EIW — ESET Israel Wiper — used in active attacks targeting Israeli orgs
ID: be33d11d-17a5-5b7f-94f2-2f09dd19c55a
STIX ID: report--be33d11d-17a5-5b7f-94f2-2f09dd19c55a
Feed Name: DoublePulsar
A malicious ZIP masquerading as ESET-distributed content contained setup.exe, a destructive wiper that irrecoverably destroys infected hosts; targeting appears focused on Israeli cybersecurity organizations and the lure used ESET branding likely via a compromised store or email. The analyst provides multiple file hashes, a YARA rule, notes ESET detection Win32/Agent.AGFH, and raises links to Iran-associated operations (Handala/CyberToufan) based on shared artifacts and political messaging.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
