Skip to content

Lazarus misuses legitimate security software in a supply-chain attack in South Korea, ESET Research discovers

BRATISLAVA – ESET researchers recently discovered attempts to deploy Lazarus malware via a supply-chain attack (on less secure parts of the supply network) in South Korea. In order to deliver its malware, the attackers used an unusual supply-chain mechanism, abusing legitimate South Korean security software and digital certificates stolen from two different companies. The attack was made easier for Lazarus since South Korean internet users are often asked to install additional security software when visiting government or internet banking websites.

“To understand this novel supply-chain attack, you should be aware that WIZVERA VeraPort, referred to as an integration installation program, is a South Korean application that helps manage such additional security software. When WIZVERA VeraPort is installed, users receive and install all necessary software required by a specific website. Minimal user interaction is required to start such software installation,” explains Anton Cherepanov, ESET researcher who led the investigation into the attack. “Usually this software is used by government and banking websites in South Korea. For some of these websites it’s mandatory to have WIZVERA VeraPort installed,” adds Cherepanov.

Additionally, the attackers used illegally obtained code-signing certificates in order to sign the malware samples. Interestingly, one of these certificates was issued to the U.S. branch of a South Korean security company. “The attackers camouflaged the Lazarus malware samples as legitimate software. These samples have similar file names, icons and resources as legitimate South Korean software,” says Peter Kálnai, ESET researcher who analyzed the Lazarus attack with Cherepanov. “It’s the combination of compromised websites with WIZVERA VeraPort support and specific VeraPort configuration options that allows attackers to perform this attack,” adds Kálnai.

ESET Research has strong indications to attribute the attack to Lazarus, as it is a continuation of what KrCERT has called Operation BookCodes, attributed to Lazarus by some in the cybersecurity research community. The other reasons are typical toolset characteristics; detection (many tools are already flagged as NukeSped by ESET); the fact that the attack took place in South Korea, where Lazarus is known to operate; the unusual and custom nature of the intrusion and encryption methods used; and the setup of network infrastructure.

It must be noted that the Lazarus toolset is extremely broad, and ESET believes there are numerous subgroups. Unlike toolsets used by some other cybercriminal groups, none of the source code of any Lazarus tools has ever been disclosed in a public leak.

For more technical details about the latest Lazarus supply-chain attack, read the blogpost “Lazarus supply-chain attack in South Korea” on WeLiveSecurity. Make sure to follow ESET Research on Twitter for the latest news from ESET Research.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

Scale Computing HCI: Improving Performance for Remote Workers from the Data Center to the Edge

INDIANAPOLISNovember 10, 2020Scale Computing, a market leader in edge computing, virtualization and hyperconverged solutions, has introduced new HC3 infrastructure appliances that deliver the extra processing power of Nvidia GPUs. For power-users on virtual desktops or computing-intensive applications for design or analytics, the HC1250DFG and HC5250DFG appliances engage high-performance GPUs to provide increased speed and processing efficiency. Scale Computing is the only technology provider delivering high performance applications from the data center to the edge on the same software platform and interface.

As remote work becomes a long term reality, organizations continue to execute on getting systems in place to support all remote users, whether they leverage applications in the cloud or work with very high performance applications that require dedicated GPU and high frame buffer requirements for remote users hosted on premises. These HC3 hyperconverged appliances are designed to enhance support for performance-intensive use cases such as high density Virtual Desktop Infrastructure (VDI) deployments, 3D Imaging/Modeling, Analytics, Artificial Intelligence, and GIS. With flexible deployment options from one appliance to clusters of multiple appliances, these appliances provide a highly-available, high-performance, hyperconverged virtualization platform.

The new HC3 infrastructure appliances delivering the superior processing power from Nvidia GPUs join other recently introduced HCI appliances designed to meet the needs for performance computing for both the enterprise and the SMB and from the core data center to the edge.

  • The HC3250DF stands out from other HCI solutions designed for performance computing with its ease of use, and brings a high amount of speed, density, throughput, and power to enable VDI for many more users per node while keeping future growth in focus. Unlike more complex infrastructure solutions that try to emulate classic SAN storage infrastructure, the Scale Computing HC3250DF is easier to deploy, manage, scale out, and its NVMe storage architecture requires no manual configuration and consumes less system RAM, resulting in more RAM being available to virtual machines and their applications.
  • The HE150 appliance is a small, all-flash, NVMe storage-based compute appliance that delivers all of the simplicity, efficiency, and enterprise-ready virtualization associated with Scale Computing’s HC3 platform. Built specifically for sites that need highly available infrastructure, the HE150 can be deployed almost anywhere, without requiring a rack or server closet. Taking up only the space needed to stack three smartphones, it also includes high availability clustering, rolling upgrades and integrated data protection.

“Enterprise and SMB customers have a need for performance-intensive use cases, both in their data centers and at the edge,” commented Jeff Ready, CEO and co-founder, Scale Computing. “Scale Computing customers now don’t have to choose different platforms to manage their data center and edge computing needs, either for on site or remote workers The HC3 platform is able to handle any application needs necessary.”

All Scale Computing HC3 appliances feature intelligent automation for self-healing and high availability to keep clusters running through component and appliance failures, as well as integrated disaster recovery capabilities to protect data and workloads to remote sites for fast failover and recovery. These capabilities enable applications to achieve maximum uptime even when local IT resources and staff are scarce, making the HC1250DFG and HC5250DFG appliances ideal application platforms for core data center to edge computing use cases for retail, industrial, transportation, manufacturing, finance, healthcare, education, remote office/back office, and mobile platforms.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Scale Computing 
Scale Computing is a leader in edge computing, virtualization, and hyperconverged solutions. Scale Computing HC3 software eliminates the need for traditional virtualization software, disaster recovery software, servers, and shared storage, replacing these with a fully integrated, highly available system for running applications. Using patented HyperCore™ technology, the HC3 self-healing platform automatically identifies, mitigates, and corrects infrastructure problems in real-time, enabling applications to achieve maximum uptime. When ease-of-use, high availability, and TCO matter, Scale Computing HC3 is the ideal infrastructure platform. Read what our customers have to say on Gartner Peer Insights, Spiceworks, TechValidate and TrustRadius.

ESET receives the Via Bona Slovakia 2019 award in two categories

Bratislava – Every year, the Pontis Foundation awards the Via Bona award for exceptional projects and socially responsible companies that change Slovakia for the better. In the 20th anniversary of this award, ESET managed to win in two categories: Responsible Large Company and Good Partner of the Community.

The Via Bona Slovakia award has been given by the Pontis Foundation since 1998 to small and large companies that inspire other companies with their activities. The winners of this prestigious award are companies that change life in Slovakia for the better with their projects and responsible approaches to business. The award in the main category Responsible Large Company for 2019 was acquired by ESET mainly for demonstrating long-term ethical values ​​in our business model and contributing to the popularization of science and research in Slovakia.

“ESET is often cited as an example of a success story of a Slovak company that established itself abroad. We are aware of the responsibility that comes with that, especially at home in Slovakia. We do not choose an easier path. We support areas that have been neglected or overlooked for a long time. At the same time, we strive to be a voice that can be heard when needed. When, as a country, we are going through difficult times, it is desirable that the representatives of companies express themselves and stand out as voices of reason. And I hope that we have people, companies and organizations in Slovakia who really care about the success and fate of Slovakia,” responded ESET CEO Richard Marko in his thank-you speech for the award.

ESET also became the winner of the Good Partner of the Community category for our investment in the popularization and development of Slovak science. Supporting education, science and research are areas that ESET has long been involved in. It is these areas that help Slovakia become a modern and successful country. Therefore, through the ESET Foundation, it created the ESET Science Award, which aims to increase the social status of science and scientists in Slovakia. In October 2020, the second year of the ESET Science Award took place with the participation of the world-famous physicist and Nobel Prize winner, Professor Kip Thorne, who was chairman of a prestigious international commission.

“I thank both the expert jury and the employees of ESET, who are the main reason for our success. It is especially thanks to them that we can celebrate this award. I would also like to wish Slovakia success, because I think it has a positive future ahead of it,” concluded Richard Marko.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

ESET Research discovers ModPipe, backdoor targeting POS software used by thousands of restaurants, hotels

BRATISLAVA – ESET researchers have discovered ModPipe, a modular backdoor that gives its operators access to sensitive information stored in devices running ORACLE MICROS Restaurant Enterprise Series (RES) 3700 POS (point-of-sale) – a management software suite used by hundreds of thousands of bars, restaurants, hotels and other hospitality establishments worldwide. The majority of the identified targets were from the United States.

What makes the backdoor distinctive are its downloadable modules and their capabilities, as it contains a custom algorithm designed to gather RES 3700 POS database passwords by decrypting them from Windows registry values. This shows that the backdoor’s authors have deep knowledge of the targeted software and opted for this sophisticated method instead of collecting the data via a simpler yet “louder” approach, such as keylogging. Exfiltrated credentials allow ModPipe’s operators access to database contents, including various definitions and configuration, status tables and information about POS transactions.

“However, based on the documentation of RES 3700 POS, the attackers should not be able to access some of the most sensitive information – such as credit card numbers and expiration dates – which is protected by encryption. The only customer data stored in the clear and thus available to the attackers should be cardholder names,” cautions ESET researcher Martin Smolár, who discovered ModPipe.

“Probably the most intriguing parts of ModPipe are its downloadable modules. We’ve been aware of their existence since the end of 2019, when we first found and analyzed its basic components,” explains Smolár.

Downloadable modules:

  • GetMicInfo targets data related to the MICROS POS, including passwords tied to two database usernames predefined by the manufacturer. This module can intercept and decrypt these database passwords, using a specifically designed algorithm.
  • ModScan 2.20 collects additional information about the installed MICROS POS environment on the machines by scanning selected IP addresses.
  • ProcList with main purpose is to collect information about currently running processes on the machine.

“ModPipe’s architecture, modules and their capabilities also indicate that its writers have extensive knowledge of the targeted RES 3700 POS software. The proficiency of the operators could stem from multiple scenarios, including stealing and reverse engineering the proprietary software product, misusing its leaked parts or buying code from an underground market,” adds Smolár.

To keep the operators behind ModPipe at bay, potential victims in the hospitality sector as well as any other businesses using the RES 3700 POS are advised to:

  • Use the latest version of the software.
  • Use it on devices that run updated operating system and software.
  • Use reliable multilayered security software that can detect ModPipe and similar threats.

For more technical details about ModPipe, read “Hungry for data, ModPipe backdoor targets popular POS software used in hospitality sector,” a blogpost on WeLiveSecurity. Make sure to follow ESET Research on Twitter for the latest news from ESET Research.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

Portnox Achieves a Microsoft Gold Cloud Platform Competency

Portnox demonstrates best-in-class capability and market leadership through demonstrated technology success and customer commitment.


NEW YORK, NY – November 4, 2020 – Portnox, a fully cloud-delivered network access control (NAC) provider, today announced it has attained a Gold Cloud Platform competency, demonstrating a “best-in-class” ability and commitment to meet Microsoft Corp. customers’ evolving needs in today’s mobile-first, cloud-first world and distinguishing itself within Microsoft’s partner ecosystem.

To earn a Microsoft Gold competency, partners must successfully complete exams (resulting in Microsoft Certified Professionals) to prove their level of technology expertise, and then designate these certified professionals uniquely to one Microsoft competency, ensuring a certain level of staffing capacity. They also must submit customer references that demonstrate successful projects, meet a performance (revenue and or consumption/usage) commitment (for most Gold competencies), and pass technology and/or sales assessments.

The cloud-delivered CLEAR NAC platform from Portnox is designed to help partners capitalize on the growing demand for infrastructure and software-as-a-service (SaaS) solutions built on Microsoft Azure. With built-in scalability, no on-site hardware, multitenancy and other benefits, the platform allows Microsoft partners to empower their customers by eliminating the traditional complexities associated with on-premises NAC.

“This Microsoft Gold Cloud Platform competency showcases our expertise in and commitment to today’s technology market and demonstrates our deep knowledge of Microsoft’s products and services,” said Ofer Amitai, CEO at Portnox “We plan to accelerate our customers’ success by serving as technology advisors for their business demands.”

“By achieving a Gold competency, partners have demonstrated the highest, most consistent capability and commitment to the latest Microsoft technology,” said Gavriella Schuster, corporate vice president, One Commercial Partner (OCP) at Microsoft Corp. “These partners have a deep expertise that puts them in the top of our partner ecosystem, and their proficiency will help customers drive innovative solutions.”

Cloud Platform

The Cloud Platform competency is designed for partners to capitalize on the growing demand for infrastructure and software-as-a-service (SaaS) solutions built on Microsoft Azure. Differentiate your company with the Cloud Platform competency, and you will be eligible for Signature Cloud Support, Azure deployment planning services, Azure sponsored credit, direct partner support, eligibility to deploy certain on-premises, internal use software on Microsoft Azure, and access to the cloud platform roadmap.

The Microsoft Partner Network helps partners strengthen their capabilities to showcase leadership in the marketplace on the latest technology, to better serve customers and to easily connect with one of the most active, diverse networks in the world.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Portnox
Portnox provides simple-to-deploy, operate and maintain network access control, security and visibility solutions. Portnox software can be deployed on-premises, as a cloud-delivered service, or in hybrid mode. It is agentless and vendor-agnostic, allowing organizations to maximize their existing network and cybersecurity investments. Hundreds of enterprises around the world rely on Portnox for network visibility, cybersecurity policy enforcement and regulatory compliance. The company has been recognized for its innovations by Info Security Products Guide, Cyber Security Excellence Awards, IoT Innovator Awards, Computing Security Awards, Best of Interop ITX and Cyber Defense Magazine. Portnox has offices in the U.S., Europe and Asia. For information visit http://www.portnox.com, and follow us on Twitter and LinkedIn.。