Malware & Threats

ESET Distributor’s Systems Abused to Deliver Wiper Malware 

ESET has launched an investigation after a product distributor in Israel sent out emails delivering wiper malware.

ESET has launched an investigation after a product distributor in Israel sent out emails delivering wiper malware.

ESET has launched an investigation after the systems of its official product distributor in Israel were abused to send out emails delivering wiper malware.

The targeted users received an email — signed by ESET’s Advanced Threat Defense (ATD) team — informing them about government-backed attackers trying to compromise their devices.

Researcher Kevin Beaumont has analyzed the attack and determined that the email passed DKIM and SPF checks, and it included a link to the ESET Israel store. In addition, ESET ATD is a real unit of the cybersecurity firm.   

However, the link pointed to a ZIP file containing some ESET DLLs and an executable named ‘setup.exe’ designed to deploy a wiper malware on the victim’s system.

While reports of the malicious emails impersonating ESET have been circulating since at least October 9, ESET apparently only issued a response late last week.

“We are aware of a security incident which affected our partner company in Israel last week,” ESET said. “Based on our initial investigation, a limited malicious email campaign was blocked within ten minutes. ESET technology is blocking the threat and our customers are secure. ESET was not compromised and is working closely with its partner to further investigate and we continue to monitor the situation.”

Advertisement. Scroll to continue reading.

A company called Comsecure appears to be the exclusive ESET product distributor in Israel and the targets appear to have been Israeli users. At least one organization in Israel was reportedly hit by the wiper

Beaumont has found some ties between this attack and two Iran-linked threat groups known for anti-Israel attacks: one named Handala, which according to the researcher has been defacing websites and allegedly exfiltrating data; and CyberToufan, which has been wiping systems.

SecurityWeek has reached out to ESET for further clarifications and will update this article if the company shares any additional information.

Related: Zscaler Confirms Only Isolated Test Server Was Hacked

Related: CrowdStrike Releases Root Cause Analysis of Falcon Sensor BSOD Crash

Related: ESET Patches Privilege Escalation Vulnerabilities in Windows, macOS Products

Related Content

Endpoint Security

Three high-severity Tenable Agent vulnerabilities could allow users to overwrite and delete files, or execute arbitrary code, with System privileges.

Vulnerabilities

Trend Micro patches critical-severity Apex Central and Endpoint Encryption PolicyServer flaws leading to remote code execution.

Fraud & Identity Theft

Security researchers flag two phishing campaigns abusing Firebase and Google Apps Script to host malware and fake login pages.

Vulnerabilities

The Radware Cloud WAF product vulnerabilities disclosed by CERT/CC were addressed two years ago.

Vulnerabilities

A sophisticated APT tracked as ToddyCat has exploited an ESET DLL search order hijacking vulnerability for malware delivery.

Malware & Threats

ESET says hundreds of freelance software developers have fallen victim to North Korean hackers posing as recruiters.

Malware & Threats

The 'Bootkitty' prototype UEFI bootkit contains an exploit for LogoFAIL and was created in a South Korea university program.

Supply Chain Security

ESET warns of a new reality: “UEFI bootkits are no longer confined to Windows systems alone.”

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version