
Analyzing

Danabot: Analyzing a fallen empire
As announced by the US Department of Justice – the FBI and US DoD’s Defense Criminal Investigative Service (DCIS) have managed to disrupt the infrastructure of the notorious infostealer, Danabot. ESET is one of the many cybersecurity companies to participate in this long-term endeavor, becoming involved back in 2018. Our contribution included providing technical analyses…

Analyzing a lightning-zapped NAS
As introduced last October, the summer of 2024 was once again brutal from a lightning-induced electronics-culling standpoint at the Dipert household. I’ve already covered the hot tub control board that got zapped, as well as documenting the laundry list of other now-DOA devices: Once again, several multi-port Ethernet switches (non-coincidentally on the ends of those…

Bootkitty: Analyzing the first UEFI bootkit for Linux
UPDATE (December 2nd, 2024): The bootkit described in this report seems to be part of a project created by cybersecurity students participating in Korea’s Best of the Best (BoB) training program. As they informed us: “The primary aim of this project is to raise awareness within the security community about potential risks and to encourage…