Skip to content

Tracking Turla: ESET researchers discover attack on governmental websites in Armenia

BRATISLAVA, MONTREAL – ESET researchers have found a watering hole operation targeting several high-profile Armenian websites. It relies on a social engineering trick — a fake Adobe Flash update — as a lure to deliver two previously undocumented pieces of malware. In this specific operation, Turla has compromised at least four Armenian websites, including two belonging to the government. Thus, it is likely the targets include government officials and politicians.

Turla is an infamous cyberespionage group active for more than 10 years. Its main targets are government and military organizations. This recent operation bears similarities to the modus operandi of several of Turla’s watering hole campaigns in the past.

ESET Research has indications that these websites had been compromised since at least the beginning of 2019. We notified the Armenian national CERT and shared our analysis with them before publication.

“If the visitor is deemed interesting, the C&C server replies with a piece of JavaScript code that creates an IFrame. Data from ESET telemetry suggests that, for this campaign, only a very limited number of visitors were considered interesting by Turla’s operators,” comments ESET researcher Matthieu Faou on the victims of the attack.

“A fake Adobe Flash update pop-up window warning to the user is displayed in order to trick them into downloading a malicious Flash installer. The compromise attempt relies solely on this social engineering trick,” he adds.

Interestingly, in this latest campaign Turla utilizes a completely new backdoor dubbed PyFlash. ESET believes this is the first time the Turla developers have used the Python language in a backdoor. The command and control server sends backdoor commands that include downloading files, executing Windows commands, and launching or uninstalling malware. “The final payload has changed, probably in order to evade detection,” explains Faou.

For more details about the latest Turla campaign, read the blogpost Tracking Turla: New backdoor delivered via Armenian watering holes on WeLiveSecurity. Make sure to follow ESET research on Twitter for the latest news from ESET Research.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

ESET Research dissects Guildma: Most impactful and YouTube-abusing Latin American banking trojan

BRATISLAVA, PRAGUE – In the latest installment about Latin American banking trojans, ESET researchers take a deep look at the most impactful and advanced banking trojan we have seen in this series and in the region: Guildma. This malware is specifically targeting banking institutions and attempts to steal credentials for email accounts, e-shops and streaming services in Brazil. It affects at least 10 times as many victims as other Latin American banking trojans that ESET Research has analyzed. During its peak – a massive campaign in 2019 – ESET recorded up to 50,000 attacks per day. Guildma spreads exclusively via spam emails with malicious attachments.

In one of its latest versions, Guildma employs a new way of distributing command and control servers, abusing YouTube and Facebook profiles. However, the authors stopped using Facebook almost immediately and, at least at this time, are relying fully on YouTube.

“Guildma uses very innovative methods of execution and sophisticated attack techniques. The actual attack is orchestrated by its C&C server. This gives the authors greater flexibility to react to countermeasures implemented by the targeted banks,” explains Robert Šuman, the ESET researcher leading the team analyzing Guildma.

Guildma boasts a backdoor with multiple functionalities, including taking screenshots, capturing keystrokes, emulating keyboard and mouse, blocking shortcuts (such as disabling Alt + F4 to make it harder to get rid of fake windows it may display), downloading and executing files, and/or rebooting the machine. In addition, Guildma is very modular and currently consists of at least 10 modules. The malware uses tools already present on the machine and reuses its own techniques. “New techniques are added every once in a while, but for the most part, the developers seem to simply reuse techniques from older versions,” says Šuman.

In one of the earlier 2019 versions, Guildma added the capability to target institutions (mainly banks) outside of Brazil. Despite that, over the past 14 months, ESET has not observed any international campaigns outside Brazil. The attackers went as far as to block any downloads from non-Brazilian IP addresses.

Guildma campaigns were ramping up slowly until a massive campaign in August 2019, when ESET Research recorded up to 50,000 samples per day. This campaign went on for almost two months and accounted for more than double the amount of detections seen in the 10 months prior.

First-stage Guildma detections since July 2019

First-stage Guildma detections since July 2019

The trojan has seemingly gone through many versions during its development, but there was usually very little development between versions due to its clunky architecture.

Distribution chain of Guildma in the latest version analyzed by ESET (150)

Guildma shares several prevailing characteristics of Latin American banking trojans. For more technical details, read the blog post Guildma: The devil drives electric on WeLiveSecurity. Make sure to follow ESET Research on Twitter for the latest news from ESET Research. 

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

ESET discovers Kr00K: Communications of a billion+ devices were at risk

BRATISLAVA, SAN FRANCISCO – February 26, 2020 – ESET researchers have discovered Kr00k (CVE-2019-15126), a previously unknown vulnerability in Wi-Fi chips used in many client devices, Wi-Fi access points and routers.

Kr00k is a vulnerability that causes the network communication of an affected device to be encrypted with an all-zero encryption key. In a successful attack, this allows an adversary to decrypt wireless network packets.

The discovery of Kr00k follows previous ESET research into the Amazon Echo being vulnerable to KRACKs (Key Reinstallation Attacks). Kr00k is related to KRACK, but is also fundamentally different. During the investigation into KRACK, ESET researchers identified Kr00k as one of the causes behind the “reinstallation” of an all-zero encryption key observed in tests for KRACK attacks. Subsequent to our research, most major device manufacturers have released patches.

Kr00k is particularly dangerous because it has affected over a billion Wi-Fi enabled devices – a conservative estimate.

ESET will publicly present its research into this vulnerability for the first time on February 26 at the RSA Conference 2020.

Kr00k affects all devices with Broadcom and Cypress Wi-Fi chips that remain unpatched. These are the most common Wi-Fi chips used in today’s client devices. Wi-Fi access points and routers are also affected by the vulnerability, making even environments with patched client devices vulnerable. ESET tested and confirmed that among the vulnerable devices were client devices by Amazon (Echo, Kindle), Apple (iPhone, iPad, MacBook), Google (Nexus), Samsung (Galaxy), Raspberry (Pi 3) and Xiaomi (Redmi), as well as access points by Asus and Huawei.

ESET responsibly disclosed the vulnerability to the chip manufacturers Broadcom and Cypress, who subsequently released patches. We also worked with the Industry Consortium for Advancement of Security on the Internet (ICASI) to ensure that all possibly affected parties – including affected device manufacturers using the vulnerable chips, as well as other possibly affected chip manufacturers – were aware of Kr00k. According to our information, devices by major manufacturers have now been patched.

“Kr00k manifests itself after Wi-Fi disassociations – which can happen naturally, for example due to a weak Wi-Fi signal, or may be manually triggered by an attacker. If an attack is successful, several kilobytes of potentially sensitive information can be exposed,” explains Miloš Čermák, the lead ESET researcher into the Kr00k vulnerability. “By repeatedly triggering disassociations, the attacker can capture a number of network packets with potentially sensitive data,” he adds.

 

Figure: An active attacker can trigger disassociations to capture and decrypt data.

“To protect yourself, as a user, make sure you have updated all your Wi-Fi capable devices, including phones, tablets, laptops, IoT smart devices, and Wi-Fi access points and routers, to the latest firmware version,” advises Robert Lipovský, an ESET researcher working with the Kr00k vulnerability research team. “Of great concern is that not only client devices, but also Wi-Fi access points and routers that have been affected by Kr00k. This greatly increases the attack surface, as an adversary can decrypt data that was transmitted by a vulnerable access point, which is often beyond your control, to your device, which doesn’t have to be vulnerable.”

For more technical details about Kr00k, read the white paper Kr00k – CVE-2019-15126 Serious vulnerability deep inside your Wi-Fi encryption and blogpost on WeLiveSecurity. Make sure to check out Kr00k in depth on its dedicated landing page and follow ESET Research on Twitter for the latest news from ESET Research.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

ESET Deep Behavioral Inspection enables deeper monitoring of unknown & suspicious processes

BRATISLAVA, February 25, 2020 – Today, ESET released a white paper focusing on ESET Deep Behavioral Inspection (DBI) – the latest enhancement of the system specifically designed to perform advanced behavioral analysis and detection known as ESET Host-based Intrusion Prevention System (HIPS).

“Cyber criminals will go to great lengths to achieve their ultimate goal –stealing information, computing resources or money.  Apart  from social  engineering  techniques, they employ  technical tricks such  as obfuscation, encryption, and process injection, designed to help their code avoid detection by built-in as well as third-party security solutions,”explains ESET Security Awareness Specialist Ondrej Kubovič. “ESET DBI, together with  other  HIPS modules,represents an  important  protective layer that can detect and report these tricks and thus block malicious activity on the targeted system,”he adds.

Deep Behavioral Inspection,as one of the latest technological additions to the ESET HIPS framework,can be  found in  the  latest  edition of ESET products for both home and  business users. DBI includes new detection heuristics and enables an even   deeper user-mode monitoring of unknown,suspicious processes. This is accomplished via hooks created by DBI within unknown, potentially harmful processes and monitoring of their activity and requests to the operating system. If malicious behavior is detected, DBI mitigates the activity and informs the user. If the process is suspicious, but does not show clear signs of malicious behavior, HIPS can also use the data gathered by  DBI to run further analysis via its other modules.

ESET Host-based Intrusion Prevention System is a detection technology specifically  created to monitor and scan behavioral events from running processes, files and  registry keys,looking for  suspicious activity. It focuses on a variety of malicious behaviors used either to wreak havoc on a victim’s device or to avoid detection by security solutions. The list of HIPS modules includes:

  • Advanced Memory Scanner (AMS)
  • Exploit Blocker (EB)
  • Ransomware Shield(RS)
  • Deep Behavioral Inspection (DBI)

(Image below: Schematic of how DBI fits into the existing HIPS process monitoring layer)

For more details on the inner workings of ESET HIPS read the latest white paper, “ESET Deep Behavioral Inspection” on https://www.welivesecurity.com/. Make  sure  to follow ESET research on Twitter for the latest news from ESET Research.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

MENDEL 3.5 NOW AVAILABLE

GREYCORTEX is happy to announce that we have released the latest version of our MENDEL network traffic analysis solution. Version 3.5.0 brings important features, improvements, and bug fixes. Among major features, you can find Central Event Management, which enables users to create multi-level appliance structure for exhaustive network overview, or data export into CSV format for more in-depth analysis or enriching other big data tools.

This version contains a number of major changes in the system. To ensure a smooth upgrade process and to provide support to all our partners and customers, we will be introducing this release gradually over the next 14 days.

NEW FEATURES

Data Export into CSV format

MENDEL users can now export data regarding hosts, network, flows, and even incidents into csv. format for further processing and creation of new network data visualizations.

Central Event Management

For customers or partners with larger deployments, MENDEL offers the ability to connect appliances using a multi-level structure; consisting of sensors, collectors, and a Central Event Management console. This provides a more comprehensive overview of the full network.

Validating SSL and TLS certificates

For encrypted communication, MENDEL detects expired or invalid SSL and TLS certificates and alerts the user.

ARP protocol parser

We have added the ability to parse the communications using the Address Resolution Protocol for even better processing of non-IP data.

ENHANCEMENTS

Operating system identification using L7 data

MENDEL is able to detect the operating system of the host more precisely, using an advanced data model based on Samba, DHCP, HTTP, SSH, and L3/L4 parameters, among others. Data is also presented within a new dashboard showing the top operating systems in the network for the chosen period.

Filtering data by additional values

We added the option to filter by additional variables, including operating system, interface, application, and port range.

New predefined dashboards

We have provided two new dashboards: Risks and Statistics; for our users to quickly and easily review the situation in their network.

Additional Enhancements:

  • Upgrade of system components
  • Printer tagging
  • Browser protocol parser
  • Sensor-Collector management
  • Enhanced TLS 1.3 protocol parser
  • Extended host/subnet lease time
  • Configurable display level
  • Decoding QoS/DSCP
  • System improvements
  • Network capture module improvements
  • GUI improvements
  • Localization improvements 

SCADA

MMS protocol processing

For the visualization of MMS protocol data and further analysis, we added MMS protocol processing.

Asset resources management

We added the ability to name, manage, and add new devices in the network.

DLMS/COSEM protocol parser

We added parsing for DLMS/COSEM, one of the most widely accepted international standards for utility meter data exchange.

OMRON FINS protocol parser

We added parsing for the OMRON FINS protocol, which can be used by a PLC program to transfer data and perform other services with a remote PLC connected on an ethernet network.

FIXED ISSUES

In general, our development team focused on improving user experience and reporting. As well as more improvements to user experience, system stability, and performance.

Please note that upgrading to version 3.5.0 will replace the system kernel and reboot the appliance.

We recommend having direct or remote access to the appliance in order to be able to restart it if necessary.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.


About GREYCORTEX
GREYCORTEX uses advanced artificial intelligence, machine learning, and data mining methods to help organizations make their IT operations secure and reliable.

MENDEL, GREYCORTEX’s network traffic analysis solution, helps corporations, governments, and the critical infrastructure sector protect their futures by detecting cyber threats to sensitive data, networks, trade secrets, and reputations, which other network security products miss.

MENDEL is based on 10 years of extensive academic research and is designed using the same technology which was successful in four US-based NIST Challenges.

ESET Named a Strong Performer in Endpoint Security Suites 2019 Report by Independent Research Firm

BRATISLAVA, February 7, 2020, ESET – a global leader in information security software – has been recognized as a “strong performer” in The Forrester Wave™: Endpoint Security Suites Q3 2019 report. The prestigious report assessed the top 15 security suites in the market, including their ability to prevent, detect, and remediate endpoint threats, with ESET emerging as a strong performer.

In reviewing the overall market, the report stated that “endpoint security suite buyers prioritize automatic threat protection.” The report highlights that endpoint security suites are now increasingly “tasked with protecting against targeted-style threats” and that therefore, customers should look for providers that “tightly integrate threat prevention, detection, and response,” “extend visibility and control over a broad endpoint ecosystem,” and “offer flexibility in a variety of environments and risk tolerances.”

The report recognized ESET’s full portfolio of enterprise offerings since ESET has widened our focus to cater to increased enterprise market demands. ESET received the highest score possible in the corporate vision and focus criterion and was noted for developing several capabilities aimed at enterprise buyers, such as Endpoint Detection and Response (EDR), managed detection and response, threat intelligence services, and vulnerability management. ESET also had the highest score possible in the OS support criterion, which is defined as having broad operating systems support relative to others in the evaluation. 

To assess the state of the endpoint security suites market and see how the vendors stack up against each other, Forrester evaluated the strengths and weaknesses of the top vendors. After examining past research, user need assessments, and vendor and expert interviews, Forrester developed a comprehensive set of 25 criteria, which they group into three categories:

•    Current offering. Each vendor’s position on the vertical axis of the Forrester Wave™ graphic indicates the strength of its current offering. Key criteria for this evaluation include malware and exploit prevention, behavioral detection, and product performance, which Forrester validated using customer feedback and demos/briefings.

•    Strategy. Placement on the horizontal axis indicates the strength of the vendors’ strategies. Here, Forrester evaluated corporate vision and focus, security community, and product road map.

•    Market presence. Represented by the size of the markers on the graphic, Forrester’s market presence scores reflect each vendor’s enterprise customer base and licensing partner ecosystem.

The Forrester Wave™ report details that security professionals want an endpoint security suite that can protect the increasing number of devices brought into the workplace and handle the increasing complexity of the security landscape. For vendors, improved behavioral protection combined with risk-based security policies will lead the way in cybersecurity solutions. We believe this is reflected in ESET’s success in receiving the highest score possible in the security community involvement, OS support, and corporate vision and focus criteria.

The report states in ESET’s profile that “ESET is perfect for buyers who value a simple, straightforward UI with more advanced functions easily invoked when required,” with ESET customers continually rating the company exceptionally well for its low impact to user experience.

Juraj Malcho, ESET’s chief technology officer, commented, “We believe the recognition of ESET as a strong performer in Forrester’s latest Endpoint Security Suite Wave is a testament to our commitment to delivering premium security to the enterprise sector. The enterprise threat landscape is constantly evolving in sophistication, and it is central to our mission that our users are protected against complex threats with the highest standard of security solutions. In our increasingly digitized world, it is imperative that enterprises and their data are safe and secure.”

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.


About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

AV-Comparatives recognizes ESET consumer products with gold medals in cybersecurity awards

BRATISLAVA, February 6, 2020 – ESET, a global leader in cybersecurity, has been recognized with gold and bronze awards in the AV-Comparatives Summary Report 2019. AV-Comparatives, a leading independent testing organization, uses one of the largest sample collections worldwide to create a real-world environment for highly accurate testing. Their Summary Report 2019 provides commentary on the consumer antivirus products tested over the course of the year, and highlights the high-scoring products from the different tests that took place over the 12 months.

The report looked at consumer Windows products from 16 different vendors, with excellent results for ESET, taking awards in three categories: Overall Performance (Low System Impact), Enhanced Real-World Test (Advanced Threat Protection), and the False Positive Test.

Overall Performance (Low System Impact)

ESET was awarded a gold medal in the Low System Impact category, which assesses each product’s impact on system speed and performance. ESET has consistently achieved great results in this category, improving on its silver award in the same category in 2018.

Enhanced Real-World Test (Advanced Threat Protection)

ESET took a gold medal in the Advanced Threat Protection category, which is a new category for 2019 and 2020. This test addresses a program’s ability to protect against advanced targeted and fileless attacks. ESET was also one of only two vendors to block all 15 targeted attacks in the testing process.

False Positive Test

ESET was awarded a bronze medal in the False Positive Test. As the report notes, false positives can cause as much trouble as a real infection, and avoiding them is a crucial element of any antivirus product. AV-Comparatives carried out extensive false-positive testing as part of the Malware protection tests and the Real-World Protection Test.

Commenting on the results, Jiří Kropáč, head of threat detection labs at ESET, said: “ESET’s recognition from AV-Comparatives is testament to our dedication to our customers and our promise to always deliver the best in IT security solutions. Ensuring consumers are equipped with cutting-edge protection against the latest threats is extremely important to us. We are honored to receive these awards and to be recognized as a key player in making technology safer for everyone.”

Read AV-Comparative’s Summary Report 2019 for more information.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.


About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

ESET launches Version 3.0 of Secure Authentication

Bratislava – ESET, a global leader in cybersecurity, has launched Version 3.0 of ESET Secure Authentication (ESA), a multifactor authentication solution that allows businesses of all sizes to secure mobile devices, prevent data breaches, and meet compliance requirements. This new version of the solution brings a range of updates, including the introduction of the Identity Connector and support for biometric authentication.

The Identity Connector gives customers the option to employ ESA to protect any service or application that uses a third-party identity provider, via the SAML authentication protocol integration. This significantly extends integration capabilities, now allowing customers to use ESA to protect access to a wide range of services and environments, such as email, VPN, Office 365 or Dropbox.

Version 3.0 also introduces support for native biometric authentication in ESA mobile apps, meaning users can now use integrated fingerprint scanners and facial recognition when approving authentication requests.

The new Notification Center gives users the option to configure their own notifications, so they can be proactively informed without the need to be logged in. The update also provides major performance improvements, bringing customers a robust solution to cover larger deployments.

Vladimír Maťovčík, senior product manager at ESET, states: “Business security solutions need to be reliable, be easy to use and cause minimal impact to a company’s processes. With an increasing need for organizations to protect a range of devices and environments, ESET Secure Authentication provides a simple, effective mobile-based solution that secures data and cloud access without affecting employee productivity.”

“The introduction of the Identity Connector increases the solution’s level of security, whilst the improved performance and addition of support of iOS and Android biometrics makes the experience even smoother for users.” 

For further information on ESET Secure Authentication, click here.  

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.


About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

 

ESET to Lead Linux Malware Workshop and Showcase Groundbreaking Amazon Echo KRACK Research at RSA 2020

Bratislava, Slovakia – January 23, 2020 ESET, a global leader in IT security, today announced a number of activities at next month’s RSA Conference 2020 (February 24-28 in San Francisco). 

ESET Malware Researcher Marc-Etienne M. Léveillé will lead a main stage workshop titled “Hunting Linux Malware for Fun and Flags.” The 50-minute workshop will take place on February 27 at 1:30 PM at Moscone West 3002. Attendees will learn to fight real-world Linux malware targeting server environments and to search for malicious processes and concealed backdoors in a compromised web server. Several examples of malware will be demonstrated with increasing layers of complexity, from scripts to ELF binaries with varying degrees of obfuscation.

ESET Senior Malware Researcher Robert Lipovský and Senior Detection Engineer, Štefan Svorenčík will present a 30-minute session on “Kr00k: How KRACKing Amazon Echo Exposed a Billion+ Vulnerable Wi-Fi Devices” on Wednesday, February 26 at 3:00pm PT at Moscone South. 

On the RSA trade show floor, ESET will be located at booth #753 in the South Hall. Senior Malware Researcher Robert Lipovský will discuss ESET’s latest cutting-edge threat research, including Operation Ghost and KRACKing the Amazon Echo. Malware Removal Support Supervisor James Rodewald will be leading demonstrations of ESET’s award-winning enterprise, SMB and consumer products. Malware Researcher Marc-Etienne M. Léveillé will also review his conference presentation and answer questions from attendees. 

Directly outside the conference, ESET will be running a four-day contest. Attend any of ESET’s inspiring presentations or live demos and get a chance to win the newest MacBook Pro 13, an iPhone 11, iPad, or Apple Watch in a prize raffle. Please see here for more details and contest rules. 

“RSA is a fantastic opportunity for our customers – both current and prospective – to see our multilayered suite of security solutions in action,” said Tony Anscombe, chief security evangelist at ESET. “The cybersecurity landscape has evolved drastically over the past decade, and we expect this to continue in the years to come. ESET is proud to be at the forefront of the field, and we are looking forward to showcasing our groundbreaking research, both on stage and at our trade show booth. We’re excited to meet and talk to attendees next month at RSA.”

Want to meet on-site with ESET at RSA? Please visit https://www.eset.com/us/rsac/.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.


About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

NEW GREYCORTEX AREA MANAGER – ALENA ŘEZNÍČKOVÁ

GREYCORTEX is happy to announce that beginning January 1st, Alena Řezníčková will be the new Area Manager for the Czech Republic and Slovakia. Řezníčková has been working in the IT security field since 1992. She has held business and managerial positions in several well-known Czech and international companies, including AEC, ASSECO, PCS, ANECT, McAfee, and Intel Czech Tradings. Prior to assuming the Area Manager role, she worked with GREYCORTEX for several months as an external consultant.

“During the time I have worked with the GREYCORTEX team, I’ve seen for myself that MENDEL, the GREYCORTEX solution for network security monitoring, is a unique product with great potential. The GREYCORTEX team is made up of committed and determined professionals with great personal qualities. It is fascinating to continually experience the “wow effect” when presenting MENDEL to customers and visualizing their networks; since, with MENDEL, they can see what is happening inside their infrastructure. Our clients and customers appreciate that they are part of the team in terms of discussions about our road map and the development of the solution. I can see my main mission in these two areas: strengthening the partner channel and expanding the partner network, including the full lifecycle of cybersecurity management, further leveraging experience and customer needs to develop our solutions,” said Řezníčková.

GREYCORTEX CEO, Petr Chaloupka added: “Alena has many years of experience working in companies offering cyber security solutions and in managing business teams. In previous positions, especially as Country Manager of McAfee (later Intel), she managed to build mutually beneficial partnerships with technology companies in the Czech Republic and Slovakia. I appreciate her involvement in the activities of the Czech branch of AFCEA and long-term relationships with key personalities of IT security.”