Cybercriminals have posed as the leading security company in Israel, launching Wiper attacks on local cyber security professionals after bypassing significant security measures. According to reports from cyber security firm Eset, the company’s systems have not been compromised.
Important findings
- Cybercriminals have posed as the Eset Advanced Threat Defense Team.
- Phishing emails were classified as malicious even though they passed authentication protocols.
- The fake email claimed that state-sponsored attackers tried to compromise the user’s device.
- Eset confirmed that the threat was blocked within 10 minutes.
- The malicious download is a Wiper that does not allow recovery.
Phishing attacks In detail
Security researcher Kevin Beaumont warned of phishing attempts posing as an Eset Advanced Threat Defense Team in Israel. These emails were deemed malicious by Google Workspace, even though they passed the authentication protocols designed to prevent spoofing. The fake October 8 email claimed that state-sponsored attackers attempted to compromise the user’s device after Eset’s threat intelligence division identified a geopolitically motivated threat group targeting technology equipment in the region.
Eset's reaction
Eset said in a statement on social media platform X that the company was affected by a security incident that affected a partner company in Israel last week. The initial investigation found that a limited malicious email campaign was blocked within 10 minutes. Eset noted that the company’s technology blocks the threat and customers are safe. The company works closely with its partner to investigate and continue to monitor the situation.
The Malicious Email
The malicious email invited users to click on download links to access Eset’s non-existent “Unleashed” program, a term the company has used in the past. Beaumont noted that the link led to a domain that allegedly belonged to Eset Israel. He noted on his blog that it was unclear why the download was offline and Eset had not informed people about what happened.
Techniques for evading detection
The malicious download uses a range of obvious techniques to evade detection. Beaumont noted that he could run the malware successfully only on a physical PC. He wrote: “There appears to be no way to recover. It is a wiper.”
Target group of attacks
Israel’s security and IT professionals have recently been targeted in several high-profile hacking attacks, including state-sponsored attacks from Iran targeting logistics, transportation and technology companies. These attacks highlight the ongoing threat of cybercrime and the need to continuously improve security measures.
Sources
- Hacker Poses as Israeli Security Vendor to Deliver Wiper, BankInfoSecurity.



