logo

EIW — ESET Israel Wiper — used in active attacks targeting Israeli orgs

ID: be33d11d-17a5-5b7f-94f2-2f09dd19c55a

STIX ID: report--be33d11d-17a5-5b7f-94f2-2f09dd19c55a

Feed Name: DoublePulsar

Threat Score
82/100

Date Published: 2024-10-17

Date Updated: 2026-04-19

Author: Kevin Beaumont

...
...

A malicious ZIP masquerading as ESET-distributed content contained setup.exe, a destructive wiper that irrecoverably destroys infected hosts; targeting appears focused on Israeli cybersecurity organizations and the lure used ESET branding likely via a compromised store or email. The analyst provides multiple file hashes, a YARA rule, notes ESET detection Win32/Agent.AGFH, and raises links to Iran-associated operations (Handala/CyberToufan) based on shared artifacts and political messaging.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.