ESET Research

ESET Research podcast

Research is at the heart of ESET and its technology and has been from the very beginning until today. In the ESET Research podcast, we want to give the world a chance to hear all the details directly from our world-class researchers.

Author

ESET Research

Category

Technology

Podcast website

esetresearch.podbean.com

Latest episode

Aug 5, 2025

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Threat Report H1 2025: ClickFix, disruptions, and ransomware deathmatch 05.08.2025

In H1 2025, a new social engineering technique called ClickFix started reshaping the threat landscape, quickly becoming the latest craze among all kinds of threat actors and rising to #2 in ESET telemetry. In stark contrast to this surge, law enforcement disrupted two major infostealer-as-a-service operations: Lumma Stealer and Danabot. And of course, no threat report would be complete without ran...

APT Activity Report Q1 2025: Malware sharing, data wiping and exploits 01.07.2025

In the latest ESET Research Podcast, Aryeh Goretsky and Rene Holt dive into key findings from the APT Activity Report. UnsolicitedBooker, a China-aligned group, showcased relentless persistence by repeatedly attempting to compromise the same organization for several years with its MarsSnake backdoor. Meanwhile, tool-sharing among China-aligned actors like Worok continues to blur attribution, with...

Threat Report H2 2024: Infostealers, novel vector for mobile, Nomani 28.02.2025

In H2 2024, the infostealer scene went through a shakeup leading to a reshaped top 10 with Formbook dethroning Agent Tesla, Lumma Stealer jumping the ranks by using a new tactic for its distribution, and both Redline Stealer and Meta Stealer losing ground after takedown. There’s also a novel attack vector that works for both Android and iOS devices, misusing technologies allowing mobile users to i...

Telekopye, again 20.12.2024

Neanderthals hunting Mammoths are back. Of course, we’re not talking about some Jurassic-Park-like technology that resurrected them in a remote region. No, this episode of ESET Research Podcast returns to the malicious operation of dozens of cybercriminal groups (Neanderthals) targeting inexperienced users (Mammoths) on online marketplaces, using a malicious Telegram bot known as Telekopye. Discus...

Gamaredon 13.11.2024

When describing state-backed threat actors, one would probably expect a super sophisticated, stealthy, group that can avoid all alarms and defenses with surgical precision. With Gamaredon, most of that goes out the window as this is one noisy, extremely active Russia-aligned group that does not care if defenders uncover its activities. However, it is also an actor that develops and improves its cy...

CosmicBeetle 24.10.2024

Some cybercriminals are sophisticated, cooperate with other attackers, and do everything to stay under the radar. Then there are threat actors like CosmicBeetle that lack the necessary skills set, yet still manage to compromise systems and even achieve “stealth” by using odd, impractical and overcomplicated techniques. If you want to know more about this crude and clumsy actor, listen to ESET seni...

EvilVideo 17.09.2024

Telegram, with nearly a billion monthly users, is a juicy target for cybercriminals, especially if they can exploit a zero-day vulnerability. ESET malware researcher Lukáš Štefanko ran into such an exploit – which ESET named EvilVideo – being sold online. In the discussion with our podcast host ESET Distinguished Researcher Aryeh Goretsky , Štefanko describes the findings of his analysis, includin...

HotPage 26.08.2024

In this episode, ESET Distinguished Researcher Aryeh Goretsky and his guest ESET Principal Threat Intelligence Researcher Robert Lipovsky detail recently discovered unusual adware called HotPage. This trojan caught attention of researchers by using a Microsoft-signed, yet vulnerable, kernel driver to inject and manipulate what victims see in their browsers. With its advanced technical means and ta...

APT Activity Report Q4 2023-Q1 2024: I-SOON, FishMonger, and MuddyWater 10.06.2024

The I-SOON data leak has allowed us to identify FishMonger, a group notorious for the cyberattacks against Hong Kong universities back in 2019, as I-SOON. This contractor also developed a platform for tracking gambling activity, linking the group to Operation ChattyGoblin. MustangPanda conducted a series of attacks on cargo shipping companies in Norway, Greece, and the Netherlands, even compromisi...

Threat Report H2 2023: ChatGPT, the MOVEit hack, and Pandora 31.01.2024

In 2023, ESET detected over 675,000 attempts to access malicious domains abusing the popularity of ChatGPT; some offer bring-your-own-key web apps that can steal OpenAI API keys. Apart from AI, in H2 the Cl0p ransomware gang exploited MOVEit software, causing a staggering $14 billion in damages. The IoT landscape faced the new Pandora botnet, compromising Android devices via malicious firmware upd...

Neanderthals, Mammoths and Telekopye 18.12.2023

In this episode, ESET researchers Radek Jizba and Jakub Souček talk about the dynamics within and between various Neanderthal groups, the techniques that this horde of scammers uses to find the best Mammoths, and especially about Neanderthals teaching each other how to wield the cybercriminal tool Telekopye effectively. While this might seem like an odd topic for a podcast about cybersecurity, qui...

Threat Report H1 2023: Sextortion, usury and brute-force 12.09.2023

In H1 2023, intrusion vectors were closing left and right. This forced many cybercriminals to search for alternative ways to compromise devices of their victims. While some of the attackers tried revisiting old routes such as brute-forcing MS SQL servers or distributing (AI-generated?) sextortion and text-based email messages, others kickstarted several Android apps running usury schemes. But ther...

MoustachedBouncer 10.08.2023

What do Disco, NightClub, backdoors, espionage, and internet service providers in Belarus all have in common? They all are tied to the same MoustachedBouncer. It sounds like a bad joke, but it sums up some of the key findings of ESET’s latest research focusing on a recently discovered APT group. Listen to ESET Director of Threat Research Jean-Ian Boutin explain the intricacies of this threat actor...

Finding the mythical BlackLotus bootkit 12.07.2023

Towards the end of 2022, an unknown threat actor boasted online that they created a new and powerful UEFI bootkit called BlackLotus. Its most distinctive feature? It could mysteriously bypass UEFI Secure Boot, a feature built into all modern computers to prevent them from running unauthorized software. What at first sounded like a myth turned into reality a few months later when ESET researchers d...

How I (could’ve) stolen your corporate secrets for $100 24.04.2023

What do you need to break into a corporate network? ESET’s latest research suggests that interest in secondhand computer hardware, a bit of time, and $100 is more than enough. In this episode, ESET Specialized Security Researcher Cameron Camp explains to host Aryeh Goretsky what secrets he found on secondhand routers bought online, what types of companies he would be able to penetrate with that in...

The year of wipers 30.03.2023

Since the Russian invasion on February 24th, 2022, Ukrainians have had to defend their data against an unprecedented number of data-wiping malware variants. While Russian threat actors seem like the obvious culprits, attributing these attacks to specific groups based on evidence is a different beast. In this podcast episode, ESET researchers Anton Cherepanov and Robert Lipovský explain to the host...

Threat Report T3 2022 28.02.2023

In the last four months of 2022, Russia-aligned APT groups unleashed several data-destroying malware variants on Ukraine. Android detections grew rapidly, while most of the crimeware scene continued on a downward spiral. In this ESET Research Podcast episode, Aryeh Goretsky and Ondrej Kubovic explore trends in several threat areas, including ransomware, exploits used for initial access, and more....

Tech in a digital vacuum 07.02.2023

Let’s say your network access gets shut off from the rest of the world due to a catastrophic event. Whether it is a natural disaster, an armed conflict, a decision of an authoritarian regime or your connection is just squeezed to a trickle by overzealous network restriction and power grid issues; how secure will you be and for how long? In this episode of ESET Research Podcast, Aryeh Goretsky and...

Threat Report T2 2022 08.12.2022

Looking at the ESET telemetry data from May through August 2022, it seems like the cybercriminal scene has taken taking its foot off the pedal in almost every possible area. But what is the reason for the drop? We expand on the brutal decline in RDP brute-force attacks; changes observed around ransomware messaging and targeting, but we also mention one malware category, where the decline did not a...

Live from RSAC 2022 20.07.2022

This is an ESET Research Podcast special, recorded at RSA Conference 2022, the world's largest conference devoted entirely to information security. It is also a double feature: first, ESET’s top machine-learning experts Juraj Jánošík and Filip Mazán discuss the use of artificial intelligence in the industry, and how it compares with the claims presented on the expo floor and in the talks they’ve s...

ESPecter 26.05.2022

As Unified Extensible Firmware Interface (UEFI) replaced legacy BIOS as the leading technology embedded into chips of modern computers and devices, it became vital to the security of the pre-OS environment and to the loading of the operating system. It’s no surprise that such a widespread technology represents a tempting target for threat actors in their search for ultimate persistence. Listen to...

Past and present cyberwar in Ukraine 03.03.2022

Long before the first Russian soldier set his foot on Ukrainian soil, the country has been a target of sophisticated digital operations, spying on its officials, and sabotaging its critical infrastructure and other sectors. It was even the initial ground for the most destructive cyberattack in history, known as NotPetya.  That trend continues also during the current crisis as ESET researchers unco...

IIS Malware 15.11.2021

The first ESET Research podcast episode dives deeper into the previously unexplored waters of malware targeting Internet Information Services (IIS), Microsoft's web server software for Windows with an extensible, modular architecture.  Threat actors misused IIS to intercept or modify network traffic already back in 2013 and in 2021 IIS backdoors are being deployed by both cybercriminals and APT gr...

Listen to the ESET Research podcast podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.