Tracking Turla: ESET researchers discover attack on governmental websites in Armenia

BRATISLAVA, MONTREAL – ESET researchers have found a watering hole operation targeting several high-profile Armenian websites. It relies on a social engineering trick — a fake Adobe Flash update — as a lure to deliver two previously undocumented pieces of malware. In this specific operation, Turla has compromised at least four Armenian websites, including two belonging to the government. Thus, it is likely the targets include government officials and politicians.

Turla is an infamous cyberespionage group active for more than 10 years. Its main targets are government and military organizations. This recent operation bears similarities to the modus operandi of several of Turla’s watering hole campaigns in the past.

ESET Research has indications that these websites had been compromised since at least the beginning of 2019. We notified the Armenian national CERT and shared our analysis with them before publication.

“If the visitor is deemed interesting, the C&C server replies with a piece of JavaScript code that creates an IFrame. Data from ESET telemetry suggests that, for this campaign, only a very limited number of visitors were considered interesting by Turla’s operators,” comments ESET researcher Matthieu Faou on the victims of the attack.

“A fake Adobe Flash update pop-up window warning to the user is displayed in order to trick them into downloading a malicious Flash installer. The compromise attempt relies solely on this social engineering trick,” he adds.

Interestingly, in this latest campaign Turla utilizes a completely new backdoor dubbed PyFlash. ESET believes this is the first time the Turla developers have used the Python language in a backdoor. The command and control server sends backdoor commands that include downloading files, executing Windows commands, and launching or uninstalling malware. “The final payload has changed, probably in order to evade detection,” explains Faou.

For more details about the latest Turla campaign, read the blogpost Tracking Turla: New backdoor delivered via Armenian watering holes on WeLiveSecurity. Make sure to follow ESET research on Twitter for the latest news from ESET Research.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

ESET Research dissects Guildma: Most impactful and YouTube-abusing Latin American banking trojan

BRATISLAVA, PRAGUE – In the latest installment about Latin American banking trojans, ESET researchers take a deep look at the most impactful and advanced banking trojan we have seen in this series and in the region: Guildma. This malware is specifically targeting banking institutions and attempts to steal credentials for email accounts, e-shops and streaming services in Brazil. It affects at least 10 times as many victims as other Latin American banking trojans that ESET Research has analyzed. During its peak – a massive campaign in 2019 – ESET recorded up to 50,000 attacks per day. Guildma spreads exclusively via spam emails with malicious attachments.

In one of its latest versions, Guildma employs a new way of distributing command and control servers, abusing YouTube and Facebook profiles. However, the authors stopped using Facebook almost immediately and, at least at this time, are relying fully on YouTube.

“Guildma uses very innovative methods of execution and sophisticated attack techniques. The actual attack is orchestrated by its C&C server. This gives the authors greater flexibility to react to countermeasures implemented by the targeted banks,” explains Robert Šuman, the ESET researcher leading the team analyzing Guildma.

Guildma boasts a backdoor with multiple functionalities, including taking screenshots, capturing keystrokes, emulating keyboard and mouse, blocking shortcuts (such as disabling Alt + F4 to make it harder to get rid of fake windows it may display), downloading and executing files, and/or rebooting the machine. In addition, Guildma is very modular and currently consists of at least 10 modules. The malware uses tools already present on the machine and reuses its own techniques. “New techniques are added every once in a while, but for the most part, the developers seem to simply reuse techniques from older versions,” says Šuman.

In one of the earlier 2019 versions, Guildma added the capability to target institutions (mainly banks) outside of Brazil. Despite that, over the past 14 months, ESET has not observed any international campaigns outside Brazil. The attackers went as far as to block any downloads from non-Brazilian IP addresses.

Guildma campaigns were ramping up slowly until a massive campaign in August 2019, when ESET Research recorded up to 50,000 samples per day. This campaign went on for almost two months and accounted for more than double the amount of detections seen in the 10 months prior.

First-stage Guildma detections since July 2019

First-stage Guildma detections since July 2019

The trojan has seemingly gone through many versions during its development, but there was usually very little development between versions due to its clunky architecture.

Distribution chain of Guildma in the latest version analyzed by ESET (150)

Distribution chain of Guildma in the latest version analyzed by ESET (150)

Guildma shares several prevailing characteristics of Latin American banking trojans. For more technical details, read the blog post Guildma: The devil drives electric on WeLiveSecurity. Make sure to follow ESET Research on Twitter for the latest news from ESET Research.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

ESET discovers Kr00K: Communications of a billion+ devices were at risk

BRATISLAVA, SAN FRANCISCO – February 26, 2020 – ESET researchers have discovered Kr00k (CVE-2019-15126), a previously unknown vulnerability in Wi-Fi chips used in many client devices, Wi-Fi access points and routers.

Kr00k is a vulnerability that causes the network communication of an affected device to be encrypted with an all-zero encryption key. In a successful attack, this allows an adversary to decrypt wireless network packets.

The discovery of Kr00k follows previous ESET research into the Amazon Echo being vulnerable to KRACKs (Key Reinstallation Attacks). Kr00k is related to KRACK, but is also fundamentally different. During the investigation into KRACK, ESET researchers identified Kr00k as one of the causes behind the “reinstallation” of an all-zero encryption key observed in tests for KRACK attacks. Subsequent to our research, most major device manufacturers have released patches.

Kr00k is particularly dangerous because it has affected over a billion Wi-Fi enabled devices – a conservative estimate.

ESET will publicly present its research into this vulnerability for the first time on February 26 at the RSA Conference 2020.

Kr00k affects all devices with Broadcom and Cypress Wi-Fi chips that remain unpatched. These are the most common Wi-Fi chips used in today’s client devices. Wi-Fi access points and routers are also affected by the vulnerability, making even environments with patched client devices vulnerable. ESET tested and confirmed that among the vulnerable devices were client devices by Amazon (Echo, Kindle), Apple (iPhone, iPad, MacBook), Google (Nexus), Samsung (Galaxy), Raspberry (Pi 3) and Xiaomi (Redmi), as well as access points by Asus and Huawei.

ESET responsibly disclosed the vulnerability to the chip manufacturers Broadcom and Cypress, who subsequently released patches. We also worked with the Industry Consortium for Advancement of Security on the Internet (ICASI) to ensure that all possibly affected parties – including affected device manufacturers using the vulnerable chips, as well as other possibly affected chip manufacturers – were aware of Kr00k. According to our information, devices by major manufacturers have now been patched.

“Kr00k manifests itself after Wi-Fi disassociations – which can happen naturally, for example due to a weak Wi-Fi signal, or may be manually triggered by an attacker. If an attack is successful, several kilobytes of potentially sensitive information can be exposed,” explains Miloš Čermák, the lead ESET researcher into the Kr00k vulnerability. “By repeatedly triggering disassociations, the attacker can capture a number of network packets with potentially sensitive data,” he adds.

Figure: An active attacker can trigger disassociations to capture and decrypt data.

“To protect yourself, as a user, make sure you have updated all your Wi-Fi capable devices, including phones, tablets, laptops, IoT smart devices, and Wi-Fi access points and routers, to the latest firmware version,” advises Robert Lipovský, an ESET researcher working with the Kr00k vulnerability research team. “Of great concern is that not only client devices, but also Wi-Fi access points and routers that have been affected by Kr00k. This greatly increases the attack surface, as an adversary can decrypt data that was transmitted by a vulnerable access point, which is often beyond your control, to your device, which doesn’t have to be vulnerable.”

For more technical details about Kr00k, read the white paper Kr00k – CVE-2019-15126 Serious vulnerability deep inside your Wi-Fi encryption and blogpost on WeLiveSecurity. Make sure to check out Kr00k in depth on its dedicated landing page and follow ESET Research on Twitter for the latest news from ESET Research.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

ESET Deep Behavioral Inspection enables deeper monitoring of unknown & suspicious processes

BRATISLAVA, February 25, 2020 – Today, ESET released a white paper focusing on ESET Deep Behavioral Inspection (DBI) – the latest enhancement of the system specifically designed to perform advanced behavioral analysis and detection known as ESET Host-based Intrusion Prevention System (HIPS).

“Cyber criminals will go to great lengths to achieve their ultimate goal –stealing information, computing resources or money.  Apart  from social  engineering  techniques, they employ  technical tricks such  as obfuscation, encryption, and process injection, designed to help their code avoid detection by built-in as well as third-party security solutions,”explains ESET Security Awareness Specialist Ondrej Kubovič. “ESET DBI, together with  other  HIPS modules,represents an  important  protective layer that can detect and report these tricks and thus block malicious activity on the targeted system,”he adds.

Deep Behavioral Inspection,as one of the latest technological additions to the ESET HIPS framework,can be  found in  the  latest  edition of ESET products for both home and  business users. DBI includes new detection heuristics and enables an even   deeper user-mode monitoring of unknown,suspicious processes. This is accomplished via hooks created by DBI within unknown, potentially harmful processes and monitoring of their activity and requests to the operating system. If malicious behavior is detected, DBI mitigates the activity and informs the user. If the process is suspicious, but does not show clear signs of malicious behavior, HIPS can also use the data gathered by  DBI to run further analysis via its other modules.

ESET Host-based Intrusion Prevention System is a detection technology specifically  created to monitor and scan behavioral events from running processes, files and  registry keys,looking for  suspicious activity. It focuses on a variety of malicious behaviors used either to wreak havoc on a victim’s device or to avoid detection by security solutions. The list of HIPS modules includes:

  • Advanced Memory Scanner (AMS)
  • Exploit Blocker (EB)
  • Ransomware Shield(RS)
  • Deep Behavioral Inspection (DBI)

(Image below: Schematic of how DBI fits into the existing HIPS process monitoring layer)

For more details on the inner workings of ESET HIPS read the latest white paper, “ESET Deep Behavioral Inspection” on https://www.welivesecurity.com/. Make  sure  to follow ESET research on Twitter for the latest news from ESET Research.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

Windows 7壽命終止,您要如何避免資安風險

正如諺語所說,“所有美好的事物終將結束” , Windows 7也是如此。

Windows 7於2009年推出,最重要任務是取代為人詬病的Windows Vista,而穩定的Windows 7深獲用戶喜愛,為廣受歡迎的作業系統(OS)且售出了共6.3億多個使用授權。在推出10年後,微軟於美國時間2020年1月14 日正式終止支援Windows 7,不再提供安全性更新,為Windows 7時代劃下句點。

但是,截至2019年12月,在所有桌機及筆電上跑的作業系統版本中,Windows 7仍以26.6%位居第二位,而這意謂著全球有數百萬台PC,從2020年起將暴露於惡意程式感染或駭客攻擊的風險中。由於微軟不會再提供任何技術支援、軟體更新、安全性更新或修正程式,故電腦將變得更容易受到各種形式的惡意軟體和其他威脅的攻擊,或被駭客發現和利用作業系統中的安全漏洞進而入侵電腦。儘管用戶仍可以繼續使用執行Windows 7的電腦,但是當您選擇這樣做時,所有的後果將得自行負責。

ESET資安專家建議用戶最好盡速升級系統,千萬不要輕忽修補或更新系統的重要性–它可能會使您免受如WannaCryptor(又名WannaCry)之類的威脅的侵害,還有選擇並安裝專業且值得信賴的資安產品,保護您的網路安全。

*****若有任何資安需求,歡迎洽詢ESET資安專業團隊,服務電話:(02)7722-6899,或上官網查詢:https://www.eset.tw/


原文出處:https://www.welivesecurity.com/2020/01/14/windows7-end-life-time-move-on/

 

MENDEL 3.5 NOW AVAILABLE

GREYCORTEX is happy to announce that we have released the latest version of our MENDEL network traffic analysis solution. Version 3.5.0 brings important features, improvements, and bug fixes. Among major features, you can find Central Event Management, which enables users to create multi-level appliance structure for exhaustive network overview, or data export into CSV format for more in-depth analysis or enriching other big data tools.

This version contains a number of major changes in the system. To ensure a smooth upgrade process and to provide support to all our partners and customers, we will be introducing this release gradually over the next 14 days.

NEW FEATURES

Data Export into CSV format

MENDEL users can now export data regarding hosts, network, flows, and even incidents into csv. format for further processing and creation of new network data visualizations.

Central Event Management

For customers or partners with larger deployments, MENDEL offers the ability to connect appliances using a multi-level structure; consisting of sensors, collectors, and a Central Event Management console. This provides a more comprehensive overview of the full network.

Validating SSL and TLS certificates

For encrypted communication, MENDEL detects expired or invalid SSL and TLS certificates and alerts the user.

ARP protocol parser

We have added the ability to parse the communications using the Address Resolution Protocol for even better processing of non-IP data.

ENHANCEMENTS

Operating system identification using L7 data

MENDEL is able to detect the operating system of the host more precisely, using an advanced data model based on Samba, DHCP, HTTP, SSH, and L3/L4 parameters, among others. Data is also presented within a new dashboard showing the top operating systems in the network for the chosen period.

Filtering data by additional values

We added the option to filter by additional variables, including operating system, interface, application, and port range.

New predefined dashboards

We have provided two new dashboards: Risks and Statistics; for our users to quickly and easily review the situation in their network.

Additional Enhancements:

  • Upgrade of system components
  • Printer tagging
  • Browser protocol parser
  • Sensor-Collector management
  • Enhanced TLS 1.3 protocol parser
  • Extended host/subnet lease time
  • Configurable display level
  • Decoding QoS/DSCP
  • System improvements
  • Network capture module improvements
  • GUI improvements
  • Localization improvements 

SCADA

MMS protocol processing

For the visualization of MMS protocol data and further analysis, we added MMS protocol processing.

Asset resources management

We added the ability to name, manage, and add new devices in the network.

DLMS/COSEM protocol parser

We added parsing for DLMS/COSEM, one of the most widely accepted international standards for utility meter data exchange.

OMRON FINS protocol parser

We added parsing for the OMRON FINS protocol, which can be used by a PLC program to transfer data and perform other services with a remote PLC connected on an ethernet network.

FIXED ISSUES

In general, our development team focused on improving user experience and reporting. As well as more improvements to user experience, system stability, and performance.

Please note that upgrading to version 3.5.0 will replace the system kernel and reboot the appliance.

We recommend having direct or remote access to the appliance in order to be able to restart it if necessary.

About Version 2 Limited

Version 2 Limited is one of the most dynamic IT companies in Asia. The company develops and distributes IT products for Internet and IP-based networks, including communication systems, Internet software, security, network, and media products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 Limited offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About GREYCORTEX

Founded in 2016 in Brno, Czech Republic, GREYCORTEX helps organizations make their IT and OT operations secure and reliable with uses advanced artificial intelligence, machine learning, and data mining methods which detect advanced threats to security and risks to reliability that other solutions miss.

為防疫加油!訊連科技「U 校園防疫專案」 免費提供各大專院校使用遠距教學及視訊會議系統

【2020年2月17日,台北訊】因應防疫需求,各大專院校對於無法進教室上課的學生,可以線上直播或視訊會議方式授課或進行討論。多媒體領導廠商訊連科技(5203.TW)宣布,免費提供各大專院校「U會議」與「U簡報」。可於即日起至U官方網站免費申請。

因應新型冠狀病毒(COVID-19)疫情延燒,各大專院校已將開學日延後至3月初後,但仍有許多國際學生或居家隔離的學生無法如期回到校園上課,因此各校教務單位勢必需要擬定遠距教學之配套方案。為支援國內高教此緊急需求,訊連即刻推出「U 校園防疫專案」,免費提供各大專院校「U簡報」與「U會議」,每校各50套、市值100萬台幣的線上直播及視訊會議系統,於防疫期間,協助各大專院校快速打造遠距教學平台。即日起至2020年7月31日止,可於訊連科技U整合通訊官方網站進行申請。

訊連科技黃肇雄執行長表示:「防疫是台灣各界齊心努力的課題,訊連很榮幸能為防疫盡一份心力,協助全台各大專院校在防疫時期,使用遠距教學及視訊會議來解決學生無法返校就學的難題。」

訊連科技「U 簡報」可提供高達500人同時觀看的線上直播。教師端可透過個人電腦,整合簡報、視訊、語音及白板進行課程直播。學生端可使用個人電腦及行動裝置觀看課程直播,並於課程中使用聊天室進行互動。訊連科技「U 會議」的線上會議室可提供高達100人參與會議,可用來進行小組討論,或透過螢幕分享方式進行線上簡報。

校園防疫申請專案
即日起至2020年7月31日止,至訊連U整合通訊官方網站U校園防疫專案,填寫貴校相關資訊與聯絡方式。申請後三個工作天內,訊連審核後以電子郵件通知。

本專案僅供台灣各大專院校申請,以學校為申請單位,每校可申請付費版「U會議」與「U簡報」各50套(市值100萬元)。授權期限為審核通過日起至2020年7月31日止。

關於訊連科技U整合通訊服務 訊連科技「U 簡報」、「U 會議」及「U 通訊」整合了遠距直播、視訊會議及即時通訊等功能,為企業及教育機構打造即時、跨國界、跨平台、行動優先、高影音品質之新世代視訊溝通服務。更多資訊,請洽:https://u.cyberlink.com/

關於Version 2 Limited

Version 2 Limited是亞洲最有活力的IT公司之一,公司發展及代理各種不同的互聯網、資訊科技、多媒體產品,其中包括通訊系統、安全、網絡、多媒體及消費市場產品。透過公司龐大的網絡、銷售點、分銷商及合作夥伴,Version 2 Limited 提供廣被市場讚賞的產品及服務。Version 2 Limited 的銷售網絡包括中國大陸、香港、澳門、臺灣、新加坡等地區,客戶來自各行各業,包括全球1000大跨國企業、上市公司、公用機構、政府部門、無數成功的中小企及來自亞洲各城市的消費市場客戶。

關於CyberLink

訊連科技創立於1996年,擁有頂尖視訊與音訊技術的影音軟體公司,專精於數位影音軟體及多媒體串流應用解決方案產品研發,並以「抓準技術板塊,擴大全球行銷布局」的策略,深根台灣、佈局全球,展現亮麗的成績。訊連科技以先進的技術提供完美的高解析影音播放效果、以尖端的科技提供完整的高解析度擷取、編輯、製片及燒錄功能且完整支援各種高解析度影片及音訊格式。產品包括:「威力導演」、「PowerDVD」、「威力製片」、「威力酷燒」等。

ESET Named a Strong Performer in Endpoint Security Suites 2019 Report by Independent Research Firm

BRATISLAVA, February 7, 2020, ESET – a global leader in information security software – has been recognized as a “strong performer” in The Forrester Wave™: Endpoint Security Suites Q3 2019 report. The prestigious report assessed the top 15 security suites in the market, including their ability to prevent, detect, and remediate endpoint threats, with ESET emerging as a strong performer.

In reviewing the overall market, the report stated that “endpoint security suite buyers prioritize automatic threat protection.” The report highlights that endpoint security suites are now increasingly “tasked with protecting against targeted-style threats” and that therefore, customers should look for providers that “tightly integrate threat prevention, detection, and response,” “extend visibility and control over a broad endpoint ecosystem,” and “offer flexibility in a variety of environments and risk tolerances.”

The report recognized ESET’s full portfolio of enterprise offerings since ESET has widened our focus to cater to increased enterprise market demands. ESET received the highest score possible in the corporate vision and focus criterion and was noted for developing several capabilities aimed at enterprise buyers, such as Endpoint Detection and Response (EDR), managed detection and response, threat intelligence services, and vulnerability management. ESET also had the highest score possible in the OS support criterion, which is defined as having broad operating systems support relative to others in the evaluation. 

To assess the state of the endpoint security suites market and see how the vendors stack up against each other, Forrester evaluated the strengths and weaknesses of the top vendors. After examining past research, user need assessments, and vendor and expert interviews, Forrester developed a comprehensive set of 25 criteria, which they group into three categories:

•    Current offering. Each vendor’s position on the vertical axis of the Forrester Wave™ graphic indicates the strength of its current offering. Key criteria for this evaluation include malware and exploit prevention, behavioral detection, and product performance, which Forrester validated using customer feedback and demos/briefings.

•    Strategy. Placement on the horizontal axis indicates the strength of the vendors’ strategies. Here, Forrester evaluated corporate vision and focus, security community, and product road map.

•    Market presence. Represented by the size of the markers on the graphic, Forrester’s market presence scores reflect each vendor’s enterprise customer base and licensing partner ecosystem.

The Forrester Wave™ report details that security professionals want an endpoint security suite that can protect the increasing number of devices brought into the workplace and handle the increasing complexity of the security landscape. For vendors, improved behavioral protection combined with risk-based security policies will lead the way in cybersecurity solutions. We believe this is reflected in ESET’s success in receiving the highest score possible in the security community involvement, OS support, and corporate vision and focus criteria.

The report states in ESET’s profile that “ESET is perfect for buyers who value a simple, straightforward UI with more advanced functions easily invoked when required,” with ESET customers continually rating the company exceptionally well for its low impact to user experience.

Juraj Malcho, ESET’s chief technology officer, commented, “We believe the recognition of ESET as a strong performer in Forrester’s latest Endpoint Security Suite Wave is a testament to our commitment to delivering premium security to the enterprise sector. The enterprise threat landscape is constantly evolving in sophistication, and it is central to our mission that our users are protected against complex threats with the highest standard of security solutions. In our increasingly digitized world, it is imperative that enterprises and their data are safe and secure.”


About Version 2 Limited
 Version 2 Limited is one of the most dynamic IT companies in Asia. The company develops and distributes IT products for Internet and IP-based networks, including communication systems, Internet software, security, network, and media products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 Limited offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint and mobile security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give consumers and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defences in realtime to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D centres worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003. For more information, visit https://www.eset.hk/ or follow us on Facebook.

AV-Comparatives recognizes ESET consumer products with gold medals in cybersecurity awards

BRATISLAVA, February 6, 2020 – ESET, a global leader in cybersecurity, has been recognized with gold and bronze awards in the AV-Comparatives Summary Report 2019. AV-Comparatives, a leading independent testing organization, uses one of the largest sample collections worldwide to create a real-world environment for highly accurate testing. Their Summary Report 2019 provides commentary on the consumer antivirus products tested over the course of the year, and highlights the high-scoring products from the different tests that took place over the 12 months.

The report looked at consumer Windows products from 16 different vendors, with excellent results for ESET, taking awards in three categories: Overall Performance (Low System Impact), Enhanced Real-World Test (Advanced Threat Protection), and the False Positive Test.

Overall Performance (Low System Impact)

ESET was awarded a gold medal in the Low System Impact category, which assesses each product’s impact on system speed and performance. ESET has consistently achieved great results in this category, improving on its silver award in the same category in 2018.

Enhanced Real-World Test (Advanced Threat Protection)

ESET took a gold medal in the Advanced Threat Protection category, which is a new category for 2019 and 2020. This test addresses a program’s ability to protect against advanced targeted and fileless attacks. ESET was also one of only two vendors to block all 15 targeted attacks in the testing process.

False Positive Test

ESET was awarded a bronze medal in the False Positive Test. As the report notes, false positives can cause as much trouble as a real infection, and avoiding them is a crucial element of any antivirus product. AV-Comparatives carried out extensive false-positive testing as part of the Malware protection tests and the Real-World Protection Test.

Commenting on the results, Jiří Kropáč, head of threat detection labs at ESET, said: “ESET’s recognition from AV-Comparatives is testament to our dedication to our customers and our promise to always deliver the best in IT security solutions. Ensuring consumers are equipped with cutting-edge protection against the latest threats is extremely important to us. We are honored to receive these awards and to be recognized as a key player in making technology safer for everyone.”

Read AV-Comparative’s Summary Report 2019 for more information.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.