Skip to content

Employee smartphones, a pack of risks in a pocket. How to minimize your business’ attack surface

With proactive prevention, companies can mitigate threats from mobile devices before they can do wider harm.

When intelligence services were trying to infiltrate companies or institutions during World War II and the Cold War, they needed to come up with some very smart ideas. They disguised cameras as coat buttons, hid transceivers in suitcases, and even tried to create a robot dragonfly with a microphone!

Today, when people want to snoop and get around a company’s defenses, they just need to get inside your employees’ smartphones. Nearly everybody has one, and many are casual about their security. Though it’s true that it is rare to see malware spreading from a phone to company laptops, a compromised phone is still a threat if it is connected to the company’s internal network or when attackers steal an employee’s credentials, sensitive corporate data, or banking information.

Considering how small those devices are, the threat landscape they create is disproportionally huge: A single phone contains several devices, such as a camera, microphone, and GPS tracker, but what is even more serious is that these components and many of the applications hosted on the phone can be abused to steal sensitive information from employees and to serve as an initial attack vector for cybercriminals to further harm a company.

Some businesses deal with this by using mobile device management (MDM), imposing strict rules on their corporate devices and allowing employees to use only a handful of apps. However, most businesses are either small or midsize, and their security may struggle to keep enforcement tight.

ESET researchers could write books about malware that threatens smartphones and its potential harm to businesses. That is why ESET, a global leader in cybersecurity, has introduced ESET Mobile Threat Defense (EMTD) as a part of its latest B2B offering.  To improve their prevention capabilities, users of ESET PROTECT Advanced and higher can now enjoy one free mobile device seat per one paid seat for other devices.

Shortly after the successful launch of the ESET’s Mobile Threat Defense module, ESET was included in Forrester’s Mobile Threat Defense (MTD) Solutions Landscape report, Q1 2024. Forrester, a respected analyst firm, provides an overview of 16 vendors in the field, including ESET, which, in our opinion, makes ESET a valuable player in this established market.

What threats are out there?

From the beginning of 2020 until the end of 2023, Android malware detected by ESET telemetry rose by 222%.

For example, last year, ESET researchers discovered two active campaigns targeting Android users distributed across several app stores and dedicated websites.

The threat actors patched the open-source Signal and Telegram apps for Android with malicious code that ESET researchers have identified as BadBazaar. The malicious apps went by the name Signal Plus Messenger and FlyGram, and their purpose was to exfiltrate user data, such as contact lists, call logs, and the list of Google accounts.

Signal Plus Messenger is even more dangerous than FlyGram with its unique capability to spy on the victim’s communications in the original Signal app. Such sensitive information could be used for further spear phishing attacks against business officials.

 

A similar case was covered in June 2023, when ESET researchers identified an updated version of Android GravityRAT spyware. It was distributed within the malicious but functional messaging apps BingeChat and Chatico, which were both based on the OMEMO Instant Messenger app. This particular spyware can exfiltrate call logs, contact lists, SMS messages, the device location, basic device information, and files with specific extensions, such as jpg, PNG, txt, pdf, etc.

And this is just the beginning. Smartphones can be attacked in numerous ways that put companies’ finances and data in danger, such as through banking trojans, phishing, vulnerabilities, or physical theft.

A similar case was covered in June 2023, when ESET researchers identified an updated version of Android GravityRAT spyware. It was distributed within the malicious but functional messaging apps BingeChat and Chatico, which were both based on the OMEMO Instant Messenger app. This particular spyware can exfiltrate call logs, contact lists, SMS messages, the device location, basic device information, and files with specific extensions, such as jpg, PNG, txt, pdf, etc.

And this is just the beginning. Smartphones can be attacked in numerous ways that put companies’ finances and data in danger, such as through banking trojans, phishing, vulnerabilities, or physical theft.

SMBs are more vulnerable

Small businesses are often considered to be the backbone of national economies. In the United States, small businesses (defined as businesses with up to 500 employees) comprise 99.9% of all American businesses.

Authorities in the United Kingdom define small businesses as those with 10 to 49 employees and medium businesses as those with 50 to 249 employees. Similarly, more than 99% of all U.K. businesses are small and medium-sized businesses (SMBs).

Being cheaper and simpler to manage than issuing business devices, a Bring Your Own Device (BYOD) policy is often the number one option for SMBs. Some may also take a hybrid approach, providing corporate devices only to chosen employees. Without proper security, this comes with risks.

Of companies opting for BYOD, 48% say they have seen malware introduced through an employee’s personal phone, and just 4 out of 10 have MDM deployed, according to a Samsung 2023 survey.

And human error is a huge factor. Several recent studies show that more than 80% of data breaches involve a human element. Specifically, the most common mistakes contributing to cyber incidents are employees’ poor password hygiene and misuse of personal email.

However, we are not here to put the blame for every cyber incident on an average employee; after all, IT professionals can make some of the most common mistakes too. For example, half of them admitted to reusing the same password in a Ponemon Institute 2020 study.

Moreover, SMBs are less eager to invest in employee training, according to a survey conducted by the U.K. Department for Science, Innovation and Technology in 2023. For example, only 28% of surveyed small businesses conducted awareness training, in comparison with 77% of large businesses.

The same survey found that SMBs often also lack properly educated senior managers: “Although we have senior managers who are good at the role, they don’t have awareness in cyber security. I try to ensure they have a basic understanding, training, and knowledge in it. But they are focused on the day-to-day,” said one of the participating human resources administrators working for a medium business.

Target mobile threats to minimize attack surfaces

Considering these threats, implementing MDM is a huge step forward. For example, ESET Mobile Threat Defense gives administrators the option to monitor and control applications for both Android and iOS. EMTD is part of ESET’s cloud and on-premises unified management console ESET PROTECT, so no additional management console is needed.

With endpoint protection included, EMTD also provides antivirus and anti-phishing features, giving businesses more cyberattack prevention capabilities.

Both are also necessary when opting for a Zero Trust approach, an increasingly popular strategy in which the company verifies every account or device before allowing it to connect to its network.

See these ESET Mobile Threat Defense key capabilities and features:

  • Security: The security features range from anti-malware, anti-phishing, anti-theft, device security to control over web access, and much more.
  • Management: Management includes remotely wiping devices, restricting application installs, preconfiguring devices for users, and other items related to IT management.
  • Multiple OS: Mobile protection typically covers Android and Apple devices, the two most widespread mobile operating systems. As these operating systems are different, mobile protection capabilities can also vary between them.
  • Single pane of glass (SPOG): EMTD is natively integrated into the ESET PROTECT platform, and there is no need for another console or management platform.
  • Remote deployment: IT administrators simply selects employees with corporate devices, and they will automatically receive a QR code to then download ESET protection. Simple as that!
  • Seamless synchronization with cloud management platforms: For streamlined enrollment of mobile devices, ESET supports Microsoft Intune, Microsoft Entra ID, VMware Workspace ONE, and Apple Business Manager.

Investing in prevention to avoid crisis

According to the 2023 ITRC Business Impact Report, nearly half of the surveyed U.S. SMBs that experienced a data breach estimated their financial losses as being up to $250,000, another 26% calculated their losses as $250,000 to $500,000, and another 10% of SMBs estimated their losses could reach $1 million.

Seeing these numbers, it is clear that the phrase “an ounce of prevention is worth a pound of cure” also applies to cybersecurity. And that is not all: One-third of those companies also experienced loss of customer trust after a breach.

MDM with endpoint protection is always a great option to avoid such damage by decreasing your attack surface and possible risks, despite a lack of employee awareness training. Even better is that device management and protection can be operated from a single user-friendly platform, saving IT professionals precious time.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

ESET Research releases latest APT Activity Report, highlighting cyber warfare of Russia-, China-, and Iran-aligned groups

  • This ESET APT Activity Report summarizes notable activities of cyberthreat groups that were documented by ESET researchers from October 2023 until the end of March 2024.
  • Iran-aligned groups increased their activity against Israel after the Hamas-led attack on Israel in October 2023 and  throughout the ongoing  war in Gaza.
  • Russia-aligned groups focused on espionage within the European Union and continued attacks against Ukraine.
  • China-aligned threat actors exploited vulnerabilities in public-facing appliances, such as VPNs and firewalls, and software.
  • The main targets of most of the campaigns were government organizations.

BRATISLAVAMay 14, 2024 — ESET has released its latest APT Activity Report, which summarizes notable activities of selected advanced persistent threat (APT) groups that were documented by ESET researchers from October 2023 until the end of March 2024. The highlighted operations are representative of the broader landscape of threats ESET Research has investigated during this period, illustrating key trends and developments. After the Hamas-led attack on Israel in October 2023, and  throughout the ongoing war in Gaza, ESET has detected a significant increase in activity from Iran-aligned threat groups. Russia-aligned groups have focused their activities on espionage within the European Union and attacks against Ukraine. On the other hand, several China-aligned threat actors exploited vulnerabilities in public-facing appliances, such as VPNs and firewalls, and software, such as Confluence and Microsoft Exchange Server, for initial access to targets in multiple verticals. North Korea-aligned groups continued to target aerospace and defense companies and the cryptocurrency industry.

“The targets of most of the campaigns were government organizations and certain verticals: for example, those targeted in continued and relentless attacks on Ukrainian infrastructure. Europe experienced a more diverse range of attacks from various threat actors. Russia-aligned groups strengthened their focus on espionage in the European Union, where China-aligned threat actors also maintain a consistent presence, indicating a continued interest in European affairs by both Russia- and China-aligned groups,” says Jean-Ian Boutin, Director of Threat Research at ESET.

Based on the data leak from Chinese security services company I-SOON (Anxun), ESET Research can confirm that this Chinese contractor is indeed engaged in cyberespionage. ESET tracks a part of the company’s activities under the FishMonger group. In this latest report, ESET also introduces a new China-aligned APT group, CeranaKeeper, distinguished by unique traits yet possibly connected by the digital footprint with the Mustang Panda group.

In the case of Iran-aligned threat groups, MuddyWater and Agrius transitioned from their previous focus on cyberespionage and ransomware, respectively, to more aggressive strategies involving access brokering and impact attacks. Meanwhile, OilRig and Ballistic Bobcat activities saw a downturn, suggesting a strategic shift toward more noticeable, “louder” operations aimed at Israel.

Regarding Russia-aligned activity, the Operation Texonto campaign, a disinformation and psychological operation (PSYOP) uncovered by ESET researchers, has been spreading false information about Russian election-related protests and the situation in the eastern Ukrainian metropolis Kharkiv, fostering uncertainty among Ukrainians domestically and abroad.

The report also describes the exploitation of a zero-day vulnerability in Roundcube by Winter Vivern, a group ESET assesses to be aligned with the interests of Belarus. Additionally, ESET spotlights a campaign in the Middle East carried out by SturgeonPhisher, a group ESET researchers believe to be aligned with the interests of Kazakhstan.

ESET products protect our customers’ systems from the malicious activities described in this report. Intelligence shared here is primarily based on proprietary ESET telemetry data and has been verified by ESET researchers, who prepare in-depth technical reports and frequent activity updates detailing activities of specific APT groups. These threat intelligence analyses, known as ESET APT Reports PREMIUM, assist organizations tasked with protecting citizens, critical national infrastructure, and high-value assets from criminal and nation-state-directed cyberattacks. This report contains only a fraction of the cybersecurity intelligence data provided to customers of ESET’s private APT reports.

You can read the full ESET APT Activity Report on WeLiveSecurity.com. Make sure to follow ESET Research on Twitter (today known as X) for the latest news from ESET Research.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

ESET Research: Ebury botnet alive & growing; 400k Linux servers compromised for cryptocurrency theft and financial gain

  • ESET Research has released its deep-dive investigation into one of the most advanced server-side malware campaigns, which is still growing – Ebury group with their malware and botnet.
  • Over the years, Ebury has been deployed as a backdoor to compromise almost 400,000 Linux, FreeBSD, and OpenBSD servers; more than 100,000 were still compromised as of late 2023.
  • Ebury actors have been pursuing monetization activities subsequent to our 2014 publication on Operation Windigo, including the spread of spam, web traffic redirections, and credential stealing.
  • Additionally, ESET has confirmed that operators are also involved in cryptocurrency heists.
  • In many cases, Ebury operators were able to gain full access to large servers of ISPs and well-known hosting providers.

BRATISLAVA, MONTREALMay 14, 2024 — ESET Research released today its deep-dive investigation into one of the most advanced server-side malware campaigns, which is still growing and has seen hundreds of thousands of compromised servers in its at least 15-year-long operation. Among the activities of the infamous Ebury group and botnet over the years has been the spread of spam, web traffic redirections, and credential stealing.  In recent years it has diversified to credit card and cryptocurrency theft. Additionally, Ebury has been deployed as a backdoor to compromise almost 400,000 Linux, FreeBSD, and OpenBSD servers; more than 100,000 were still compromised as of late 2023. In many cases, Ebury operators were able to gain full access to large servers of ISPs and well-known hosting providers.

Ten years ago, ESET published a white paper about Operation Windigo, which uses multiple malware families working in combination, with the Ebury malware family at its core. In late 2021, the Dutch National High Tech Crime Unit (NHTCU), part of the Netherlands national police, reached out to ESET regarding servers in the Netherlands suspected of being compromised with Ebury malware. Those suspicions turned out to be well-founded and with NHTCU’s assistance, ESET Research has gained considerable visibility into operations run by the Ebury threat actors.

“Following the release of the Windigo paper in early 2014, one of the perpetrators was arrested at the Finland-Russia border in 2015, and later extradited to the United States. While initially claiming innocence, he eventually pleaded guilty to the charges in 2017, a few weeks before his trial at the U.S. District Court in Minneapolis was set to proceed, and where ESET researchers were scheduled to testify,” says Marc-Etienne M. Léveillé, the ESET researcher who investigated Ebury for more than a decade.

Ebury, active since at least 2009, is an OpenSSH backdoor and credential stealer. It is used to deploy additional malware to: monetize the botnet (such as modules for web traffic redirection), proxy traffic for spam, perform adversary-in-the-middle attacks (AitM), and host supporting malicious infrastructure. In AitM attacks, ESET has observed over 200 targets across more than 75 networks in 34 different countries between February 2022 and May 2023.  

Its operators have used the Ebury botnet to steal cryptocurrency wallets, credentials, and credit card details. ESET has uncovered new malware families authored and deployed by the gang for financial gain, including Apache modules and a kernel module to perform web traffic redirection. Ebury operators also used zero-day vulnerabilities in administrator software to compromise servers in bulk.

After a system is compromised, a number of details are exfiltrated. Using the known passwords and keys obtained on that system, credentials are reused to try logging into related systems. Each new major version of Ebury introduces some important change and new features and obfuscation techniques.

“We have documented cases where the infrastructure of hosting providers was compromised by Ebury. In these cases, we have seen Ebury being deployed on servers rented out by those providers, with no warning to the lessees. This resulted in cases where the Ebury actors were able to compromise thousands of servers at once,” says Léveillé. There is no geographical boundary to Ebury; there are servers compromised with Ebury in almost all countries in the world. Whenever a hosting provider was compromised, it led to a vast number of compromised servers in the same data centers.

At the same time, no verticals appear more targeted than others. Victims include universities, small and large enterprises, internet service providers, cryptocurrency traders, Tor exit nodes, shared hosting providers, and dedicated server providers, to name a few.

In late 2019, the infrastructure of a large and popular US-based domain registrar and web hosting provider was compromised. In total, approximately 2,500 physical and 60,000 virtual servers were compromised by the attackers. A very large portion, if not all, of these servers are shared between multiple users to host the websites of more than 1.5 million accounts. In another incident, a total of 70,000 servers from that hosting provider were compromised by Ebury in 2023. Kernel.org, hosting the source code of the Linux kernel, had been a victim of Ebury too.

“Ebury poses a serious threat and a challenge to the Linux security community. There is no simple fix that would make Ebury ineffective, but a handful of mitigations can be applied to minimize its spread and impact. One thing to realize is that it doesn’t only happen to organizations or individuals that care less about security. A lot of very tech-savvy individuals and large organizations are among the list of victims,” concludes Léveillé.

For more technical information and a set of tools and indicators to help system administrators determine whether their systems are compromised by Ebury, read the full white paper “Ebury is alive but unseen: 400k Linux servers compromised for cryptocurrency theft and financial gain”. Make sure to follow ESET Research on Twitter (today known as X) for the latest news from ESET Research.

Ebury deployments per month using two different scales on the Y axis, according to the database of compromised servers maintained by the perpetrators.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

ESET Research: Russia-aligned Turla group likely uses Lunar arsenal to target & spy on European diplomats

  • ESET Research discovered two previously unknown backdoors — which we named LunarWeb and LunarMail — compromising a European ministry of foreign affairs and its diplomatic missions abroad, primarily in the Middle East.
  • ESET researchers attribute these compromises with medium confidence to the infamous Russia-aligned cyberespionage group Turla. The aim of the campaign is cyberespionage.
  • Turla, also known as Snake, has been active since at least 2004, possibly even dating back to the late 1990s. It is believed to be part of the Russian FSB.
  • ESET believes that the Lunar toolset has been in use since at least 2020.
  • Both backdoors employ steganography, a technique in which commands are hidden in images to avoid detection.
BRATISLAVAMay 15, 2024 — ESET Research discovered two previously unknown backdoors — which we named LunarWeb and LunarMail — compromising a European ministry of foreign affairs and its diplomatic missions abroad, primarily in the Middle East. ESET believes that the Lunar toolset has been used since at least 2020 and, given the similarities between the tactics, techniques, and procedures and past activities, ESET researchers attribute these compromises with medium confidence to the infamous Russia-aligned cyberespionage group Turla. The aim of the campaign is cyberespionage. The ESET investigation began with the detection of a loader deployed on an unidentified server, which decrypts and loads a payload from a file. This led ESET researchers to the discovery of a previously unknown backdoor, which ESET named LunarWeb. Subsequently, a similar chain with LunarWeb deployed at a diplomatic mission was detected. Notably, the attacker also included a second backdoor — which ESET named LunarMail — that uses a different method for command and control (C&C) communications. During another attack, ESET observed simultaneous deployments of a chain with LunarWeb at three diplomatic missions of a European country in the Middle East, occurring within minutes of each other. The attacker probably had prior access to the domain controller of the ministry of foreign affairs and utilized it for lateral movement to machines of related institutions in the same network. LunarWeb, deployed on servers, uses HTTP(S) for its C&C communications and mimics legitimate requests, while LunarMail, deployed on workstations, persists as an Outlook add-in and uses email messages for its C&C communications. Both backdoors employ steganography, a technique in which commands are hidden in images to avoid detection. Their loaders can exist in various forms, including trojanized open-source software, demonstrating the advanced techniques used by the attackers. “We observed varying degrees of sophistication in the compromises — for example, the careful installation on the compromised server to avoid scanning by security software contrasted with coding errors and different coding styles of the backdoors. This suggests multiple individuals were probably involved in the development and operation of these tools,” says ESET researcher Filip Jurčacko, who discovered the Lunar toolset. Recovered installation-related components and attacker activity suggest that possible initial compromise happened via spearphishing and abuse of misconfigured network and application monitoring software Zabbix. Furthermore, the attacker already had network access, used stolen credentials for lateral movement, and took careful steps to compromise the server without raising suspicion. In another compromise, researchers found an older malicious Word document, likely from a spearphishing email. LunarWeb collects and exfiltrates information from the system, such as computer and operating system information, a list of running processes, a list of services, and a list of installed security products.  LunarWeb supports common backdoor capabilities, including file and process operations, and running shell commands. On first run, the LunarMail backdoor collects information from recipients’ sent email messages (email addresses). In terms of command capabilities, LunarMail is simpler and features a subset of the commands found in LunarWeb. It can write a file, create a new process, take a screenshot, and modify the C&C communication email address. Both backdoors have the unusual capability of being able to execute Lua scripts. Turla, also known as Snake, has been active since at least 2004, possibly even dating back to the late 1990s. Believed to be part of the Russian FSB, Turla mainly targets high-profile entities such as governments and diplomatic organizations in Europe, Central Asia, and the Middle East. The group is notorious for breaching major organizations, including the US Department of Defense in 2008 and the Swiss defense company RUAG in 2014. For more technical information about the Lunar toolset, read the blogpost “To the Moon and back(doors): Lunar landing in diplomatic missions.” Make sure to follow ESET Research on Twitter (today known as X) for the latest news.

Illustration of an exfiltration email with data hidden in the image

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

ESET included among notable vendors in Mobile Threat Defense Solutions Landscape report

BRATISLAVAMay 9, 2024ESET, a global leader in cybersecurity solutions, has been included in Forrester’s Mobile Threat Defense (MTD) Solutions Landscape report, Q1 2024. Forrester, a respected analyst firm, provides an overview of 16 vendors in the field, including ESET, which, in our opinion, makes ESET a valuable player in this established market.

The importance of mobile malware protection is highlighted in the Forrester’s MTD Solutions Landscape report,1 which states: “Mobile devices are just as vulnerable to attacks as traditional endpoints like laptops and servers, whether through malicious applications, operating system (OS) vulnerabilities, phishing through messaging applications unique to mobile devices, or web-based attacks.” The report also emphasizes the comprehensive capabilities of MTD solutions designed to protect mobile devices with a level of rigor traditionally reserved for enterprises.

This inclusion comes shortly after the successful launch of the ESET’s Mobile Threat Defense module, a testament to ESET’s commitment to advancing mobile security. The module integrates seamlessly with the ESET PROTECT Platform, ensures comprehensive coverage of the mobile fleet attack vector with a one-to-one ratio to endpoints, and is included in all cloud subscription tiers starting from ESET PROTECT Advanced with no increase in price. This integration ensures unified security management and eliminates the need to juggle multiple consoles or platforms.

“The recognition in Forrester’s MTD Solutions Landscape report underscores for us the necessity of robust mobile threat defense in today’s security ecosystem,” explained Jakub Debski, Chief Product Officer at ESET. “With remote work expanding the scope of corporate networks, mobile devices have become prime targets for attackers. Our Mobile Threat Defense module not only addresses traditional threats but also adapts to the unique characteristics and challenges of mobile platforms, offering a solution that is both comprehensive and compliant with the evolving market needs.”

The report outlines three core and five extended use cases that underline the critical focus areas for organizations looking to strengthen their mobile security. Support for remote work, bring your own device policies, and mobile app security has been identified as core use cases, which are primary buyer expectations. Beyond these, the analysts have noted extended use cases like compliance assurance, contractor security, executive protection, and Zero Trust endpoint security. While not all MTD solutions cover these extended areas, they represent growing buyer interests alongside the core functionalities. ESET self-reported the extended use cases of compliance assurance, executive protection, and mobile knowledge worker as the top use cases for which clients select them.

For more information about ESET and its recently launched ESET Mobile Threat Defense module, please read here. The full report is available to Forrester clients with a valid subscription or for purchase.

1Forrester: Mobile Threat Defense Solutions Landscape, Q1 2024. Paddy Harrington and Team. March 18, 2024

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.