Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
ESET

ESET Vendor Cyber Rating & Cyber Score

eset.com

When technology enables progress, ESET is here to protect it. ​​​​​​​Since its beginning, ESET cybersecurity software has empowered people to use IT to improve their lives and grow their businesses. A lot has changed over the three decades of ESET’s existence, but our ambition remains the same. We’ve grown into a global brand, protecting tens of millions of people and hundreds of thousands of companies worldwide. We continue to develop ways to protect the technology that enables progress and strive to make inevitable change a change for the better.​​​​​​​​​​​​​​​​​​​​​​​​​​​​ Visit www.eset.com to learn more.


ESET A.I CyberSecurity Scoring

ESET
Company Information
Website:http://www.eset.com
Employees number:2,007
Number of followers:93,801
NAICS:5112
Industry Type:Software Development
Homepage:eset.com
ESET Risk Score (AI oriented)
Between 0 and 549
logo
ESETSoftware Development
Updated:
03/07/2026
365/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
ESET Global Score (TPRM)
xxxx
logo
ESETSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

ESET
ESETCritical
Current Score
365C (CRITICAL)
01000
5 incidents
-122 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
375Before Incident
JULY 2026
365Before Incident
JUNE 2026
381Before Incident
Cyber Attack
21 Jun 2026ESET
CrowdStrike, SentinelOne, ESET, Microsoft and Kaspersky: Gentlemen Ransomware Builds Modular EDR Killer Suite From Rival Gang Tools

Gentlemen Ransomware Deploys Modular EDR-Killing Framework with Cross-Gang Tools

362After Incident
CRITICAL-19
MICSENKASESECRO1782073479
Gentlemen Ransomware Deploys Modular EDR-Killing Framework with Cross-Gang Tools The Gentlemen ransomware operation has adopted a sophisticated, modular approach to evading endpoint detection and response (EDR) systems, leveraging tools sourced from multiple criminal groups. According to an analysis by cybersecurity firm ESET, the gang’s arsenal includes GentleKiller a custom-built EDR killer with at least eight variants alongside borrowed tools like HexKiller, ThrottleBlood, and HavocKiller, previously used by other ransomware gangs. GentleKiller employs the bring your own vulnerable driver (BYOVD) technique, using eight distinct vulnerable drivers to gain kernel-level privileges. Its target list spans over 400 processes across 48 security vendors, including Microsoft, CrowdStrike, SentinelOne, and ESET itself. The tool impersonates legitimate software, such as Kaspersky and Valorant, and uses commercial packers like Enigma and Themida for obfuscation. The modular design allows affiliates to swap drivers without rewriting core code, complicating defenses static blocklists may catch one variant while leaving others operational. Beyond GentleKiller, the gang incorporates tools from rival groups, including HexKiller (linked to Warlock), ThrottleBlood (used by MesudaLocker and DragonForce), and HavocKiller (seen in multiple ransomware campaigns). This tool-sharing creates redundancy, attribution challenges, and tactical flexibility for affiliates. ESET also identified OxideHarvest, a Rust-based credential stealer likely developed externally. The gang’s targeting strategy includes exploiting FortiGate configurations, as seen in the compromise of Romanian energy provider Oltenia. A SystemBC proxy botnet, comprising over 1,570 corporate hosts, provides persistent access for EDR-killer-assisted attacks. The overlap between SystemBC detections and Gentlemen ransomware activity suggests energy-sector defenders should treat such infections as potential indicators of compromise. ESET’s findings highlight the gang’s operational persistence, with 478 victims documented before the modular framework was fully analyzed. The interchangeable nature of the tools combined with stolen digital signatures and rapid driver swaps makes detection and attribution increasingly difficult. Defenders are advised to audit driver blocklists against all eight GentleKiller variants, flag multi-gang EDR killer signatures in incidents, and harden FortiGate configurations to reduce exposure.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain (ransomware), data exfiltration
IMPACT
Data Compromised: Credentials (via OxideHarvest), potentially sensitive corporate dataSystems Affected: Endpoint detection and response (EDR) systems, corporate hosts (1,570+ via SystemBC botnet)Operational Impact: Disruption of security defenses, potential system encryptionIdentity Theft Risk: High (due to credential theft)
DATA BREACH
Type Of Data Compromised: Credentials, potentially sensitive corporate dataSensitivity Of Data: High (credentials, corporate data)Data Exfiltration: Yes (via OxideHarvest, potential ransomware exfiltration)Data Encryption: Yes (ransomware encryption)
JUNE 2026
707Before Incident
Ransomware
15 Jun 2026ESET
Amadey: Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered

Global Law Enforcement Takedown Disrupts Amadey and StealC Malware Operations

380After Incident
CRITICAL-327
ESE1782332741
Global Law Enforcement Takedown Disrupts Amadey and StealC Malware Operations A coordinated international law enforcement operation, supported by private cybersecurity firms including Bitdefender, Bitsight, ESET, and Microsoft, has dismantled the infrastructure behind the Amadey and StealC malware families. The effort, part of Operation Endgame, targeted cybercriminal "assembly lines" used to deploy ransomware, financial fraud, and attacks on critical infrastructure. Conducted between June 15 and 19, 2026, the operation involved authorities from Belgium, Canada, Denmark, France, Germany, the Netherlands, the U.K., and the U.S. Key outcomes included: - Seizure of 326 servers and 142 domains linked to malware distribution. - Recovery of 27 million stolen login credentials. - Restriction of over $47 million in cryptocurrency assets tied to criminal activity. - Disruption of 15,000 infected WordPress sites used to spread SocGholish malware. ### Amadey: A Persistent Malware Loader Active since October 2018, Amadey operates as a malware-as-a-service (MaaS) loader, sold for $600 per license with an additional $50 per rebuild. Its capabilities include: - Executing commands, downloading payloads, and stealing credentials. - Deploying secondary malware like Lumma Stealer, Vidar Stealer, and RedLine Stealer. - Peaking in activity in 2025, with 11,635 samples distributed up from just 66 in 2019. Amadey’s command-and-control (C2) servers saw a surge in 2023, averaging 5–30 active servers daily, before declining in 2024. The malware avoids execution in Russia, Ukraine, and Belarus by checking system locales. ### StealC: A Versatile Information Stealer First detected in January 2023, StealC is a C++-based stealer sold for $300/month (or $1,000 for six months). It targets: - Browser data (credentials, cookies, autofill entries). - Desktop apps (Discord, Telegram, Steam, Outlook). - Files matching specific naming patterns. Like Amadey, StealC terminates if running in Russia, Ukraine, Belarus, Kazakhstan, or Uzbekistan. A cross-site scripting (XSS) vulnerability in its control panel was patched in February 2026 after being exploited to steal data from affiliates. ### Shared Infrastructure and Global Impact Microsoft reported that Amadey and StealC shared infrastructure, infecting over 140,000 computers worldwide in early May 2026. The company seized control of 18,000 victim devices and shut down 200 malicious C2 domains and IPs. The operation highlights the growing collaboration between public and private sectors to dismantle cybercrime ecosystems, particularly those enabling ransomware and credential theft at scale.
INCIDENT DETAILS -
TYPE
malwareransomwarecredential theft
MOTIVATION
financial gaindata exfiltrationransomware deployment
IMPACT
Financial Loss: $47 million in cryptocurrency assets restrictedData Compromised: 27 million stolen login credentialsSystems Affected: 140,000 computers worldwide, 15,000 infected WordPress sitesOperational Impact: disruption of malware distribution infrastructureIdentity Theft Risk: high
DATA BREACH
login credentialsbrowser dataautofill entriesdesktop app dataNumber Of Records Exposed: 27 millionSensitivity Of Data: high
MAY 2026
706Before Incident
APRIL 2026
705Before Incident
MARCH 2026
723Before Incident
Cyber Attack
11 Mar 2026ESET
Sophos, CrowdStrike, Microsoft, Proton Drive, SentinelOne, Bitdefender, ESET and McAfee: New Avalon Malware Framework Packs CrownX Ransomware Capabilities

New Modular Malware Framework 'Avalon' Unveiled in Sophisticated Phishing Attack

703After Incident
CRITICAL-20
CROMICBITSOPSENPROESEMCA1783117511
New Modular Malware Framework "Avalon" Unveiled in Sophisticated Phishing Attack Cybersecurity researchers have identified a previously unknown modular malware framework, Avalon, distributed via a multi-stage phishing campaign designed to evade traditional security controls. The framework integrates credential theft, lateral movement, remote access, recovery disruption, and ransomware execution with its ransomware component internally dubbed CrownX. The attack begins with a spoofed legal document email directing recipients to a password-protected archive hosted on Proton Drive. Instead of attaching malicious files directly, attackers embedded them within an ISO image, reducing detection at the email layer. When a victim interacts with a document-themed Windows shortcut (Secure Document CA-283505.pdf.lnk) inside the mounted image, it triggers a sequence that deploys Avalon. The shortcut executes an MSBuild project within the ISO, which loads an embedded .NET assembly to disable Event Tracing for Windows (ETW), obscuring forensic visibility. The malware then downloads a next-stage payload over HTTPS to deploy Avalon, which includes an extensive defense evasion subsystem targeting security tools from Microsoft Defender, SentinelOne, CrowdStrike, Sophos, Elastic Endpoint, FortiEDR, ESET, McAfee, and Bitdefender. Avalon’s capabilities include: - Credential harvesting from Chromium-based browsers, Firefox, cryptocurrency wallets (MetaMask, Coinbase Wallet, Exodus, etc.), and apps like Discord, Slack, and Teams. - Data exfiltration to a remote server (helloxcherry[.]com) and command polling for further instructions. - Reconnaissance to prioritize high-value systems for lateral movement. - Ransomware execution using Windows Cryptography API, encrypting files tied to business operations, software development, and virtual infrastructure. - Recovery disruption by terminating the Volume Shadow Copy Service and deleting shadow copies. - Anti-forensic measures, including direct disk manipulation to corrupt partition data or boot records. Researchers note that CrownX represents only the final extortion stage by the time the ransom note appears, the framework has already stolen credentials, established C2 communications, and weakened recovery options. The malware also exhibits signs of AI-assisted development, suggesting lower barriers to entry for threat actors with limited technical expertise. ### AI-Driven Ransomware and Codeless Attacks Emerge In related developments, Sysdig reported the first publicly documented agentic ransomware attack powered by a large language model (LLM). The threat actor, JADEPUFFER, exploited CVE-2025-3248 to gain access to an exposed Langflow instance, executing an automated campaign that adapted in real-time to pivot toward a production database server for extortion. Separately, Palo Alto Networks Unit 42 uncovered an AI-powered malware combining a Telegram bot with a public LLM API (api.groq[.]com) to enable codeless attacks. The malware forwards system details to the attacker’s Telegram bot, then polls the API every five seconds to translate natural language instructions into shell commands eliminating the need for command-line expertise. The sample, uploaded to VirusTotal in March 2026, remains undetected by all engines.
INCIDENT DETAILS -
TYPE
MalwareRansomwarePhishing
MOTIVATION
Financial GainData ExfiltrationExtortion
IMPACT
Data Compromised: Credentials, cryptocurrency wallet data, business documents, software development files, virtual infrastructure filesSystems Affected: Windows systems with Chromium-based browsers, Firefox, cryptocurrency wallets, Discord, Slack, Teams, and security tools from Microsoft Defender, SentinelOne, CrowdStrike, Sophos, Elastic Endpoint, FortiEDR, ESET, McAfee, and BitdefenderOperational Impact: Recovery disruption, encryption of critical files, termination of Volume Shadow Copy ServiceIdentity Theft Risk: High (credential harvesting, PII exposure)
DATA BREACH
CredentialsCryptocurrency wallet dataBusiness documentsSoftware development filesVirtual infrastructure filesSensitivity Of Data: High (PII, financial data, operational files)Data Exfiltration: Yes (to helloxcherry[.]com)Data Encryption: Yes (Windows Cryptography API for ransomware)Personally Identifiable Information: Yes (credentials, wallet data)
FEBRUARY 2026
722Before Incident
JANUARY 2026
721Before Incident
DECEMBER 2025
611Before Incident
NOVEMBER 2025
719Before Incident
OCTOBER 2025
718Before Incident
SEPTEMBER 2025
717Before Incident
JUNE 2024
704Before Incident
Vulnerability
16 Jun 2024ESET
ESET

ToddyCat Exploits ESET Vulnerability to Deliver TCESB Malware

700After Incident
CRITICAL-4
ESE939041025
In an alarming security incident, a threat actor known as ToddyCat exploited a critical vulnerability in ESET's cybersecurity solution to deliver covert malware, identified as TCESB, to Windows devices. This breach was enabled by CVE-2024-11859, which allowed attackers to manipulate the library loading process of ESET's command-line scanner. By positioning a malicious version.dll file, the attackers were able to run their malware, thereby evading detection mechanisms. The impact of this incident could extend to various user groups, as the corrupted solution deployed stealth malware that could disrupt systems, potentially leading to data leaks, reputation damage or more severe consequences if the malware affected critical infrastructure or sensitive targets.
INCIDENT DETAILS -
TYPE
Malware Delivery
IMPACT
Windows devicesSystem disruptionPotential data leaksReputation damageReputation damage
MAY 2024
762Before Incident
Breach
01 May 2024ESET
ESET

Phishing Campaigns Targeting SMBs in Central and Eastern Europe

703After Incident
CRITICAL-59
ESE001080824
In May 2024, significant phishing campaigns targeted SMBs in Central and Eastern European countries like Poland, Romania, and Italy, distributing malware families such as Agent Tesla, Formbook, and Remcos RAT. ESET researchers identified multiple waves of attacks exploiting compromised email accounts and company servers, resulting in over 21,000 users in Poland being impacted. Malicious emails were sent to businesses, with attachments containing ModiLoader for malware delivery. The sophistication of these campaigns indicates an increased cybersecurity threat level for SMBs, with data theft and system compromise as potential outcomes.
INCIDENT DETAILS -
TYPE
Phishing Campaign
MOTIVATION
Data TheftSystem Compromise
IMPACT
Data Compromised: UnknownSystems Affected: Email Accounts and Company Servers

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for ESET ?
?
What was ESET's A.I Rankiteo Cyber Score in July 2026 ?
?
What was ESET's A.I Rankiteo Cyber Score in June 2026 ?
?
What was ESET's A.I Rankiteo Cyber Score in May 2026 ?
?
What was ESET's A.I Rankiteo Cyber Score in April 2026 ?
?
What was ESET's A.I Rankiteo Cyber Score in March 2026 ?
?
What was ESET's A.I Rankiteo Cyber Score in February 2026 ?
?
What was ESET's A.I Rankiteo Cyber Score in January 2026 ?
?
What was ESET's A.I Rankiteo Cyber Score in December 2025 ?
?
What was ESET's A.I Rankiteo Cyber Score in November 2025 ?
?
What was ESET's A.I Rankiteo Cyber Score in October 2025 ?
?
What was ESET's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on ESET's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with ESET ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view ESET's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
ESET Cyber Scoring History | Rankiteo