M ransom reportedly identified; Craigslist founder becomes security philanthropist, and more Infosec In Brief Something's wrong with macOS Sequoia, and it's breaking security software installed on some updated Apple...
3 weeks ago - macOS 15 is hardly breaking new ground in terms of advanced features or technology. In fact, Mac users may want to skip or delay the upgrade, as the new OS is experiencing significant compatibility issues with anti-malware programs and...
1 week ago - It's hard enough creating one air-gap-jumping tool. GoldenJackal did it 2x in 5 years.
1 week ago - Firefixed: It's maintenance time for low-complexity, high-impact security flaw It's patch time for Firefox fans as Mozilla issues a security advisory for a critical code execution vulnerability in the browser.…
Other stories
24 minutes ago - The details, which remained under wraps until now, come from people familiar with the situation who spoke to Bloomberg. According to the sources, the iPhone maker collaborated with BYD for years on lithium iron phosphate battery cells...
24 minutes ago - The student in question, identified only by his initials, RNH, admitted to Hingham High School teachers that he had used AI to complete a Social Studies project in December. He claimed the tool was only used for research and not to write...
1 hour ago - Nothing's better than a crispy fry, but you can only achieve them in an air fryer by following these rules.
1 hour ago - Why You Can Trust CNET Our expert, award-winning staff selects the products we cover and rigorously researches and tests our top picks. If you buy...
1 hour ago - Contrary to popular belief, buying a gift for a girlfriend doesn't have to be stressful. Whether you're shopping for a significant other, long-distance pal or BFF, we've curated this list of unique and thoughtful gifts for girlfriends...