HomeSecurityHackers distribute Wiper Malware to Israeli organizations

Hackers distribute Wiper Malware to Israeli organizations

Hackers attempted to distribute Wiper Malware to employees of organizations across Israel, pretending to represent cybersecurity company ESET via email.

Hackers distribute Wiper Malware to Israeli organizations

The attack that took place involved electronic “phishing” (phishing) that seemed to come from the “Eset Advanced Threat Defense Team”, warning about hackers backed by the state who are trying to compromise the target devices.

Read more: 2/3 of malware is linked to nation-states

A recipient posted the email on the ESET Security Forum on October 8, seeking confirmation of the possible phishing attempt. Security researcher Kevin Beaumont confirmed that the email passed DKIM and SPF checks and that the link came from the ESET Israel website. He also discovered that the ZIP file that targets were being asked to download was actually a Wiper disguised as ransomware, which was dubbed ESET Israel Wiper.

The malicious software requires a physical computer and time to explode. Since the beginning of the Gaza-Israel conflict in October 2023, Israeli companies have repeatedly become targets of Wiper Malware.

ESET confirms the incident

See also: Microsoft: Cyberattacks increase to 600 million

Beaumont's research into the matter this week led ESET Research to publicly disclose a " security" that occurred at a partner company in Israel.

“Based on our initial analysis, a limited malicious email campaign was blocked within ten minutes. ESET technology blocked the threat and our customers remain safe. ESET was not a victim of a breach and is working closely with its partner to further investigate, while we continue to monitor the situation,” said the ESET research team.

phishing email ESET

"ESET Israel operates through ComSecure Ltd under the ESET brand. Based on ESET, I assume ComSecure was the point of the breach. However, ESET appears in emails and downloads, as well as in partner infrastructure," Beaumont said.

Read also: New ClickFix attack: Fake Google Meet errors distribute malware

Currently, account compromise appears to be the most likely explanation for how the intruders managed to proceed with this process.

Source: helpnetsecurity

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS