Skip to content

ESET Launches Ransomware Remediation and AI Advisor Updates at ESET World 2025

  • ESET adds Ransomware Remediation to the ESET PROTECT Platform – offering next-gen ransomware rollback enhanced with remediation features. Working in tandem with ESET’s proprietary Ransomware Shield, Ransomware Remediation enables comprehensive rollback through automated file restoration from secure backups, limiting threat actor attempts to raise remediation costs.
  • ESET Cloud Office Security module updated with anti-spoofing and homoglyph protection, profoundly improving email security.
  • ESET has also expanded the availability of AI Advisor to its EDR/XDR customers, including those with ESET PROTECT Enterprise, ESET PROTECT Elite, and ESET PROTECT MDR subscriptions – while making performance updates.

LAS VEGAS, Nev.March 25, 2025 — ESET, a global leader in cybersecurity solutions, today released new updates for the ESET PROTECT Platform, including Ransomware Remediation, a new way to prevent ransomware encryption from causing long-term business disruption, as well as new functionalities for ESET Cloud Office Security and the ESET AI Advisor. These new cybersecurity features were launched at ESET World 2025, taking place in Las Vegas from March 24 to 26, 2025, at the ARIA Resort & Casino.

As ransomware attacks increase in sophistication, threat actors seek to undermine nearly all areas of business security and stability. One well-known and -used attack is encryption, which prevents you from accessing your device and the data stored on it. Causing costly process disruption, and ultimately forcing firms to pay to decrypt their systems, threat actors often target system backups, such as Volume Shadow Copy, by immediately deleting or corrupting them. This makes recovery nearly impossible and drives up remediation costs.

Building on ESET LiveSense, ESET’s next-gen Ransomware Remediation feature works in concert with Ransomware Shield to immediately create backups until the system confirms whether the suspicious activity is malicious or benign. If malicious, Ransomware Shield will kill the process and roll back the files from the newly created secure backups. If benign, the backups created can be discarded. Unlike other solutions, Ransomware Remediation has its own protected storage section on the drive, where files cannot be modified, corrupted, or deleted by the attacker. This differentiator actively solves one of the most common failings of regular backups during a ransomware attack. As a free addition for customers signed up for the ESET PROTECT Advanced tier and above, Ransomware Remediation is available for Windows-based systems.

“ESET has a history of innovation in mitigating ransomware, both in the context of our endpoint security platform, our service offerings such as ESET MDR, and our part in the ‘No More Ransom’ initiative, which partners with law enforcement and IT Security companies to disrupt cybercriminal businesses with ransomware connections,” said Michal Jankech, Vice President, Enterprise & SMB/MSP at ESET. “ESET’s Ransomware Remediation delivers comprehensive Ransomware defense, from encryption, theft and data holding. Easy to use, ESET’s Ransomware Remediation offers businesses peace of mind as we help them in the fight against ransomware.”

Email Security and AI Advisor Updates

ESET has added anti-spoofing and homoglyph protection to its ESET Cloud Office Security module, preventing attackers from pretending to be trusted sources while also identifying their efforts to disguise malicious domains or URLs through letter substitution from other alphabets. Moreover, ESET Cloud Office Security now also has an email clawback feature, enabling swift recall and quarantine of any delivered emails deemed suspicious. New dashboards are visually enhanced and include fully customizable tabs and components that fit a user’s specific needs.

ESET has also expanded the availability of AI Advisor to its EDR/XDR customers, including those with ESET PROTECT Enterprise, ESET PROTECT Elite, and ESET PROTECT MDR subscriptions – while making performance updates. By investing in AI, businesses are able to access SOC-level advisory, enabling enhanced security analyst workflows. Unlike other vendor offerings and typical generative AI assistants that focus on soft features like administration or device management, ESET AI Advisor seamlessly integrates into the day-to-day operations of security analysts. This is a gamechanger for companies with limited IT resources that want to utilize the advantages of advanced XDR solutions and threat intelligence feeds.

For more information about the ESET LiveSense technologies used by the ESET PROTECT Platform, please visit here.

For more information about the ESET PROTECT Platform, please visit our dedicated webpage.

For more information about ESET Cloud Office Security and the ESET AI Advisor, please visit our webpage and our AI blog.

To discover how ESET has been handling ransomware, please read ESET MDR success stories and ESET Inspect’s preventive power.

 

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

How to turn back time on ransomware

Security solutions including ransomware remediation bolster resiliency and business continuity.

Ransomware is a critical threat that can instantly encrypt and lock users out of business computers, halting essential work processes. According to IBM’s Cost of a Data Breach Report 2024, the average cost of a ransomware attack is a staggering $4.91 million, with expenses escalating if law enforcement is involved. Recovery can span days, months, or even years, depending on the threat actor’s persistence and the security team’s preparedness. For companies that face double extortion ransomware – where cybercriminals encrypt sensitive user data and also threaten to publish it on the dark web, sell it to the highest bidder, or restrict access if the ransom is unpaid – the timeline for recovery can be even longer.

This makes recovery and related expenditures not just problematic, but potentially devastating, often leaving businesses at the mercy of cybercriminals even after paying the initial ransom.

A critical landscape for businesses of all sizes

The rapidly evolving nature of ransomware, including the involvement of nation-state actors, has created an increasingly hostile threat landscape for small and medium-sized businesses (SMBs), enterprises, and state infrastructure. Ransomware now accounts for 23% of all breaches, with SMBs particularly vulnerable due to limited cybersecurity budgets. In the Asia-Pacific region, 1 in 4 attacks against SMBs were ransomware-related, according to ESET. The urgency to bolster defenses has never been greater, as the frequency and sophistication of these attacks continue to rise.

What is ESET Ransomware Remediation?

Minimizing business impact in the event of a ransomware attack is paramount. Thus, ESET Ransomware Remediation (RR) combines prevention and remediation into one, providing a comprehensive multistage approach to combating encryption.

It all starts with the ESET Ransomware Shield (RS), which is triggered by suspicious actions. Like other behavioral detection systems, such as the ESET Host-based Intrusion Prevention System, it works in concert with ESET LiveSense technologies, dissecting and analyzing malware to its core. If ransomware is likely, RS flags it and initiates remediation.

ESET RR then starts creating file backups for any file operation impacted by the flagged process (before it can make any modifications). It will continue to do so until RS decides the process is OK, at which point the backup is discarded. Otherwise, RS decides the process is malicious, kills it, and rolls back files from the backup.

Ransomware Remediation is highly configurable. Adding or removing file types that need to be backed up can make a large difference.

This backup process is much more robust, as unlike Windows Volume Shadow Copy-based solutions, it is not a local service that can be abused by the attackers. RR has its own protected storage section on the drive where files cannot be modified or corrupted, nor can the backup be deleted by the attacker. This solves and actively blocks one of the most common failings of regular backups following a ransomware attack.

Days of future past

The role of the admin in the RR process is to understand the capabilities and add file types to the filter that RR applies when creating backups. The only limit to the backups is disk size (and a max size of 30MB per file).

While ESET Ransomware Remediation is very powerful, having other backups as described by the 3-2-1 rule is still a best practice. Always remember to have at least three different copies of data (including the original), two different media types (disk, tape), and one off-site copy (cloud).

All in all, ransomware can be quite sophisticated and troublesome, but it can still be combated. And thanks to secure backups, time travel is not so sci-fi anymore.

For more information on how ESET Ransomware Remediation works, please visit our webpage.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

ESET Research investigates RansomHub, dives into EDR killers, uncovers ties among rival gangs

  • ESET Research releases its analysis of the current ransomware ecosystem with focus on ransomware-as-a-service gang RansomHub.
  • ESET discovered links between the RansomHub, Play, Medusa, and BianLian ransomware gangs by following the trail of tooling that RansomHub offers its affiliates.
  • ESET analysis documents findings about EDRKillShifter and offers insights into the emerging threat of EDR killers.

PRAGUE, BRATISLAVAMarch 26, 2025 — ESET researchers have released a deep-dive analysis about significant changes in the ransomware ecosystem, with focus on the newly emerged and currently dominating ransomware-as-a-service gang RansomHub. The report shares previously unpublished insights into RansomHub’s affiliate structure and uncovers clear connections between this newly emerged giant and well-established gangs Play, Medusa, and BianLian. Furthermore, ESET highlights the emerging threat of Endpoint Detection and Response (EDR) killers, unmasking EDRKillShifter, a custom EDR killer developed and maintained by RansomHub. ESET has observed an increase in ransomware affiliates using EDR killer code derived from publicly available proofs of concept, while the set of drivers being abused is largely unchanged.

“The fight against ransomware reached two milestones in 2024: LockBit and BlackCat, formerly the top two gangs, dropped out of the picture. And for the first time since 2022, recorded ransomware payments dropped significantly by a stunning 35%. On the other hand, the recorded number of victims announced (to be outed publicly) on dedicated leak sites increased by roughly 15%. A big part of this increase is due to RansomHub, a new ransomware-as-a-service (RaaS) gang that emerged around the time of law-enforcement Operation Cronos, which disrupted LockBit activities,” says ESET researcher Jakub Souček, who investigated RansomHub.

Just as any emerging RaaS gang, RansomHub needed to attract affiliates — who rent ransomware services from operators — and since there is strength in numbers, the operators weren’t very picky. The initial advertisement was posted on the Russian-speaking RAMP forum in early February 2024, eight days before the first victims were posted. RansomHub prohibits attacking nations from the post-Soviet Commonwealth of Independent States, Cuba, North Korea, or China. Interestingly, it lures affiliates in with the promise that they will receive the whole ransom payment to their wallet, and the operators trust the affiliates to share 10% with them, something quite unique.

In May, RansomHub operators made a significant update: They introduced their own EDR killer — a special type of malware designed to terminate, blind, or crash the security product installed on a victim’s system — typically by abusing a vulnerable driver.

RansomHub’s EDR killer, named EDRKillShifter, is a custom tool developed and maintained by the gang. EDRKillShifter is offered to RansomHub affiliates. Functionality-wise, it is a typical EDR killer targeting a large variety of security solutions that the RansomHub operators expect to find protecting the networks they aim to breach.

“The decision to implement a killer and offer it to affiliates as part of the RaaS program is rare. Affiliates are typically on their own to find ways to evade security products — some reuse existing tools, while more technically oriented ones modify existing proofs of concept or utilize EDR killers available as a service on the dark web. ESET researchers saw a steep increase in the use of EDRKillShifter, and not exclusively in RansomHub cases,” explains Souček.

Advanced EDR killers consist of two parts — a user mode component responsible for orchestration (the killer code) and a legitimate, but vulnerable, driver. The execution is typically very straightforward — the killer code installs the vulnerable driver, typically embedded in its data or resources, iterates over a list of process names of security software, and issues a command to the vulnerable driver, resulting in triggering the vulnerability and killing the process from kernel mode. “Defending against EDR killers is challenging. Threat actors need admin privileges to deploy an EDR killer, so ideally, their presence should be detected and mitigated before they reach that point,” adds Souček.

ESET discovered that RansomHub’s affiliates are working for three rival gangs — Play, Medusa, and BianLian. Discovering a link between RansomHub and Medusa is not that surprising, as it is common knowledge that ransomware affiliates often work for multiple operators simultaneously. On the other hand, one way to explain Play and BianLian having access to EDRKillShifter is that they hired the same RansomHub affiliate, which is unlikely given the closed nature of both gangs. Another, more plausible explanation is that trusted members of Play and BianLian are collaborating with rivals, even newly emerged ones like RansomHub, and then repurposing the tooling they receive from those rivals in their own attacks. Play has been linked to the North Korea-aligned group Andariel.

For a more detailed analysis of RansomHub and EDRKillShifter, check out the latest ESET Research blogpost “Shifting the sands of RansomHub’s EDRKillShifter” on WeLiveSecurity.com. Make sure to follow ESET Research on Twitter (today known as X), BlueSky, and Mastodon for the latest news from ESET Research.

Schematic overview of the links between Medusa, RansomHub, BianLian, and Play

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

ESET Doubles Down on North American Corporate Solutions Business with New Field CISO

LAS VEGAS, Nev.March 26, 2025ESET, a global leader in cybersecurity, is growing its Corporate Solutions business in North America with the appointment of Charles (Chuck) Everette as Field Chief Information Security Officer (CISO). Following the recent appointment of ESET’s global Chief Corporate Solutions Officer Martin Talian, today’s news marks a significant milestone as the division looks to rapidly gain further traction in North America.

ESET’s Corporate Solutions division was launched globally in 2022 to deliver custom solutions and high-value threat intelligence for Fortune 500 companies and large enterprises to proactively defend against advanced threats. Featured at ESET World 2025 taking place this week, the Corporate Solutions team in North America and globally delivers highly configurable, scalable, and innovative solutions for customers operating critical infrastructure, providing financial services as well as government and defense organizations. This includes highly configurable, scalable, and innovative solutions designed for organizations delivering mission critical services. Specialized solutions offered by Corporate Solutions include but are not limited to:

  • Air-gapped instances for local sandboxing and threat analysis
  • Managed cybersecurity services covering end-to-end perimeter
  • Advanced scanning solutions for complex and high-volume environments
  • Long-life support aligned with customer’s product lifecycles
  • Integrated solutions for both homes and businesses
  • High-value cybersecurity advisory services

ESET Corporate Solutions excels in the design, delivery, and operation of these solutions and services, offering various levels of customization.

“Large Fortune 500 companies and North America enterprises have incredibly complex cybersecurity requirements, and Chuck brings the rare combination of visionary leadership, relationships, and hands-on expertise to drive momentum for Corporate Solutions locally,” said Martin Talian. “His deep technical knowledge and ability to communicate complex ideas to diverse audiences make him an invaluable asset to our organization and a trusted voice in the industry. We are thrilled to welcome him to the ESET team and to see this business reach its full potential in North America.”
Everette is an accomplished cybersecurity veteran with more than two decades of global IT security leadership. After starting his career as a hands-on practitioner in manufacturing and finance, he rose through the ranks to become a Deputy CISO of Fidelity National Information Services, where he oversaw 80% of the United States’ financial traffic and built a 60-person Security Operations Center (SOC) from the ground up. Everette has acted as a trusted advisor to Fortune 500 companies, municipalities, and venture capital firms evaluating cybersecurity investments. He has also worked extensively with federal agencies, including Homeland Security, and has been involved in addressing many of the most significant data breaches over the past 15 years.

“As a CISO and security practitioner myself, it’s important to me that I work with vendors known for technology excellence – and that’s what led me to ESET,” said Everette. “ESET is recognized across the industry for the strength of its products, in-house innovation, and unwavering commitment to its customers. I’m not coming in as a salesperson but as a peer who can relate to other CISOs because I’ve been in their shoes. I’m excited to help grow ESET’s presence in the North American market.”

A respected voice in the cybersecurity industry, Everette has spoken at prestigious conferences such as RSA and Black Hat, and has authored articles for Forbes and Dark Reading. His deep network of industry professionals and unwavering commitment to advancing cybersecurity make him a pivotal figure in the field.

To learn more about ESET Corporate Solutions, visit https://www.eset.com/us/business/corporate-solutions/.

 

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

ESET World 2025 Kicks Off in Las Vegas

SAN DIEGO, Calif. March 24, 2025ESET, a global leader in cybersecurity, today kicked off ESET World 2025 at the Aria Resort & Casino in Las Vegas. Taking place from March 24-27, 2025, this global cybersecurity conference brings together leading experts, technologists, government, and industry professionals to discuss the latest cyber threats, innovations, regulations, and cutting-edge research facing attendees.

Keynote and featured speakers at the show include:

  • Richard Marko, Chief Executive Officer at ESET
  • Michal Valko, Chief Models Office, Member of the Founding Team, Member of the Technical Staff, Stealth AI Startup
  • Roman Unuchek, Reverse Engineer, Android Malware Research Team, Google
  • Tyler Welt, Global Lead for Security Partner Enabling, Client Computing Group, Intel Corporation
  • Juraj Malcho, Chief Technology Officer, ESET
  •  Kirsten Bay, Co-founder & Chief Executive Officer, Cysurance
  • Richard Stiennon, Chief Research Analyst, IT-Harvest
  • Dalibor Kacmar, National Technology Officer, Microsoft
  • Elliott Peterson, Special Agent, DCIS (DOD)
  • Dave Ahn, Chief Architect, Vice President, Centripetal
  • Henrique Barnard, Strategic Vendor Manager, Dutch Central Government
  • Bas Dekker, Sr. Legal Counsel, Strategic Vendor Management, Dutch Central Government
  • William Booth, General Manager & Director of ATT&CK Evaluations, MITRE
  • Joseph Blankenship, Vice President, Research Director, Security & Risk, Forrester
  • Padraic Harrington, Sr. Analyst, Security and Risk, Forrester
  • Craig Robinson, Research Vice President, Security Services, IDC
  • Chris Kissell, Research Vice President, Security & Trust Product, IDC
  • Peter Stelzhammer, Co-Founder AV-Comparatives

“We are excited to bring ESET World to North America, ensuring that we create meaningful connections with ESET’s customers, partners and technology thought leaders,” said Richard Marko, Chief Executive Officer at ESET. “Cyber threats know no borders, and ESET World 2025 will unite the industry to talk about the future of cybersecurity, including new groundbreaking research from ESET Labs. ESET World’s theme, ‘Prevention-First for a Secure Future,’ will include topics such as harnessing AI, the gamification of large language learning models, zero-trust strategies, cyber resilience, and how companies can harness threat intelligence. ”

Featured entertainment at ESET World 2025 will include Cirque du Soleil Mad Apple on Tuesday, March 25th at the New York-New York Hotel and Casino and entertainment at the House of Blues on Wednesday March 26th.

“Collaboration is necessary in cybersecurity, and we are excited to bring the industry together in Las Vegas this week,” said Ryan Grant, Vice President of Sales and Marketing at ESET North America. “The event highlights ESET’s commitment to cutting-edge research, AI-driven security solutions, and the future of digital protection. Our attendees at ESET World will get to hear from researchers who are tracking the rise and fall of new ransomware groups, sharing new insights into the threat landscape and also releasing new data on attacks against the U.S. financial services industry.”

For more information and to register for free virtual attendance, visit http://www.esetworld.com/. #ESETWorld2025

 

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.