{"id":8647,"date":"2024-10-24T12:00:00","date_gmt":"2024-10-24T09:00:00","guid":{"rendered":"https:\/\/blog.eset.ee\/et\/?p=8647"},"modified":"2026-06-14T19:41:26","modified_gmt":"2026-06-14T16:41:26","slug":"eset-research-podcast-cosmicbeetle","status":"publish","type":"post","link":"https:\/\/blog.eset.ee\/et\/en\/2024\/10\/24\/eset-research-podcast-cosmicbeetle\/","title":{"rendered":"ESET Research Podcast: CosmicBeetle"},"content":{"rendered":"<p>Some cybercriminal groups are sophisticated, create advanced schemes, cooperate with other attackers and do everything to stay under the radar. Then there are threat actors like CosmicBeetle \u2013 they lack the necessary skills set, write crude malware, yet still compromise interesting targets, and achieve \u201cstealth\u201d by using odd, impractical and overcomplicated techniques.<\/p>\n<p>Our guest, ESET senior malware researcher<a href=\"https:\/\/www.welivesecurity.com\/en\/our-experts\/jakub-soucek\/\"> Jakub Sou\u010dek<\/a>, talks about his investigation into CosmicBeetle\u2019s toolkit written in Delphi, and the fact that their malware is controlled via graphical user interface (GUI) with buttons and text fields necessary to set up, control and run any attack on victims\u2019 devices.<\/p>\n<p>Discussing further with ESET Research Podcast host and Distinguished Researcher <a href=\"https:\/\/www.welivesecurity.com\/en\/our-experts\/aryeh-goretsky\/\">Aryeh Goretsky<\/a>, Jakub shared his view of CosmicBeetle\u2019s encryption routine, information about their victimology, and details of their \u201cinvolvement\u201d with high-profile gangs such as LockBit and RansomHub.<\/p>\n<p>For details on how this crude and clumsy threat actor, whose malicious tools are \u201criddled with bugs\u201d, achieved to penetrate any of its targets, listen to this ESET Research Podcast episode. To read more about activities of CosmicBeetle or other cybercriminal and state-aligned actors, follow ESET Research on <a href=\"https:\/\/twitter.com\/esetresearch\">X (formerly known as Twitter)<\/a> and check out our latest <a href=\"https:\/\/www.welivesecurity.com\/eset-research\/index.html\">blogposts<\/a> and <a href=\"https:\/\/www.welivesecurity.com\/white-papers\/index.html\">white papers<\/a>.<\/p>\n<p>If you like what you hear, subscribe for more on <a href=\"https:\/\/open.spotify.com\/show\/1WDjY2A3A3s5FKycrOVkhg\">Spotify<\/a>, <a href=\"https:\/\/podcasts.apple.com\/us\/podcast\/eset-research-podcast\/id1596306608\">Apple Podcasts<\/a>, or <a href=\"https:\/\/esetresearch.podbean.com\/\">PodBean<\/a>.<\/p>\n<\/p>\n<p class=\"wls-source\"><a href=\"https:\/\/www.welivesecurity.com\/en\/podcasts\/eset-research-podcast-cosmicbeetle\/\" rel=\"nofollow noopener\" target=\"_blank\">Read the full analysis on WeLiveSecurity \u2192<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Learn how a rather clumsy cybercrime group wielding buggy malicious tools managed to compromise a number of SMBs in various parts of the world<\/p>\n","protected":false},"author":5,"featured_media":8648,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2914],"tags":[],"class_list":["post-8647","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-media"],"acf":[],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/8647","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/comments?post=8647"}],"version-history":[{"count":1,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/8647\/revisions"}],"predecessor-version":[{"id":9307,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/8647\/revisions\/9307"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/media\/8648"}],"wp:attachment":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/media?parent=8647"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/categories?post=8647"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/tags?post=8647"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}