Skip to content

Optimized Malware Detection from ESET & Intel


ESET has been collaborating with Intel for several years to deliver endpoint security software that can take advantage of hardware-based security and performance features—a major advantage in the battle to detect advanced ransomware and other constantly evolving threats. 

Why businesses need hardware layer security on their endpoints

Despite all efforts, ransomware attacks continue to escalate in frequency and severity, with cybercriminals’ extortion tactics becoming progressively more brutal. Ransomware and malware in general are also becoming more sophisticated and better able to avoid detection by conventional means.

For example, recent ransomware variants can rewrite themselves once they infiltrate a victim’s environment, thus dodging traditional signature-based detection tools. Another emerging ransomware capability is hiding inside virtual machines.

These advanced obfuscation techniques are creating gaps in cybersecurity coverage. This is where hardware-based malware detection comes into play—detecting both known and novel malware to keep companies safer. While malware software always leaves a “fingerprint” when it executes, hardware-based monitoring of CPU telemetry can flush out even the most sophisticated ransomware, providing elevated immunity to many detection bypasses.

Mutual customers have benefitted from ESET’s collaboration with Intel since March 2022, when ESET rolled out its ESET PROTECT multilayered cybersecurity suite integrated and automatically configured with Intel® Threat Detection Technology (Intel® TDT).  Today, approximately 90% of ESET end users are running on Intel-based systems. Residing  on the Intel CPU, the combined solutions use AI to analyze CPU telemetry to provide advanced detection against new and existing strains of malware—especially ransomware.

The latest from ESET and Intel: Leveraging hybrid processors to optimize performance

While the need for advanced, AI-driven threat detection grows by the day, cybersecurity and IT leaders look to balance new technology deployments against the performance and productivity challenges brought on by remote and hybrid work scenarios. Endpoint security tools must keep a low profile to avoid slowing down other tasks and/or draining users’ batteries.

This is why ESET and Intel have expanded their work together, now offering advanced endpoint solutions that take advantage of Intel’s latest hybrid processor architecture. The newer generations of Intel® Core™ and Intel® Core™ Ultra processors have two kinds of cores:

  1. Performance cores, which compute at the highest speeds
  2. Efficient cores, which compute relatively fast but with much lower energy consumption

How is hybrid chip architecture relevant to cybersecurity incident detection and response? If you are trying to detect the presence of malware, you probably want that operation to run as fast as possible. So, you would run it on performance cores. But some other cybersecurity processes, such as updates and background scans, can run on efficient cores to save device power and optimize the performance of priority tasks.

By taking advantage of Intel’s hybrid processor architecture to intelligently schedule background workloads on efficient cores when available, ESET endpoint protection solutions can better meet the demands of remote and hybrid work scenarios. Another key benefit discovered in initial testing: battery power savings on laptops running the hybrid aware software have been on the order of 5% to 8%.

According to Előd Kironský, Vice President of Endpoint Solutions and Security Technologies at ESET, “Our endpoint protection product is aware that it is running on a hybrid processor, and it is able to direct different workloads to use either efficient cores or performance cores. Assigning workloads to efficient cores has no negative impact on product performance. In a number of scenarios, performance increases were documented and processes completed faster.”

This new “hybrid aware” capability is slated to be released to ESET customers in early December.

Compound benefits for ESET customers running on Intel

Low impact to system performance is an area that ESET has always prioritized within its multilayered software architecture and is a key selling point for many of our clients. Leveraging technology that can help with prevention and protection while also preserving performance is a win-win choice.

Likewise, ESET has always advocated a multilayered approach to security. By adding the silicon layer to our security stack, ESET and Intel have reached a new milestone in combatting cyberthreats.

By taking advantage of newly expanded capabilities in the Intel relationship, our customers witness multiple benefits from the joint solution.

  • Intel TDT’s hardware-level malware detection coupled with its ongoing machine learning improvements are a powerful weapon in the fight against ransomware and other cyberattacks.
  • The added compute demands from this new hardware-level detection capability are largely being offloaded onto the GPU or efficiency cores, minimizing impacts on system performance and end user productivity.
  • Because the joint solution activates and operates automatically, it delivers an immediate boost to ransomware protection with no increase in IT complexity or administrative workload.

Customers looking to take advantage of next-gen cybersecurity won’t have to wait long for continued innovation from ESET and Intel. We are currently working together to develop new functionalities and tools that take advantage of the neural processing unit (NPU) in Intel Core Ultra processors and expand on ESET’s leadership in AI-native security for AI PCs.

It’s important that we continue to maximize innovation and address tomorrow’s unknown threats through our work with innovation partners, like Intel. It’s these types of collaborations that will empower a safer tomorrow for businesses of all sizes, and we are proud to include them in the ESET technology ecosystem.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

How UEM Boosts IAM: A First-class Strategy for Operational Efficiency

ProMobi Technologies today announced that Scalefusion- its leading unified endpoint management solution (UEM), has now launched support for ChromeOS device management. This addition reinforces Scalefusion’s commitment to offering a versatile multi-OS management platform that caters to the diverse needs of modern businesses. 

With the integration of ChromeOS, Scalefusion enables IT administrators to streamline the management of ChromeOS devices alongside Windows, macOS, Android, and Linux, simplifying the complexities of multi-OS environments.

ChromeOS has seen significant adoption across industries, from education to enterprise, thanks to its balance of affordability, speed, and security. Recognizing this growing trend, Scalefusion’s new ChromeOS device management provides organizations with the ability to provision, secure, and monitor ChromeOS devices seamlessly through the same intuitive platform used for their existing device ecosystems.

Scalefusion’s ChromeOS management empowers businesses to streamline device management by integrating ChromeOS into their existing device strategy. With Scalefusion’s unified platform, IT administrators can boost productivity by providing a consistent, unified experience for users across all platforms. Whether organizations are deploying Chromebooks in educational settings or managing ChromeOS devices for remote workforces, Scalefusion makes it simple to provision, secure, and monitor these devices—all from a single dashboard. With the addition of ChromeFlex, businesses can repurpose existing PCs and Macs by converting them to ChromeOS devices, further extending the life of their hardware while maintaining seamless management through Scalefusion’s unified platform.

Sriram Kakarala, Chief Product Officer at Scalefusion, highlighted the importance of this new addition: “With the rise of ChromeOS in diverse sectors, we saw a clear opportunity to enhance the Scalefusion platform. By adding ChromeOS support, we are delivering on our promise to simplify device management for our customers, regardless of which operating systems they choose to deploy.”

Scalefusion’s integration aims to provide organizations with a straightforward approach to managing their multi-OS device ecosystems. Request a free trial of this release by setting up a demo of Scalefusion for ChromeOS here.

About Scalefusion

ProMobi Technologies provides a leading Unified Endpoint Management solution under the brand Scalefusion. Scalefusion UEM allows organizations to secure and manage endpoints, including smartphones, tablets, laptops, rugged devices, POS and digital signage, and apps and content. It supports the management of Android, iOS, macOS, Windows, Linux, and ChromeOS devices and ensures streamlined device management operations with Scalefusion Remote Troubleshooting.

More than 8000 companies worldwide are unlocking their true potential using Scalefusion, which is used across various industries, such as Transportation & Logistics, Retail, Education, Healthcare, Manufacturing, Construction & Real Estate, Hospitality, Software & Telecom, Financial Services, and others.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Scalefusion
Scalefusion’s company DNA is built on the foundation of providing world-class customer service and making endpoint management simple and effortless for businesses globally. We prioritize the needs and feedback of our customers, making sure that they are at the forefront of all decision-making processes. We are dedicated to providing comprehensive customer support services, and place emphasis on customer-centric thinking throughout the organization.

The Crucial Role of MSPs in Safeguarding Clients Against Evolving Threats: Lessons from the WarmCookie Malware Incident

Key Takeaways: 

  • Evolving Threat Landscape: Cybercriminals increasingly use sophisticated techniques, such as fake browser updates, to distribute malware like WarmCookie, posing significant risks to organizations with insufficient security awareness.
  • MSPs as Frontline Defenders: Managed Service Providers (MSPs) are responsible for staying current with the latest threats to protect their clients from emerging cyber risks, such as phishing websites and malicious downloads.
  • Awareness Is Key: Both MSPs and their clients must maintain high levels of awareness about new vulnerabilities and threats, with MSPs playing a critical role in educating and guiding their customers.

Introduction: A New Breed of Cyber Threat – The WarmCookie Malware

A recent campaign, called FakeUpdate,  of fake browser update pop-ups spreading the WarmCookie malware highlights the ever-evolving tactics cybercriminals use to breach organizational defenses. This attack, targeting users with fraudulent update alerts, emphasizes the critical role MSPs play in safeguarding their clients from these sophisticated threats.

The WarmCookie Malware and Its Impact

In the new FakeUpdate campaign, as reported by Gen Threat Labs, the WarmCookie leverages deceptive browser update notifications, luring unsuspecting users into downloading malicious software. Users, believing they are securing their systems with an update, unknowingly open the door to data theft, unauthorized access, and further compromise of their IT infrastructure.

This type of malware presents a particularly dangerous threat to organizations lacking cybersecurity vigilance. Employees may unwittingly engage with phishing sites or download harmful software disguised as legitimate updates, triggering a chain reaction of security breaches. For small and medium-sized businesses (SMBs), where resources for IT security might be limited, the consequences can be devastating, resulting in data loss, financial damage, or even business closure.

MSPs: Guardians of Cybersecurity for SMBs

MSPs act as the first line of defense for SMBs. They manage IT services and infrastructure, but their role goes beyond mere technical support. They are responsible for securing their clients’ digital environments against a broad spectrum of threats, ranging from ransomware and phishing to malware like WarmCookie.

Cybercriminals are continually updating their tactics, and the WarmCookie case serves as a reminder that staying informed about the latest vulnerabilities is vital. For MSPs, this involves:

  1. Threat Awareness: MSPs need to continuously monitor cybersecurity trends and threat reports, such as those provided by the Cybersecurity and Infrastructure Security Agency (CISA), to identify emerging risks. By knowing about threats like WarmCookie, they can implement defenses proactively.
  2. Client Education: Many attacks exploit user behavior—such as clicking on a fake browser update. MSPs should implement awareness training programs that teach clients to recognize phishing and fraudulent download attempts, significantly reducing their exposure to risk.
  3. Proactive Defense Measures: MSPs must deploy solutions like intrusion detection systems (IDS) and regularly update their clients’ software and security patches to reduce the likelihood of such threats being effective.

A Pattern of Growing Threats: Fake Updates and Malware

The WarmCookie case isn’t isolated. In the past, similar tactics have been used, including:

  • 2019 Chrome Update Scam: A widespread campaign used fake Chrome updates to install banking malware on victims’ devices, leading to significant financial theft.
  • Firefox Phishing Attack (2021): Attackers distributed ransomware using fake Firefox update alerts, locking down victims’ systems until a ransom was paid.

These incidents underscore a worrying trend: Cybercriminals exploit users’ trust in browser updates to compromise systems. In this environment, MSPs must act as constant guardians, equipped to recognize and mitigate these threats before they cause harm.

Practical Tips for MSPs and SMBs

For MSPs:

  1. Automate Software Updates: Use centralized management tools to ensure that all client software, including browsers, is up-to-date with the latest patches. This will reduce the chance that users will fall for fake update scams.
  2. Monitor and Detect Phishing Sites: Leverage tools that scan and block access to known phishing domains and suspicious IP addresses.
  3. Run Simulated Phishing Attacks: Regularly test client readiness with simulated phishing attempts to identify potential vulnerabilities in human behavior.

For SMBs:

  1. Enable Multi-Factor Authentication (MFA): Adding a layer of protection beyond passwords can significantly reduce the risk of unauthorized access, even if malware like WarmCookie is introduced.
  2. Conduct Regular Security Training: Ensure employees know how to spot phishing attempts, fake update alerts, and other scams.
  3. Back-Up Critical Data: Regular, secure backups will allow SMBs to recover quickly from malware attacks or data loss incidents.

Guardz: Empowering MSPs with AI-Native Detection and Response

As October marks Cybersecurity Awareness Month, it is an ideal time for organizations to revisit their security strategies. MSPs, in particular, must take this opportunity to bolster their defenses and awareness against the latest threats.

At Guardz, we recognize the challenges that MSPs face in protecting SMBs from rapidly evolving threats like infostealers. That’s why our AI-powered unified detection and response platform equips MSPs with cutting-edge tools to proactively detect, isolate, and mitigate threats before they can cause damage. With Guardz, MSPs can offer their clients enhanced security without compromising on efficiency or affordability.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Guardz
Guardz is on a mission to create a safer digital world by empowering Managed Service Providers (MSPs). Their goal is to proactively secure and insure Small and Medium Enterprises (SMEs) against ever-evolving threats while simultaneously creating new revenue streams, all on one unified platform.

×

Hello!

Click one of our contacts below to chat on WhatsApp

×