logo

ESET partner breached to send data wipers to Israeli orgs

ID: 51a792a6-443b-5259-9e7d-0d639e199ec5

STIX ID: report--51a792a6-443b-5259-9e7d-0d639e199ec5

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-10-18

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Attackers compromised ESET Israel's partner to send authentic-looking phishing emails from the eset.co.il domain delivering an archive (hosted under backend.store.eset.co.il) that included legitimate signed ESET DLLs and a malicious Setup.exe data wiper; the wiper is designed to delete files and evade detection, detonating on physical systems. BleepingComputer and VirusTotal artifacts confirm the malicious installer and signed DLLs, SPF/DKIM/DMARC authentication passed for the phishing emails, and attribution remains unconfirmed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.