daily cyber × ai intelligence

index

tagged

[eset]

11 editions · 15 items

September 2, 2026

  • UAC-0099 is weaponising LLM safety filters as an anti-analysis technique. ESET's GuardBreaker write-up describes the Russia-aligned actor embedding nuclear-weapons-themed content in malware to deliberately trip refusal behaviour and block AI-assisted reverse engineering of samples (The Hacker News). Follows the same actor's activity noted last week (earlier coverage). · AI & Model Security

in OpenAI Says Astra Crossed the Line: Autonomous Zero-Day Discovery at "Critical" Cyber Risk

August 28, 2026

  • UAC-0099 is deliberately tripping LLM safety filters to block malware analysis. ESET documented GuardBreaker, used against a Ukrainian victim: the operators pad a malicious VBS downloader with a comment asking for help building a nuclear weapon, so an AI-assisted analysis pipeline refuses and never reaches the actual MATCHBOIL installer logic (ESET Research). Anyone running LLM triage in a malware workflow should assume this is now standard tradecraft. · AI & Model Security

in Australia Charges Two Over the TeamPCP Supply-Chain Spree

July 29, 2026

  • ESET is tracking 100+ EDR killers, with 60+ still relying on BYOVD against legitimate-but-vulnerable drivers. The team notes the Gentlemen gang runs a shared defense-evasion layer — in-house GentleKiller plus third-party and leaked tools — and can operationalize new BYOVD PoCs within days, a supply they expect to grow as actors weaponize thousands of vulnerable drivers with AI coding assistance (ESET). · Threat Activity

in Artifactory Zero-Days Confirmed as the Hugging Face AI Agent's Escape Route

June 26, 2026

  • ESET detailed Gamaredon's 2025 evolution: six new PowerShell downloaders (PteroDee, PteroDum, PteroPaste, PteroOdd, PteroEffigy, PteroCache) plus the revived PteroSetup weaponizer, 35 spear-phishing campaigns against Ukrainian government/military, and heavy infrastructure laundering via Cloudflare Workers, Microsoft dev tunnels, Loophole, and dead drops on Telegram, Telegraph, Rentry, Dropbox, Supabase and Clever Cloud. WeLiveSecurity, whitepaper + IOCs · Threat Intelligence

in Malware Weaponizes Prompt Injection to Sabotage AI Analysis as Gamaredon Retools Against Ukraine

June 25, 2026

  • Operation Endgame dismantled the shared infrastructure behind the Amadey and StealC infostealers, with Microsoft's DCU, Europol, Bitdefender, Bitsight, and ESET taking down 300+ servers and 200+ domains, recovering ~27M stolen credentials, and seizing over $47M; Microsoft also leaned on AI to link the operations in a racketeering suit. Microsoft, The Record, The Register · Threat Intelligence

in Cisco SD-WAN Manager Zero-Day Gives Root via a Malicious CSV as Operation Endgame Smashes Amadey and StealC

June 21, 2026

  • ESET published a deep dive on the Gentlemen RaaS's EDR-killer portfolio, centered on the in-house GentleKiller framework (eight variants, each impersonating a different legitimate product) and supplemented with HexKiller, ThrottleBlood, and HavocKiller. Across builds it targets 400+ processes mapped to 48 security products; leaked Gentlemen data confirmed GentleKiller as an internal tool and linked one affiliate to a stealer ESET named OxideHarvest. IoCs are on GitHub (WeLiveSecurity, BleepingComputer). · Ransomware & EDR Evasion
  • DeadLock is expanding its abuse of Polygon blockchain smart contracts — moving beyond chat-proxy rotation to host its data-leak site entirely on-chain (75 victims since February), with HTML ransom notes fetching victim data live from the contract (ESET). Nextron flagged KRYBIT, a new double-extortion strain whose YARA profile overlaps heavily with the leaked Babuk codebase (Nextron), and Prinz Eugen emerged prioritizing recently-modified files for faster encryption while leaving no ransom note (BleepingComputer). · Ransomware & EDR Evasion
  • ESET uncovered two undocumented Windows variants of the SprySOCKS backdoor (WIN_DRV and WIN_PLUS), attributed with high confidence to China-nexus FishMonger and used against governments in Honduras, Taiwan, Thailand, and Pakistan. WIN_DRV weaponizes a kernel driver to redirect traffic to a hidden TCP port triggered by crafted packet data, with possible UEFI bootkit involvement (WeLiveSecurity, The Hacker News). · Threat Intelligence

in FortiBleed Exposes 86,000 FortiGate Devices as North Korea's Sapphire Sleet Poisons the Mastra npm Catalog

June 20, 2026

  • ESET dissected GentleKiller, the in-house EDR-killer at the core of the Gentlemen RaaS portfolio — eight variants, each impersonating a legitimate product, collectively targeting 400+ processes mapped to 48 security products, and combined with externally sourced HexKiller, ThrottleBlood, and HavocKiller. A leak of Gentlemen's own data also linked an affiliate to a stealer ESET named OxideHarvest; IoCs are published. The Hacker News, WeLiveSecurity · Ransomware & Extortion
  • DeadLock is expanding its use of Polygon smart contracts — now hosting its leak-site entries on-chain (75 victims since February) in addition to chat-proxy rotation, with notes fetching victim data live from the contracts. ESET · Ransomware & Extortion
  • ESET attributed two undocumented Windows variants of the previously Linux-only SprySOCKS backdoor (WIN_DRV, WIN_PLUS) to China-nexus FishMonger; WIN_DRV weaponizes a kernel driver for a passive, hidden-port TCP backdoor triggered by crafted packets, used against governments in Honduras, Taiwan, Thailand, and Pakistan. The Hacker News, WeLiveSecurity · Threat Intelligence & Espionage

in FortiBleed Burns 86,000 FortiGate Devices as Novo Nordisk Loses 1.3TB — Including AI Models — to a Leaked GitHub Token