Kaspersky Securelist

securelist.com

Imported from official source

Kaspersky Securelist — publications from its own official source.

Type
Company
Scope
RU · national
Website
securelist.com
Feed
Atom

Publications 12

  1. MacSync under the microscope: new delivery methods and a new payload

    We look at a new version of the MacSync macOS stealer with a backdoor module that targets crypto enthusiasts and developers.

  2. Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO

    Kaspersky GERT experts dive into the technical incident analysis of PAYLOAD ransomware: an encryptionless, binary-less operation that abused Active Directory mechanisms for managing Group Policy Ob...

  3. The Odyssey and Trojans again: MovieReaper attacks users in multiple countries through compromised torrents

    Kaspersky experts have discovered a new MovieReaper campaign. The multi-stage Trojan spreads through movie torrents, such as The Odyssey, and uses the Solana blockchain to hide its C2 infrastructure.

    Cybersecurity 2 versions
  4. NightEagle targets Russian companies

    Kaspersky GERT experts have uncovered a new campaign by the NightEagle APT, featuring the GhostContainer backdoor and tools hosted on GitHub. The group is also exploiting vulnerabilities in Active ...

  5. Angry Birds: Toy Ghouls’ new toys

    Kaspersky GERT experts have discovered new backdoors used by the Toy Ghouls group. One version of the backdoor uses the HiveMQ MQTT broker as its command-and-control server; the other uses the Matr...

  6. Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set

    Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.

  7. ValleyRAT masquerading as adware

    Threat actors are distributing the ValleyRAT backdoor disguised as adware. We analyze the infection chain, from the malicious installer to the final payload.

  8. Threat landscape for industrial automation systems. Q2 2026

    The report contains statistics on industrial threats for Q2 2026, including ransomware, miners, spyware and other threats that were detected and blocked on industrial control systems.

  9. Exploits and vulnerabilities in Q2 2026

    This report covers statistics on vulnerabilities, exploits, and C2 frameworks in Q2 2026. For the first time ever, we aggregate data on vulnerabilities in open-source AI agents and AI frameworks.

  10. The invisible passenger in your car

    Kaspersky expert has discovered new Android malware designed to serve ads and build a proxy botnet. It's delivered through legitimate software for DoFun head units.

  11. APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit

    Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.

  12. Armored Likho expands its cyber-espionage toolkit

    Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.