ESET Highlights 5 High‑Impact Malware Families Discovered in 2019
What Happened — ESET’s Antimalware Day 2019 report catalogued five malware families that surfaced in 2019:
* Machete – a spear‑phishing espionage tool targeting government agencies in Latin America;
* Android/Filecoder.C – ransomware encrypting mobile files and extorting victims;
* Android/FakeApp.KP – a credential‑stealing app that bypassed Google’s SMS‑2FA restrictions;
* Varenyky – a sextortion campaign using macro‑enabled documents to capture screenshots;
* KRACK‑vulnerable Wi‑Fi implementations in Amazon Echo and Kindle devices, still exploitable two years after disclosure.
Why It Matters for Trust & Control Assurance
- These campaigns illustrate the exact scenarios a continuous security‑awareness program is built to detect, train against, and document as evidence of due diligence.
- Persistent vulnerabilities (e.g., KRACK) underscore the need for systematic patch‑management controls and verifiable remediation records.
- Credential‑theft techniques that sidestep SMS‑2FA highlight the importance of layered authentication policies and regular control testing.
Who Is Affected – Government ministries, law‑enforcement and education bodies; financial‑services platforms (cryptocurrency exchanges); mobile‑device users; any organization deploying Wi‑Fi‑enabled IoT devices.
Recommended Actions
- Map phishing‑resistance, credential‑management, and patch‑management controls to your audit framework and collect evidence of training completion and remediation.
- Deploy endpoint detection and response (EDR) solutions that can surface the listed malware behaviors.
- Conduct periodic phishing simulations and security‑awareness refreshers, especially around macro‑based documents and SMS‑2FA bypass techniques.
Source: ESET Antimalware Day 2019 Press Release
Technical Notes
- Machete – spear‑phishing attachment; capabilities: screenshot, keylogging, clipboard access, file encryption, geolocation.
- Android/Filecoder.C – ransomware encrypts files, sends ransom demand in Bitcoin; distribution via forums.
- Android/FakeApp.KP – reads on‑screen notifications to harvest one‑time passwords, bypassing Google’s SMS‑2FA hardening.
- Varenyky – macro‑enabled Office document; records screen to obtain compromising images for extortion.
- KRACK – Wi‑Fi key reinstallation attack; enables DoS, traffic interception, credential capture on vulnerable Echo/Kindle devices.
Source: same as above