ESET partner breached to send data wipers to Israeli orgs
ID: 51a792a6-443b-5259-9e7d-0d639e199ec5
STIX ID: report--51a792a6-443b-5259-9e7d-0d639e199ec5
Feed Name: Bleeping Computer
Attackers compromised ESET Israel's partner to send authentic-looking phishing emails from the eset.co.il domain delivering an archive (hosted under backend.store.eset.co.il) that included legitimate signed ESET DLLs and a malicious Setup.exe data wiper; the wiper is designed to delete files and evade detection, detonating on physical systems. BleepingComputer and VirusTotal artifacts confirm the malicious installer and signed DLLs, SPF/DKIM/DMARC authentication passed for the phishing emails, and attribution remains unconfirmed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
