Salta al contenuto principale


Regarding this - does anybody know if this is a legit ESET email? @ESETresearch

I'm trying to establish if the ESET download is the cause or a symptom of existing access

cyberplace.social/@ericshmeric…

Questa voce è stata modificata (7 mesi fa)
in reply to Kevin Beaumont

Okay... I've obtained the file and the email.

The emails passed SPF and DKIM for ESET Israeli's email, and are signed as Eset Advanced Threat Defense Team.

The file has been taken offline.

in reply to Kevin Beaumont

Okay... I think ESET Israel got compromised a few weeks ago and they haven't told people.
in reply to Kevin Beaumont

Okay, ESET Israel definitely got compromised, this thing is fake ransomware that talks to an Israeli news org server for whatever reason.