ESET WeLiveSecurity
eset · B · active
https://www.welivesecurity.com/en/
ESET research blog; particularly strong on European APT activity. RSS at https://www.welivesecurity.com/en/rss/feed/ mirrors the listing. 2026-05-08 audit: 5 dated posts latest 2026-05-07 on CallPhantom, ScarCruft. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → webfetch https://www.welivesecurity.com/en/ (listing) then webfetch per-article URL; RSS mirror at https://www.welivesecurity.com/en/rss/feed/. AVOID: No issues; WebFetch works on listing and detail. No bridge needed.. | 2026-07-05 admiralty audit: B, vendor research lab, original telemetry-driven research (esp. EU APTs); live, keep active.
Cited in 13 entries
Citation cadence
Citation days per ISO week (19 weeks of coverage span, total 13).
- FamousSparrow retires SparrowDoor for SparroWocky, a modular backdoor with BOF-loading and call-stack spoofing, deployed almost exclusively against Latin American governments2026-09-18
- TA458 / Operation RoundPress: a running supply of half-click webmail zero-days adds a fresh SOGo flaw (CVE-2026-8496)2026-07-25
- CVE-2026-8863, CVE-2026-10797, forgotten pre-0.9 UEFI shims bypass Secure Boot via a signature-length validation mismatch2026-07-14
- ESET Threat Report H1 2026: first Android malware using generative AI at runtime, ClickFix detections more than double, record QR-phishing, 100+ EDR-killers2026-07-09
- ESET's 2025 Gamaredon paper: exfil and C2 moved wholesale onto trusted cloud services (ANNUAL REPORT)2026-06-26
- Operation Endgame dismantles the Amadey and StealC malware-as-a-service backbone2026-06-25
- ESET: the Gentlemen RaaS gang centrally builds and maintains its affiliates' EDR-killer framework2026-06-19
- FishMonger (I-SOON) ports its SprySOCKS backdoor to Windows with a kernel-driver rootkit2026-06-17
- ESET: OceanLotus (APT32) compromises a stock-trading platform's update server, selective SPECTRALVIPER delivery, no integrity checks to defeat2026-06-12
- ESET APT Activity Report Q4 2025–Q1 2026: Sandworm strikes NATO energy, Lazarus targets EU drone sector, UNC5221 pivots to Ivanti SPAWN toolset2026-05-30
- WatchGuard documents Grandoreiro's Delphi-DLL-side-loading + WebSocket/STUN C2 against Portuguese & Spanish banks; ESET maps parallel Android BTMOB MaaS2026-05-29
- Webworm (China-aligned) shifts to EU government targets, EchoCreep (Discord C2) and GraphWorm (Microsoft Graph / OneDrive C2) backdoors documented by ESET, with Belgian, Italian, Serbian, Polish and Spanish governmental victims2026-05-21
- FrostyNeighbor / Ghostwriter (UNC1151, Belarus state-aligned): ESET documents March–May 2026 campaign targeting Polish, Lithuanian, and Ukrainian government and industrial sectors2026-05-15