Ultra-fast high-accuracy threat scanner from ESET, now available in AWS Marketplace

  • ESET PRIVATE Scanning Solutions are now available in AWS Marketplace.
  • AWS Marketplace is a curated digital catalog where businesses can find, buy, and deploy third-party software, data products, and professional services that run on AWS. 
  • AWS customers can streamline the purchase and management of ESET PRIVATE Scanning Solutions within their AWS Marketplace account.  

BRATISLAVAAugust 19, 2026 — ESET, a global leader in cybersecurity solutions, announced today that its ESET PRIVATE Scanning Solutions are now available in AWS Marketplace.

Customers increasingly expect seamless purchase and service options when seeking to procure products, and this is helping to establish AWS Marketplace as a primary commercial and deployment channel. AWS customers will now have access to ESET PRIVATE Scanning Solutions’ ultra-fast multilayered threat scanning directly within AWS Marketplace, and are able to streamline purchase and management within their AWS Marketplace account. This helps to reduce time-to-value and allows security and DevOps teams to deploy the solution faster.

“Today’s organizations expect security solutions they can evaluate quickly, purchase seamlessly, and deploy without delay. By making ESET PRIVATE Scanning Solutions available in AWS Marketplace, we’re simplifying procurement while enabling organizations to integrate high-performance threat scanning into their cloud applications to help protect critical data flows,” said Head of Corporate Solutions NORAM, Andrea Doyle. 

ESET PRIVATE Scanning Solutions’ static scanning engine scans large volumes of inbound data, providing real-time threat detection that scales dynamically with workloads. It enables organizations to inspect files before they are stored, shared, or processed. Built for accuracy, it uses advanced behavioral analysis to detect malware and zero-day threats, integrating into apps, storage platforms, upload portals, and others, to detect malware in milliseconds without requiring full endpoint security deployment. 

Visit AWS Marketplace to learn more and try our scanning solution for one month for free.

Discover the benefits of ESET PRIVATE’s tailored security line.

Learn more about ESET PRIVATE Scanning Solutions and its use case for enterprise data pipelines.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

ESET showcases cutting-edge AI Security at Black Hat 2026

LAS VEGASAugust 3, 2026 — ESET, a global leader in cybersecurity, today announced cutting-edge security AI solutions at Black Hat 2026 in Las Vegas, Nevada. ESET is expanding its AI capabilities across threat detection, investigations, threat protection, and security operations, delivering added value to customers through built-in innovations rather than separate add-on solutions.

“AI is a new class of actor inside the company – reading, writing, making decisions and executing. As such, it deserves the same security attention as users and endpoints, because it behaves like both at once,” said Kamil Pšenák, Senior AI Product Manager at ESET. “It is all converging around the endpoint. What used to be a neglected part of the cybersecurity stack is now primed to shine anew thanks to the proliferation of AI tools at a business level.”

As a pioneer in AI and machine learning for more than two decades, ESET has long used AI to strengthen threat prevention and detection. As organizations rapidly adopt AI tools and autonomous agents—often without IT oversight—ESET is expanding its portfolio to help customers secure AI itself, reducing the security and compliance blind spots created by shadow AI. Available September 30 across the ESET PROTECT portfolio, new features include:

  • ESET AI Agent Security: As autonomous AI agents access files, download components, call external services, use repositories, interact with code, or rely on skills and plugins, they may introduce malicious or compromised elements into the customer environment. AI Agent Security helps protect against this risk by inspecting AI-related components across the entire AI supply chain.
  • ESET AI Behavioral Monitoring: Where AI Agent Security helps inspect components and supply-chain activity, AI Behavioral Monitoring focuses on the behavior and actions of autonomous agents. It is designed to detect and block malicious or suspicious activity from AI agents, such as agents that attempt to access inappropriate resources, run unsafe actions, or behave outside the expected scope of their task.
  • ESET AI Conversation Security: Designed for organizations using generative AI tools, this capability helps reduce the risk of unsafe prompting or accidental data leakage by inspecting uploaded files and metadata for sensitive content. It also helps protect users from malicious AI-generated responses by flagging content originating from phishing, malicious, or unwanted websites.

Built on ESET’s best-in-class prevention system and decades of AI expertise, these new capabilities help organizations manage AI risk without adding complexity. ESET owns the technology, models, and intelligence behind these protections, embedding them directly into ESET AI Technologies rather than bolting on third-party solutions, or requiring customers to manage separate tools and platforms.

By extending protection to AI agents, behaviors, and conversations, ESET empowers channel partners and IT teams to secure the AI era and defend against emerging threats at scale through a single, unified solution that delivers stronger protection with less operational overhead and no additional cost.

“AI is changing the conversations our partners are having with customers,” said Ryan Grant, Country Manager, U.S. and Canada at ESET. “Instead of simply reacting to new AI risks, partners can lead with a prevention-first strategy that helps businesses adopt AI securely while reducing operational complexity. That’s a meaningful opportunity to deepen customer relationships and grow recurring security services.”

At Black Hat 2026, visitors to ESET’s booth #4917 can learn more about the company’s AI-driven cybersecurity innovations, threat intelligence and managed detection and response (MDR) capabilities. Throughout the event, ESET researchers, partners, product leaders and cybersecurity experts will present on the impact of AI on cybersecurity, real-world MDR incident response and how to build resilience through intelligence-led defense.

Highlights at Black Hat 2026 include:

  • Thursday, Aug. 6, 2:05–2:25 p.m. – Kamil Pšenák will present The Shock of AI Impact and How to Absorb It at Pulse Stage 5, examining how organizations can responsibly adopt AI while defending against emerging cyber threats.
  • Thursday, Aug. 6, 3:15–3:35 p.m. – Tony Anscombe will join Dark Reading panel discussion, Cyber Extortion Hacked, at Pulse Stage 5 to discuss the rise of data extortion attacks and practical response strategies.
  • Wednesday, Aug. 5, 3:00 p.m. & Thursday, Aug. 6, 1:00 p.m. – Celebrity book signing with Tanya Janca, internationally recognized application security expert, author, and founder of SheHacksPurple, featuring signed copies of Alice and Bob Learn Secure Coding while supplies last.
  • ESET x Intel: Intelligence-Led Defense – ESET’s Kamil Pšenák and Intel’s Tyler Welt will showcase how ESET PROTECT leverages Intel DTECT, using processor-level execution telemetry and AI models to identify sophisticated threats, alongside advanced Cloud Workload Protection capabilities that improve visibility, simplify security operations and transform SOCs from reactive to proactive.
  • Interactive experiences including the Cybersecurity Trivia Showdown and The Great Escape: Cyber Challenge, where attendees can test their cybersecurity knowledge and skills.

Discover more about ESET’s presence at Black Hat 2026. Learn more about AI and ESET.

 

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

ESET Research discovers vulnerable UEFI shims undermining devices’ Secure Boot

  • ESET researchers discovered 11 old, Microsoft-signed, UEFI applications that allow bypassing UEFI Secure Boot on the majority of UEFI-based systems.
  • An attacker exploiting one of these vulnerable applications can execute untrusted code during system boot, enabling deployment of malicious UEFI bootkits or other malware.
  • Exploitation is not limited to systems with the affected software or Operation system (OS) installed, as attackers can bring their own copy of the vulnerable binaries to any UEFI system with the Microsoft third-party UEFI certificate enrolled.
  • All UEFI systems with Microsoft third-party UEFI signing enabled are affected (Windows 11 Secured-core PCs are expected to have this option disabled by default).
  • The vulnerable binaries were revoked by Microsoft.

BRATISLAVAJuly 14, 2026 — ESET researchers discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass UEFI Secure Boot by exploiting decade-old vulnerabilities. UEFI shim bootloaders are tiny bits of code designed to bridge the gap between motherboard UEFI firmware and an operating system. The vulnerable shims, at versions 0.9 and below, can be used to bypass UEFI Secure Boot on any UEFI-based machine that trusts the Microsoft Corporation UEFI CA 2011 third-party UEFI certificate authority (CA) certificate, regardless of the installed operating system. Reported shims can be exploited to execute untrusted code during system boot, enabling attackers to deploy malicious UEFI bootkits even on systems with UEFI Secure Boot enabled. ESET reported findings to CERT/CC; the vulnerable UEFI applications were then revoked.

The discovered shims come from various tools or software packages, including PC-diagnostic software, Linux distributions, and other UEFI-based utilities. Importantly, exploitation is not limited to systems with the affected software or OS installed, as attackers can bring their own copy of the vulnerable shims to any UEFI system with the Microsoft third-party UEFI certificate enrolled.

“What makes these old shims dangerous is not a novel vulnerability; it’s that no new vulnerability is needed to bypass UEFI Secure Boot. An attacker needs no complicated exploitation primitives – only a copy of an old, still-trusted, but unrevoked shim binary and a basic understanding of how UEFI shims work. That is enough to bypass such an essential security feature as UEFI Secure Boot,” says ESET researcher Martin Smolár, who discovered the vulnerable shims.

“To understand the impact that such vulnerable shims can have on UEFI Secure Boot-protected systems, in the report we examine a few specific issues in the reported shims – issues that are easily exploitable and that highlight the breadth of the attack surface they expose,” adds Smolár.

Over the years, the UEFI shim bootloader has naturally evolved, with new improvements and security features introduced in successive releases of the upstream UEFI shim repository. At the same time, many third-party vendors have taken available versions of the shim source code to build their own binaries, which they subsequently submitted to Microsoft for signing. This behavior is expected and aligns with the original design of shims. However, insufficient attention has been given to revoking outdated Microsoft-signed shims, many of which can, by design, be leveraged to bypass newer security mechanisms. 

These vulnerable shims can be blocked by applying the latest UEFI revocations from Microsoft. Windows systems should be updated automatically.  For Linux systems, updates should be available through the Linux Vendor Firmware Service. For more general recommendations regarding how to protect against (or at least detect) exploitation of unknown vulnerable signed UEFI bootloaders and deployment of UEFI bootkits, see ESET Research blogpost: Under the cloak of UEFI Secure Boot: Introducing CVE-2024-7344.

For a more details about the vulnerable UEFI shims, check out the ESET Research blogpost “Forgotten UEFI shims undermining Secure Boot” on WeLiveSecurity.com. Make sure to follow ESET Research on Twitter (today known as X), BlueSky, and Mastodon for the latest news from ESET Research.

Simplified UEFI boot flow on Linux systems

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

ESET Threat Report: AI boosts cyber attackers’ efficiency

  • ESET Research has released its H1 2026 Threat Report with statistics from December 2025 through May 2026.
  • ClickFix – a social engineering technique leveraging fake error messages – has expanded into AI-themed help pages, browser extensions, and cloud authentication scenarios.
  • QR code phishing – also known as quishing – has reached record levels in ESET telemetry.
  • ESET analyzed nearly 900,000 AI skills – small functional components used by AI agents – and identified tens of thousands of suspicious and thousands of malicious instances. AI is also beginning to appear within malware.
  • Ransomware showed no signs of slowing down, with its continued use of EDR killers – tools designed to disable security software during attacks.
BRATISLAVAJuly 8, 2026 — ESET Research has released its H1 2026 Threat Report, which summarizes threat landscape trends seen in ESET telemetry, as well as insights from ESET threat detection and research experts, from December 2025 through May 2026. The first half of 2026 shows how attackers continue to improve the efficiency and scalability of their operations. Artificial intelligence (AI) is playing a growing role in this development. ESET analyzed nearly 900,000 AI skills – small functional components used by AI agents – and identified tens of thousands of suspicious and thousands of outright malicious instances. AI is also beginning to appear within malware itself: ESET researchers have identified PromptSpy, the first known Android malware to use generative AI in its execution flow. “Rather than relying on entirely new methods and tools, attackers are quickly adapting established techniques to new platforms, technologies, and user behaviors. The number of AI skills within this new ecosystem is growing rapidly as we speak, further expanding the attack surface,“ says ESET Director of Threat Prevention Labs Jiří Kropáč. “On the other hand, PromptSpy illustrates the potential for increased flexibility in future threats – although guardrails against abuse included in LLMs are likely slowing down the adoption,” explains Kropáč. AI skills are small add-ons or sets of instructions that instruct an AI agent how to perform a specific task, including which services or tools to use and what data to access. The published report covers details about malicious AI skills using third-party hacking tools such as Mimikatz or Impacket and a suspicious self-modifying skills designed to create a persistence mechanism (JSON file) and a tool for self-modification (Python code). This can lead to unpredictable behavior of the agent or its abuse by an attacker. And finally, there are benign but problematic skills such as those marketed as security scanners, which create a false sense of security but implement only basic scanning techniques – like AV tools from the 1990s – or simply query the reputation of hashes, URLs, and IP addresses on VirusTotal. Meanwhile, ClickFix – a social engineering technique leveraging fake error messages – has expanded beyond fake CAPTCHA prompts into AI-themed help pages, browser extensions, and cloud authentication scenarios. AI-fix shows how adversaries exploit trust in generative AI, embedding ClickFix compromise chains into AI-generated troubleshooting content to nonexistent issues on pages that abuse domains of AI powerhouses. ConsentFix highlights an evolution toward token theft, combining ClickFix-style interaction with OAuth authorization abuse to hijack cloud accounts without the need to steal credentials, often bypassing MFA and relying entirely on legitimate login workflows. ESET detections of this vector more than doubled between H2 2025 and H1 2026, indicating sustained activity and adaptation. Phishing campaigns are also evolving in response to user behavior. QR code phishing – also known as quishing – has reached record levels in ESET telemetry, with attackers embedding malicious links in QR codes to bypass inspection and shift user interaction to mobile devices while exploiting the implicit trust many people place in the barcodes with square patterns. Approximately 11% of all detected phishing emails in H1 2026 utilized QR codes, and QR code phishing threats were most prevalent in the US (19% of detections), Spain (17%), and Mexico (6%). Last but not least, ransomware activity showed no signs of slowing down, with the continued use of EDR killers – tools designed to disable security software during attacks. ESET Research has documented over 100 different EDR killers used in the wild, with new variants appearing regularly. The number of ransomware attacks continued to grow in H1 2026, but the number of victims willing to pay reached all-time lows. Three recent industry reports confirmed this downward trend, reporting a 14–28% share of paying victims. For more information, check out the ESET Threat Report H1 2026 on WeLiveSecurity.com. Make sure to follow ESET Research on Twitter (today known as X), BlueSky, and Mastodon for the latest news from ESET Research.

Unique AI skills scanned by ESET systems per day, seven-day average

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

ESET takes part in global Operation Endgame to disrupt Amadey botnet and Stealc infostealer

  • ESET took part in a coordinated global operation to disrupt Amadey and Stealc.
  • The disruption operation aimed to seize or render inoperative all known Amadey and Stealc C&C servers, directly disrupting the infrastructure relied upon by both MaaS offerings’ affiliates.
  • ESET Research provided technical analysis, statistical information, known C&C servers, encryption keys, campaign identifiers, and other insights.
  • In its report, ESET Research provides an overview of the MaaS ecosystem at the affiliate level for both malware families.

BRATISLAVA, PRAGUEJune 24, 2026 — ESET Research assisted in disrupting the Amadey botnet and the Stealc infostealer by providing technical analysis, infrastructure tracking, and affiliate-level insights. Both are operated as malware as a service (MaaS). The operation – coordinated by Microsoft Digital Crimes Unit (DCU), BitSight, Lumen, and Mitsui Bussan Secure Directions (MBSD) – targeted all known network infrastructure used by Amadey and Stealc affiliates in order to cripple their cybercriminal operations. At the same time, Europol’s European Cybercrime Centre (EC3), together with European law enforcement partners, including Germany’s Federal Criminal Police Office, and both the Dutch and Danish National Police, were investigating Stealc as part of Operation Endgame, alongside IBM and Proofpoint.

The ESET telemetry detection rate indicates that Amadey was observed globally without a specific regional focus. The highest detection rates were observed in India, Turkey, Egypt, Mexico, and Spain. Stealc, too, was distributed globally without a specific regional focus. The highest detection rates were observed in the United States, Poland, and Italy.

ESET contributed to the disruption by providing technical analysis, statistical information, known command and control (C&C) servers, encryption keys, campaign and build identifiers, and other threat intelligence collected during our long-term tracking of both malware families.

“ESET has been tracking both Amadey botnet and Stealc infostealer for the past three years. For the disruption operation, we shared statistics covering Q4 2025 to H1 2026, along with technical indicators and configuration data extracted from processed malware samples,” explains ESET researcher Jakub Tomanek, who assisted in the Amadey and Stealc disruption efforts. “Our automated systems have been dissecting Amadey and Stealc samples and identifying the fields most relevant for large-scale tracking. These include C&C servers, build identifiers, encryption keys, URL paths, campaign identifiers, and other embedded values used by the malware families during communication with attacker-controlled infrastructure,” he adds.

Sharing technical analysis, statistical information, and threat intelligence, such as C&C server lists, affiliate identifiers, and encryption keys, enables law enforcement agencies to identify, prioritize, and act against infrastructure with a high degree of confidence.

Amadey is a modular malware loader. Its main purpose is to distribute additional malware to compromised systems, although it also offers modules for data exfiltration and remote access. Stealc, in contrast, is typical infostealer as a service. It targets credentials, cookies, cryptocurrency wallets, browser extensions, and files matching affiliate-defined patterns.

Both malware families are sold as services and advertised on darknet forums. In both ecosystems, affiliates receive a self-hosted administration panel that must be deployed on their own server infrastructure. This requires a certain level of technical skill from affiliates, and gives them direct control over victim data and payload distribution.

While distribution methods ultimately depend on each individual affiliate, ESET telemetry consistently showed that both malware families were delivered through a wide range of channels. The most common methods included fake software updates, cracked software installers, and third-party malware loaders.

Amadey used a pay-per-rebuild model. Affiliates purchased a license and then paid an additional fee each time they needed to generate a new build (for example, when rotating to a new C&C server). In other words, Amadey operators did not provide affiliates with a builder tool; instead, samples were compiled on request for each affiliate. It offers three modules for further data exfiltration and access: a clipboard monitoring module, a credential theft module, and a VNC-based remote access module. The service is priced at USD 600 in Bitcoin for a single license, with an additional USD 50 charged per rebuild.

Stealc took a more affiliate-friendly approach, offering unlimited build generation as part of the subscription. This lowered the operational cost of rotating C&C infrastructure and made it easier for affiliates to generate new samples as needed. It targets a broad range of data sources, including credentials stored by web browsers, email clients, FTP clients, gaming platforms, cryptocurrency wallet files, and browser extensions. Stealc is sold as a monthly subscription with the cheapest subscription for 1,000 USD per six months.

Trying to avoid impersonation scams, both operators explicitly instructed prospective affiliates on darknet forums to contact them only through official channels. Amadey directed buyers to private messages on the darknet forum where it is advertised, while Stealc used private messages on darknet forums or Telegram.

ESET will continue to monitor both families and track any attempts to rebuild operational infrastructure following the disruption.

For more details about Amadey and Stealc disruption, check out the ESET Research blogpost, “ESET takes part in global operation to disrupt Amadey and Stealc,” on WeLiveSecurity.com. Make sure to follow ESET Research on Twitter (today known as X), BlueSky, and Mastodon for the latest news from ESET Research.

Distribution of Amadey – detection heatmap (2025-present)

Distribution of Stealc – detection heatmap (2025-present)

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

ESET Research investigates Gentlemen ransomware gang and its defense-evasion tools

  • Gentlemen operators develop and maintain an EDR-killer suite provided directly to affiliates.
  • GentleKiller, an in-house framework, has at least eight variants abusing different vulnerable or malicious drivers.
  • Gentlemen operators apply a unified evasion strategy across tools to standardize impersonation and protection.
  • Third-party EDR killers (HexKiller, ThrottleBlood, and HavocKiller) are operationally integrated.
  • The gang’s victimology is globally distributed and notably not US focused.
BRATISLAVA, PRAGUEJune 18, 2026 — ESET researchers analyzed the robust EDR-killing toolset of the ransomware-as-a-service (RaaS) gang Gentlemen. Since the beginning of 2026, Gentlemen has emerged as one of the most active gangs in the ransomware ecosystem. The group distinguishes itself through a mature, operator-maintained set of endpoint detection and response (EDR) killers — tools for disrupting security software. Additionally, unlike most top-tier gangs, Gentlemen does not exhibit a strong US-centric victimology, instead targeting victims across Southeast Asia, South America, and Western Europe. The gang’s targeting includes some otherwise rarely targeted countries like Thailand, Brazil, and France. “While there have been multiple reports covering Gentlemen in recent months, they have not focused on a detailed analysis of the group’s EDR killers. Thanks to ESET’s continued incident-level visibility, we can provide a uniquely deep view into Gentlemen’s EDR-killer development practices. The internal data leak that Gentlemen suffered in May 2026 gave us more insight into the inner workings of the group,” says ESET researcher Jakub Souček, who tracks EDR killers. “The leak also allowed us to confirm the hypothesis we formed in February 2026: that Gentlemen operators actively develop and maintain a portfolio of EDR killers that they offer to affiliates, centered around their in-house framework, which we have named GentleKiller.” Additionally, the group incorporates third-party or leaked tools such as HexKiller, ThrottleBlood, and HavocKiller. These tools are standardized through a shared defense-evasion layer, impersonating predominantly security vendors by using fake version information and copied legitimate certificates and icons. Gentlemen also demonstrates an ability to unusually quickly operationalize newly disclosed Bring Your Own Vulnerable Driver proofs-of-concept, often within days of public release. Apart from the EDR killers, we also identified a credential stealer we named OxideHarvest; this tool was developed by one of Gentlemen’s affiliates. For context, Gentlemen emerged in late 2025 as a RaaS operation and quickly grew into one of the most active ransomware gangs observed in Q1 2026. The gang offers a generous 90% share to affiliates. Gentlemen utilizes double extortion — in addition to encrypting the victim data, the group also threatens to leak the data if the ransom is not paid. One of the things that sets Gentlemen apart is the gang’s willingness to offer more than just encryptors to affiliates — in particular, the gang also provides EDR killers. Gentlemen represents a different, and so far underreported, approach. Rather than relying on affiliates to source their own EDR killers, Gentlemen operators actively develop and maintain a portfolio of EDR killers for affiliates. While the victimology of large RaaS operations is often shaped more by affiliates’ choices than by operator-led strategy, one particular pattern still tends to emerge. Most major ransomware gangs show a strong and persistent focus on the United States, which frequently accounts for roughly half of all announced victims. Gentlemen stands out as a notable exception to this trend. Despite ranking among the five most active ransomware gangs in Q1 2026, its victimology does not exhibit a comparable US focus. Instead, Gentlemen affiliates consistently target victims across a broad and geographically diverse range of countries, with a significant number of victims coming from regions such as Southeast Asia, South America, and Western Europe. Gentlemen operators apply a specific set of defense evasion techniques to the gang’s various EDR killers. These techniques are applied to compiled samples rather than source code. This gives Gentlemen the option to also protect the EDR killers whose source code the gang does not possess. GentleKiller is by far the most prevalent EDR killer observed in the Gentlemen ecosystem. To date, ESET Research has discovered eight distinct variants, each impersonating a different legitimate product and abusing a different vulnerable or malicious driver. Despite these surface-level differences, ESET classifies all of these samples under the GentleKiller umbrella due to a high degree of shared internal characteristics. “From a defense perspective, understanding how GentleKiller works allows defenders to better design their defensive strategies and defend even against yet-to-be-developed additions to Gentlemen’s EDR-killing arsenal,” concludes Souček. For a more details about Gentlemen’s EDR killers, check out the ESET Research blog post “Killing me gently: Inside Gentlemen’s EDR killer framework” on WeLiveSecurity.com. Make sure to follow ESET Research on Twitter (today known as X), BlueSky, and Mastodon for the latest news from ESET Research.  

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

ESET 2025 Annual Report: Strong growth driven by technology leadership, independence, and trusted expertise

BRATISLAVAJune 18, 2026ESET, Europe’s largest cybersecurity vendor*, today announced its 2025 results, highlighting sustained growth, strong profitability, and continued progress in innovation and global expansion.

The ESET Group reported revenues of €733 million, representing a 6% year-over-year increase (8% at fixed exchange rates based on 2025). EBITDA reached €105 million, with business customers continuing to drive growth, while the consumer segment also exceeded expectations.

A clear identity: independence, technology, and trust

ESET’s performance is rooted in a distinctive approach to cybersecurity. As a privately owned European company, ESET combines independence, in-house technology development, and long-term expertise to deliver reliable protection in an increasingly complex threat landscape. These features further anchor its commitment to regulatory compliance and trustworthy technology development.

With its technology stack developed internally—from detection engines to AI and threat intelligence—ESET maintains full control over quality, innovation, and security. This model enables faster response to emerging threats and strengthens trust among customers, partners, and institutions.

“Rapid technological change and rising geopolitical tensions continued to reshape the cybersecurity landscape in 2025,” said Richard Marko, CEO of ESET. “These dynamics not only accelerated demand, but also reinforced the importance of trusted, independent cybersecurity providers.”

Growth driven by enterprise expansion

Growth was largely fueled by strong demand from business customers. ESET also continued to advance its custom offering through ESET PRIVATE solutions, delivering cybersecurity designed for large organizations, governments, critical infrastructure operators including air-gapping, embedded scanning, proactive client protection, industrial security, and services including both private Security Operations Center services and custom advisory. This offer combines advanced technologies with specialized services to address both complex operational and regulatory requirements.

Advancing cybersecurity through innovation and AI

In 2025, ESET further strengthened its product portfolio across both business and consumer segments, with a strong focus on AI-driven security, automation, and resilience. ESET applies AI with a focus on responsible and practical use cases, ensuring measurable security outcomes while maintaining privacy and compliance standards.

Key innovations included:

  • Introduction of ESET AI Advisor to ESET PROTECT XDR to simplify security operations, check analyst fatigue, and help address talent shortages
  • Enhanced ransomware resilience
  • Faster Managed Detection and Response
  • Expansion of integrations with major platforms such as Splunk and Wazuh
  • New threat intelligence feeds, covering ransomware, phishing, and botnets
  • For consumers: ransomware remediation, deep web inspection for advanced phishing detection, and router-level VPN for extended protection across home networks

European roots and global expansion

As a European company with over 35 years of experience, ESET continues to expand its global footprint while maintaining a strong regional identity.

In 2025, the company strengthened its presence in Northern Europe with the launch of ESET Norden, headquartered in Copenhagen. This expansion reflects a broader strategy to combine global reach with local expertise, enabling closer relationships with customers and partners.

The expansion was accompanied by the full global rollout of ESET Cyber Awareness Training as a service—a core component of improved cyber resilience in all markets.

Research-led expertise and global impact

ESET’s research capabilities remain a cornerstone of its success, providing visibility into the evolving threat landscape and supporting both product development and global cybersecurity efforts.

In 2025, ESET researchers contributed significant discoveries, including:

Beyond research, ESET actively collaborates with international organizations such as Europol and ENISA, supporting coordinated efforts to combat cybercrime and strengthen global resilience.

Recognition and performance validation

ESET’s technology and expertise were consistently recognized by independent testing organizations and industry analysts in 2025, including:

  • ESET HOME Security Essential won AV Comparatives’ 2024 Product of the Year
  • ESET HOME Security named Leader in the 2025 IDC MarketScape: Worldwide Consumer Digital Life Protection Report
  • ESET earned top performance in MITRE ATT&CK® evaluations with 100% protection rates
  • ESET won multiple AV-Comparatives awards for EPR, EDR, and Business Security
  • ESET won 2025 SC Award for Ransomware Remediation

These results reinforce ESET’s position as a trusted provider of high-quality cybersecurity solutions.

A resilient organization built on expertise

ESET’s long-term success is underpinned by its people. The company benefits from exceptional talent continuity, with a significant share of experts remaining for over a decade—an important advantage in an industry facing a global talent shortage.

Combined with its independence and in-house capabilities, this stability enables ESET to maintain consistent innovation and deliver long-term value.

Looking ahead

In 2025, ESET continued to strengthen its position as a technology-led cybersecurity company, combining AI, human expertise, and global threat intelligence to deliver resilient, future-ready solutions in an increasingly AI-driven world.

The company remains committed to protecting organizations and individuals worldwide while contributing to a more secure and trustworthy digital environment.

For more information, read the full

ESET 2025 Annual Report.

*According to Frost Radar™: Endpoint Security, 2025 (Frost & Sullivan), ESET is the largest global cybersecurity provider headquartered in Europe.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

ESET named a Market Leader in KuppingerCole Analysts’ 2026 Leadership Compass for Managed Detection & Response

BRATISLAVA — June 17, 2026 —ESET, a global leader in cybersecurity, is proud to be recognized as a Market Leader in the KuppingerCole Analysts’ 2026 Leadership Compass for Managed Detection & Response (MDR). The report evaluates leading vendors delivering advanced threat detection, investigation, and response services.

The report highlights ESET’s solid global coverage and growing MDR footprint, alongside strengths including “Fast automated response and containment, mature threat intelligence and research capability, and multilingual support across many regions.” KuppingerCole Analysts also note that “ESET concentrates innovation in ESET PROTECT MDR on usability and automation.”

“Organizations today require continuous monitoring and rapid, accurate response to evolving threats,” said Michal Jankech, Vice President, Enterprise & SMB/MSP at ESET. “We are proud to be recognized by KuppingerCole as a Market Leader in MDR. This acknowledgment reinforces our commitment to delivering affordable, high-quality MDR services that combine cutting-edge technology with human expertise, helping organizations stay resilient and detect and respond to cyber threats quickly and effectively.”

ESET’s MDR offering, ESET PROTECT MDR, combines 24/7 monitoring, threat hunting, rapid response, and advanced analytics within a unified platform. The service is designed to help organizations of all sizes strengthen resilience against evolving cyber threats while simplifying security operations.

The Leadership Compass evaluates vendors across multiple dimensions, including product capabilities, innovation, and market presence. It emphasizes the importance of delivering measurable security outcomes, such as reduced mean time, to detect and respond, while supporting customers with managed or co-managed security operations models

With cyber threats targeting endpoints, cloud environments, identities, and applications, organizations are increasingly turning to MDR providers for unified visibility and coordinated defense. The report highlights how MDR solutions have evolved to integrate capabilities such as XDR, SIEM, SOAR, and identity threat detection, enabling more efficient and proactive security operations.

With ongoing investment in automation, AI-assisted analysis, and threat intelligence, ESET continues to enhance its MDR capabilities and deliver measurable improvements in detection speed, response effectiveness, and overall security posture for customers worldwide.

Discover more about the ESET PROTECT MDR.

See what industry analysts, independent tests, and IT professionals are saying about ESET and its solutions.

 

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

ESET releases 2026 SMB Cyber Readiness Index showing growing confidence but also concerns about AI

BRATISLAVAJune 2, 2026 — ESET, a global leader in cybersecurity, today released its SMB Cyber Readiness Index 2026, based on a global survey of 4,400 SMB decision makers representing organizations with 25 to 1,000 endpoints across 13 countries in North America, Europe, and Asia. 

The index examines SMB cybersecurity sentiment across the most pressing challenges facing the segment, including the dual role of AI in driving new threats within the threat landscape and defending against them in business environments, overall cybersecurity posture, awareness training, and incident response.

The data shows that 45% of SMBs experienced a cybersecurity incident in the past 12 months, with 14% experiencing more than one incident. A majority of surveyed SMBs (61%) report  being seriously concerned about cyberattacks, while 75% consider cyberwarfare and global conflicts to be real cyber threats capable of impacting their business operations.

Among cyber threats, SMBs report the greatest concern with AI powered malware, even though such threats remain relatively rare at present.

Overall, the survey highlights several positive trends. Insurance and compliance requirements are driving stronger cybersecurity practices, and many SMBs have accepted that organizational size does not provide protection from cyber threats. As a result, businesses appear increasingly prepared to confront attacks.

  • 68% of SMBs are confident in their ability to prevent attacks, and 75% trust their cyber resilience when responding to incidents
  • 65% are satisfied with their cybersecurity budgets, with an additional 15% reporting they are “more than satisfied”
  • Only 11% operate with essential (minimal) cybersecurity protection
  • 87% view employee education as very important or critical to cyber resilience, with 67% conducting training more than once per year
  • Just 6% rely solely on basic awareness training programs, while an additional 2% provide no cybersecurity training at all
  • More than one third of SMBs investigated cyber incidents within two weeks

Despite these improvements, notable concerns remain. Many SMBs underestimate the seriousness of supply chain attacks and the risks associated with AI enabled tools, including so called shadow AI.

Read the full report.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

ESET has been named the only Challenger in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection

BRATISLAVAMay 29, 2026ESET, a global leader in cybersecurity, is proud to be recognized as a Challenger in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection1 for the third consecutive year for its ESET PROTECT offering. The company has been recognized in the report for 16 consecutive years and has been named a Challenger 7 times in the last 8 editions.

ESET believes strong execution and thorough vision drive its positioning, supported by competitive pricing and proven long-term performance. “Being named the only Challenger in the 2026 Magic Quadrant for Endpoint Protection is, in our view, a strong validation of our strategy and the value we deliver to customers worldwide,” said Pavol Balaj, Chief Business Officer at ESET. “We see this as recognition of our consistent innovation, strong performance, and dedication to making cybersecurity both effective and easy to manage. We will continue to invest in advancing our platform capabilities to help organizations stay ahead of evolving cyber threats.”

“Challengers offer mature endpoint protection products that effectively meet the needs of endpoint protection buyers. They also have strong market visibility, resulting in better Ability to Execute compared to Niche Players,” said Gartner. “Challengers are practical choices, especially for customers with established strategic relationships with them.”

ESET PROTECT is a comprehensive cybersecurity platform designed to meet the evolving needs of modern organizations. Built on decades of expertise and continuous innovation, it delivers a Prevention-First approach to security, integrating advanced technologies and security services into a single, scalable solution to meet the cyber resilience requirements of today.

Discover more about the ESET PROTECT Platform.

See what industry analysts, independent tests, and IT professionals are saying about ESET and its solutions.

Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner’s business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.

1Gartner, Magic Quadrant for Endpoint Protection, By Deepak Mishra, Evgeny Mirolyubov, Nikul Patel, 26 May 2026

Gartner and Magic Quadrant are trademarks of Gartner, Inc., and/or its affiliates.

 

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.