Skip to content

ETeC 2024: Prevention first, Success second: An ESET MDR tale

At the annual internal ESET Technology Conference 2024 (ETeC), a series of high-powered workshops, seminars, hackathons, and presentations occurred.

ESET experts Gabriel Balla (product manager for Enterprise Solutions and Services), James Rodewald (security monitoring analyst), and Michal Hajovsky (global sales lead) provided a sneak peek into ESET MDR – its evolution, backend systems, delivery, as well as success stories demonstrating its ultimate value for businesses of all sizes.

The road to success with ESET MDR

During the initial session with Gabriel Balla and James Rodewald, some of the most influential aspects of ESET MDR on business security, both past successes and future prospects, were discussed.

Balla began by describing a familiar situation many generalist IT admins face – an overabundance of tasks that heavily impact the overall quality of an organization’s security, as admins have to contend with matters such as user support, various device maintenance, monitoring, and more – daily at that.

This is especially burdensome for small and medium-sized businesses (SMBs), which might lack:

  • Budget: SMBs have fewer resources to spend on high-level security and, as specialists are costly and not in abundance, they face tough competition from competitors with larger wallets.
  • Time: An average EDR/XDR solution might generate up to 160,000 detections for an SMB with just 250 seats. This requires lots of dedicated time and understanding to sort through, possibly resulting in alert fatigue.
  • Knowledge: Identifying threats requires professional skills while understanding the newest threats targeting businesses is another heavy task altogether.

While enterprises might not see these points as untenable, they have their specific issues, such as having a larger attack surface with multiple weak spots. Moreover, an enterprise requires finely-tuned preventive security, since the larger a business is, the more likely it is to face issues related to spotty coverage (missed devices) or compliance (country-specific regulations).

In fact, Rodewald later described a situation in which someone had purchased a security service but forgot to deploy it – which might sound comical, if not for its potential to end up causing a costly incident.

How to demonstrate the value of MDR within 30 days

So, why would an SMB want an MDR service? Equally, why would an enterprise need something other than its own Security Operation Center (SOC)?

Hajovsky easily answered these questions: “As much as 82% of ransomware attacks target SMBs. Businesses can break even with endpoint on, as threat actors can get in without using malware, just by abusing RDP or MS SQL…so the initial behavior is, therefore, crucial to monitor for,” he said. Time to detect and respond is crucial. On average, the detection of malicious behavior in business systems takes around 277 days, without any EDR/XDR solution.

For an enterprise SOC, it should take around 16 hours, which is a lot better, but with MDR, this can all be done in less than 30 minutes, due to the way an MDR service is set up. Hajovsky also highlighted that many businesses don’t have the time to dedicate their teams solely to security management. Likewise, with the need for constant education on novel threats, more expertise for threat hunting and incident remediation is required – which is often missing due to skills shortages.

However, ESET MDR, for example, is manned by top experts working with powerful in-house SOAR/SIEM tools ingesting data from multiple points, using a dash of AI-native power, ESET research, and actionable threat intelligence to empower fast proactive threat detection and threat hunting. Additional value can also be found in satisfying compliance and insurance requirements – often asking for EDR/XDR for lower premiums or as a condition.

Don’t believe it? Try it. ESET offers an ESET MDR Trial that can demonstrate its power shortly after deployment – so if the prospects are that you’re not ready to buy, you are most probably ready to try 🙂

ESET MDR success stories

Rodewald dedicated his side of the ESET MDR tale to describing successes – in detail.

In one success story, ESET MDR operators noticed that odd-looking user accounts had started to appear, each added to local administrators. This was being done by a mesh agent (an open-source RMM tool for network management), which is not usually malicious. However, the mesh agent had been installed in a c2Update folder (sounding suspiciously like a C&C server) by notepad.exe running from ProgramData – signaling malicious activity.

When a user account started to perform more actions, such as trying to create a reverse shell, or dropping an EXE (doing a CVE in Veeam software to dump backups) immediately detected and deleted by ESET, the intent became clear: “I suspect that this was likely the beginning of a ransomware or extortionware attack, since we have seen mesh agents used in the US to deploy ransomware,” said Rodewald.

In another success story, ESET analysts saw EsetIpBlacklist detected on a port that was actively used by an sqlserver.exe process, exposed to the internet. The same process was compromised by an outside connection, logging into MS SQL, making themselves into an admin, and starting to execute commands on the OS. The MDR team acted quickly. “The best course of action was to isolate the device – by cutting them off, they weren’t able to execute new commands,” elaborated Rodewald.

Upon further analysis, the team discovered that the MS SQL server command tried to create a PowerShell script named updt.ps1 (downloading a file saved as tzt.bat) and execute it with WMI. “This breaks the process tree a little bit, so without an EDR solution capable of connecting it back together, it wouldn’t look like MS SQL did anything.”

After additional research, the team was able to attribute the latter attack to a case of Mallox Ransomware. “We stopped the attack before it was able to drop an EXE payload just in its initial stages as it was exploring if it could get the .bat file to run. This means that ESET MDR was able to prevent ransomware for a customer, that is a huge success as I see it,” Rodewald concluded.

Prevention first with ESET MDR

According to ESET telemetry, ransomware attacks rose by 32% in H1 2024, compared to the previous semester. This comes in tandem with large-scale compromises of small and large businesses and critical infrastructure (such as hospitals), highlighting a growing problem.

However, sophisticated threats, such as ransomware, are exactly what services like ESET MDR thrive on. They fulfill the notions of a prevention-first security approach by stealthily working in the background to let businesses keep ahead of threats without disrupting their processes.

The main takeaway, as pointed out by Gabriel Balla, should be security success without worry, free from constant notifications about detection or remediation efforts. That is the way of ESET MDR, so let ESET take care of you, and live a life full of green checkmarks indicating that everything is secure in your world.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

New ransomware group Embargo uses toolkit that disables security solutions, ESET Research discovers

  • New ransomware group Embargo is developing and testing Rust-based tooling.
  • The threat actor is capable of disabling security solutions running on the victim’s machine.
  • Embargo tailors its tools to each victim’s environment.

PRAGUE, BRATISLAVAOctober 23, 2024 —ESET researchers have discovered new tooling leading to the deployment of Embargo ransomware. Embargo is a relatively new group in the ransomware scene, first observed by ESET in June 2024. The new toolkit consists of a loader and an endpoint detection and response killer (EDR), which ESET has named MDeployer and MS4Killer, respectively. MS4Killer is particularly noteworthy as it is custom-compiled for each victim’s environment, targeting only selected security solutions. The malware abuses Safe Mode and a vulnerable driver to disable the security products running on the victim’s machine. Both tools are written in Rust, the Embargo group’s language of choice for developing its ransomware.

Based on its modus operandi, Embargo seems to be a well-resourced group. It sets up its own infrastructure to communicate with victims. Moreover, the group pressures victims into paying by using double extortion: the operators exfiltrate victims’ sensitive data and threaten to publish it on a leak site, in addition to encrypting it. In an interview with an alleged group member, an Embargo representative mentioned a basic payout scheme for affiliates, suggesting that the group is providing RaaS (ransomware as a service). “Given the group’s sophistication, the existence of a typical leak site, and the group’s claims, we assume that Embargo indeed operates as a RaaS provider,” says ESET researcher Jan Holman, who analyzed the threat along with fellow researcher Tomáš Zvara.

Differences in deployed versions, bugs, and leftover artifacts suggest that these tools are under active development. Embargo is still in the process of building its brand and establishing itself as a prominent ransomware operator.

Developing custom loaders and EDR removal tools is a common tactic used by multiple ransomware groups. Besides the fact that MDeployer and MS4Killer were always observed deployed together, there are further connections between them. The strong ties between the tools suggest that both are developed by the same threat actor, and the active development of the toolkit suggests that the threat actor is proficient in Rust.

With MDeployer, the Embargo threat actor abuses Safe Mode to disable security solutions. MS4Killer is a typical defense evasion tool that terminates security product processes using the technique known as Bring Your Own Vulnerable Driver (BYOVD). In this technique, the threat actor abuses signed, vulnerable kernel drivers to gain kernel-level code execution. Ransomware affiliates often incorporate BYOVD tooling in their compromise chain to tamper with security solutions protecting the infrastructure being attacked. After disabling the security software, affiliates can run the ransomware payload without worrying whether their payload gets detected.

The main purpose of the Embargo toolkit is to secure the successful deployment of the ransomware payload by disabling the security solution in the victim’s infrastructure. Embargo puts a lot of effort into that, replicating the same functionality at different stages of the attack. “We have also observed the attackers’ ability to adjust their tools on the fly, during an active intrusion, for a particular security solution,” adds ESET researcher Tomáš Zvara.

For a more detailed analysis and technical breakdown of Embargo’s tools, check out the latest ESET Research blogpost “Embargo ransomware: Rock’n’Rust” on WeLiveSecurity.com. Make sure to follow ESET Research on Twitter (today known as X) for the latest news from ESET Research.

Malware execution diagram

 

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

ESET Integrates with SuperOps to Elevate Cybersecurity for MSPs

Setting a New Benchmark in Endpoint Management: Enhancing Operational Efficiency and Elevating Client Security

BRATISLAVAOctober 16, 2024 — ESET, a global leader in cybersecurity, and SuperOps, a next-generation Remote Monitoring and Management (RMM) and Professional Services Automation (PSA) platform, today announced their powerful integration.

This collaboration enables Managed Service Providers (MSPs) to seamlessly manage and secure their endpoints directly within the SuperOps platform, bringing unmatched efficiency and protection to their operations with the added power of ESET Endpoint Security, a core solution of the awarded and recognized ESET PROTECT Platform.

“Our goal at SuperOps is to make the work of MSPs more efficient and intuitive. Integrating ESET with SuperOps provides MSPs with a streamlined, all-in-one solution for endpoint security management. This partnership will empower MSPs to offer enhanced protection to their clients while, at the same time, simplifying their workflows,” said Arvind Parthiban, Co-founder and CEO, SuperOps.

ESET’s security products are highly regarded by analysts and customers for delivering a comprehensive high-quality multi-layered security stack configured to both prevent threats from taking hold on a network and to efficiently manage detection and response actions by leveraging both its AI-native detection technologies and its globally recognized research and threat intelligence.

The integration with SuperOps enables rapid deployment of our endpoint security solution on all assets within minutes, ensuring immediate protection and optimization. MSPs can automate ESET’s next-gen security solution during asset onboarding to safeguard against zero-day, ransomware, phishing, and targeted attacks, and monitor protection status in real-time within SuperOps. This is all thanks to the multi-layered AI-native ESET LiveSense security stack incorporated within our endpoint product, turbocharging protection in an always-evolving threat landscape.

“ESET is well known as a reliable partner for thousands of MSPs, as we are quite serious about our partnerships. With this integration, MSPs can manage cybersecurity with greater ease and confidence. To achieve that, ESET’s robust security measures combined with SuperOps’ comprehensive management tools create a powerful synergy that enhances operational efficiency and client protection,” said Michal Jankech, Vice President, Enterprise & SMB/MSP at ESET.

As damage from global cybercrime is projected to increase by 15% annually, reaching $10.5 trillion by 2025 (Source: Forbes), businesses, especially MSPs, need to make cybersecurity their top priority. The integration of ESET with SuperOps significantly enhances cybersecurity operations and boosts the security offerings of MSPs. By combining their strengths, ESET and SuperOps are redefining industry standards, empowering MSPs to provide their clients with unparalleled security.

To learn more about how to integrate SuperOps with ESET, please visit the guidance page.

For more information about the ESET PROTECT Platform and its underlying modules, visit our page here.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

ESET Named Strategic Leader in EPR Comparative Report 2024

  • ESET has earned recognition as a Strategic Leader for the fourth time in the AV-Comparatives Endpoint Prevention and Response (EPR) Comparative Report 2024 and has become a certified EPR vendor for the fifth time in a row
  • ESET PROTECT Enterprise achieved the highest Prevention and Response score in this year’s EPR test.
BRATISLAVAOctober 14, 2024ESET, a global leader in cybersecurity, is pleased to announce that ESET PROTECT Enterprise has been rigorously tested and named a Strategic Leader in the AV-Comparatives Endpoint Prevention and Response (EPR) Comparative Report 2024. This marks the fourth time ESET has achieved this prestigious ranking, reinforcing its position among the best in the industry. “Our consistent ranking as a ‘Strategic Leader’ in AV-Comparatives reports highlights our ongoing commitment to delivering best-in-class security solutions,” said Juraj Malcho, Chief Technology Officer of ESET. “ESET PROTECT Enterprise is built to provide robust defense while ensuring seamless operations for enterprises of all sizes. We’re proud to see our efforts recognized, and we remain dedicated to innovation and excellence in cybersecurity.” The 2024 AV-Comparatives report evaluated 12 security solutions, including ESET PROTECT Enterprise, across 50 sophisticated attack scenarios. ESET achieved outstanding results by detecting and neutralizing 98% of threats during the earliest phase of attacks, with the remaining 2% successfully mitigated in the second phase. By preventing threats from advancing any further, early prevention by ESET ensured that no asset breaches occurred and no malicious activity went unnoticed. These results positioned ESET PROTECT among the highest scoring in Prevention and Response. The performance ensures that ESET continues to set a benchmark for prevention, detection, and response capabilities. “ESET’s strong performance in the 2024 EPR Test highlights their dedication to delivering effective and reliable protection against advanced threats. Their consistent success reflects a solid commitment to cybersecurity excellence,” said Andreas Clementi, Founder and CEO of AV-Comparatives. ESET PROTECT Enterprise includes ESET Inspect, an extended detection and response (XDR) enabling solution that provides enterprise-grade security with advanced threat hunting, detailed network visibility, and incident response. Its comprehensive cross-platform coverage supports Windows, Mac, Linux, and mobile platforms like Android and iOS, delivering industry-leading ransomware, zero-day protection, and more. This is the fifth consecutive certification for ESET as an EPR vendor. The EPR Comparative Report is known for its rigorous testing standards, offering a transparent evaluation of how well security solutions protect organizations from real-world cyber threats. For more information about ESET PROTECT Enterprise, please click here.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

Names of the ESET Science Award 2024 laureates announced. Mária Bieliková named Outstanding Scientist in Slovakia.

An international jury, headed by Nobel Laureate Emmanuelle Charpentier, has selected the laureates of the prestigious ESET Science Award. In the category of Outstanding Scientist in Slovakia, the laureate is Maria Bielikova, an expert in the field of artificial intelligence and the founder of the Kempelen Institute for Intelligent Technologies. In the category of Outstanding Scientist under 35, the award went to physicist Frantisek Herman, and the award in the category of Outstanding Academic went to Igor Farkas, an expert in artificial intelligence. Oncologist Michal Mego received the most votes from the public in the Public Choice Award with almost 14 thousand people in Slovakia voting this year. On Thursday, October 10, 2024, the sixth annual ESET Science Award took place, during which the ESET Foundation and main partner, ESET, honored outstanding scientific personalities and educators in Slovakia. The ESET Science Award recognizes those who, through their research and academic activities, not only contribute to the development of their scientific field, but also the results of which have a positive impact on other areas of life and help find solutions to the challenges facing our planet and society. This year, the Outstanding Scientist in Slovakia award went to Mária Bielikova, an expert in the field of artificial intelligence with a focus on machine learning and solving the problem of information overload in the online space and the founder of the Kempelen Institute of Intelligent Technologies, the first independent research institute in Slovakia, which aims to bring excellent science to companies and link them with the academic sector. In the category of Outstanding Scientist under 35, the award went to František Herman, a talented young scientist who, together with his team at the Department of Experimental Physics at the Faculty of Mathematics, Physics and Informatics at the Comenius University in Bratislava, is researching the theoretical physics of condensed matter. Igor Farkaš, Deputy Head of the Department of Applied Informatics at the Faculty of Mathematics, Physics and Informatics at Comenius University in Bratislava and an expert in the field of artificial intelligence, who specializes in the study of artificial neural network models, was awarded the Outstanding Academic in Slovakia award. The international jury that selected the laureates in the scientific categories this year, was chaired by Nobel Laureate Emmanuelle Charpentier. The other members of the jury were computer scientist Subhashis Banerjee, material scientist Michael John Reece, nuclear physicist Jürgen Schukraft and oncologist Jan Trka. The final decision on the laureates is the result of a consensus of the jury, which considers dozens of criteria. These include both measurable and qualitative indicators, such as scientific ethics and integrity, the ability to communicate the research and its resonance in the international scientific community. The laureate in the category of Outstanding Academic was decided by a panel of the top representatives of Slovak universities. Emmanuelle Charpentier presented the award to the laureate in the category of Outstanding Scientist in Slovakia. She said: “Congratulations to all the award recipients, as well as the finalists. Their scientific research brings findings that have a real impact on our world and society. I believe that ESET Science Award not only highlights the importance of scientific work to the public but also inspires others to bravely continue exploring new knowledge that has the power to change the world around us.” The winner of the Public Choice Award was oncologist Michal Mego, head of II. Oncology Clinic of the Medical Faculty at Comenius University and the National Cancer Institute (NCI). In addition to devoting his working time to patient care and the education of medical professionals, he also gives his time to research. He even founded the Translational Research Unit at NCI, which aims to transfer knowledge from basic research to clinical practice and vice versa. Michal Mego and his research team are particularly interested in breast and testicular cancer. He is also researching the microbiome and probiotic bacteria that could help cancer patients better cope with the side effects of treatment. Mária Bielikova, Outstanding Scientist in Slovakia Laureate Prof. Ing. Mária Bielikova works on artificial intelligence and machine learning at the Kempelen Institute of Intelligent Technologies. She founded the institute in 2020 and considers it her biggest success thus far. Her scientific field is young and still changing, and her field of research keeps changing as well. Over the long term, she and her team have been tackling the problem of information overload. František Herman, Outstanding Scientist in Slovakia Under the Age of 35 Laureate Mgr. František Herman, PhD., works at the Department of Experimental Physics at the Faculty of Mathematics, Physics and Informatics at Comenius University Bratislava, where he and his students research theoretical condensed matter physics in addition to teaching. At the moment, they are most interested in superconductivity. Igor Farkaš, Outstanding Academic in Slovakia Laureate Prof. Ing. Igor Farkaš, Dr., is one of the leading Slovak experts on artificial intelligence. In recent years, he has also been active in its popularization. He is the Associate Department Chair at the Department of Applied Informatics at the Faculty of Mathematics, Physics and Informatics at Comenius University Bratislava. At its Centre of Cognitive Science, he has long been focused on researching artificial neural network models inspired by the human brain. For more information about the Laureates, please visit https://www.esetscienceaward.sk/en/laureates For more information about the ESET Science Award, please visit www.esetscienceaward.sk/en

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.