;
;

Securelist

Angry Birds: Toy Ghouls’ new toys

Kaspersky GERT experts have discovered new backdoors used by the Toy Ghouls group. One version of the backdoor uses the HiveMQ MQTT broker as its c...
Posted on 4 September 2026 | 10:00 am

Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set

Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat i...
Posted on 1 September 2026 | 7:00 am

ValleyRAT masquerading as adware

Threat actors are distributing the ValleyRAT backdoor disguised as adware. We analyze the infection chain, from the malicious installer to the fina...
Posted on 31 August 2026 | 10:00 am

Threat landscape for industrial automation systems. Q2 2026

The report contains statistics on industrial threats for Q2 2026, including ransomware, miners, spyware and other threats that were detected and bl...
Posted on 27 August 2026 | 10:05 am

Exploits and vulnerabilities in Q2 2026

This report covers statistics on vulnerabilities, exploits, and C2 frameworks in Q2 2026. For the first time ever, we aggregate data on vulnerabili...
Posted on 26 August 2026 | 10:00 am

The invisible passenger in your car

Kaspersky expert has discovered new Android malware designed to serve ads and build a proxy botnet. It's delivered through legitimate software for ...
Posted on 21 August 2026 | 8:00 am

APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit

Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network conne...
Posted on 14 August 2026 | 9:00 am

Armored Likho expands its cyber-espionage toolkit

Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Te...
Posted on 13 August 2026 | 8:00 am

Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants

Kaspersky experts have discovered malicious TrueConf software installers. The Head Mare APT group uses them to deliver the PhantomCore and PhantomG...
Posted on 11 August 2026 | 12:00 pm

Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection

Project CAV3RN targets Israel with Google Apps Script C2 relays and DNS-based routing. Modular .NET NativeAOT framework blends C2 traffic with legi...
Posted on 11 August 2026 | 10:00 am