NEW#0001KKaspersky5 days ago12 min▣LLM reporthigh HoneyMyte APT group has upgraded the CoolClient backdoor with a kernel-mode Windows rootkit driver (msagent.sys) that provides process hiding, file and registry protection, and network data filtering via Nsiproxy hooking. The driver is signed with an expired certificate from 2013-2014 issued to 'Nanjing Ranyi Technology Co., Ltd.' and communicates with the user-mode backdoor through IOCTL requests to device \Device\ToolTool. The malware uses DLL sideloading via a legitimate Sangfor application and a multi-stage execution chain with encrypted payloads, establishing persistence through AutoRun registry keys and Windows services.
NEW#0002KKaspersky6 days ago13 min▣LLM reporthigh Armored Likho expanded its cyber-espionage toolkit with a new Rust-based framework called Still Toolkit, comprising Still Sync and Still Audio. Still Sync steals Telegram session data from the tdata folder, authenticates to the victim's Telegram account via the Telegram API, and exfiltrates messages, media, and channel data. Still Audio captures audio from input devices using a custom RMS-based Voice Activity Detection algorithm, encodes recordings with libmp3lame, and sends them to a C2 server. Both modules communicate over gRPC with FlatBuffers serialization, create Windows services for persistence, and share code-level overlap with earlier AquilaRAT samples including the same sysmarker hashing algorithm and Blowfish-ECB dead drop resolver key.
#0003KKaspersky8 days ago12 min▣LLM reporthigh Project CAV3RN is a modular espionage framework targeting Israeli entities. A newly identified communication module (GoogleService.dll) uses DNS A-record responses to select between direct HTTPS and a Google Apps Script relay for each C2 transaction. The DNS infrastructure also supports chunked retrieval and freshness validation of the Google Apps Script deployment ID, enabling operator rotation of the relay channel. A local DLL broker (rnp.dll) masquerades as the RNP OpenPGP library, coordinates modular components, and supports runtime upgrades via directory rescanning.
#0004KKaspersky8 days ago14 min▣LLM reportcritical Head Mare APT group exploited a chain of two vulnerabilities (KLCERT-26-057, KLCERT-26-058) in unpatched TrueConf Server instances to achieve unauthenticated remote code execution as SYSTEM. After gaining elevated privileges, attackers replaced the locale.php file with a web shell, then trojanized the TrueConf client installer to deliver the PhantomCore backdoor to all clients downloading it. A second backdoor, PhantomGraph, uses Microsoft OneDrive as C2 and splits its functionality across two service-installed DLLs to evade EDR detection.
#0005KKaspersky9 days ago8 min▣LLM reporthigh Kaspersky Q2 2026 mobile threat telemetry shows a continued decline in overall mobile attacks to 1.99 million, but banking Trojans remain the dominant threat category at 30.77% of detected applications. Multiple malicious loaders were found on Google Play, including a trojanized PDF reader dropping Anatsa and the Cleanova app using SDK-based installation source telemetry to selectively deliver payloads only to targeted victims. The Creduz banking Trojan family saw a surge in detected packages without corresponding victim telemetry, indicating active development cycles by the threat actors.
#0006KKaspersky9 days ago10 min▣LLM reporthigh Kaspersky's Q2 2026 threat landscape report identifies 400 million blocked web attacks, 71,860 ransomware victims, and 213,003 miner-attacked users. Microsoft disrupted the Fox Tempest malware-signing-as-a-service operation that supplied code-signing certificates to multiple ransomware groups. CISA confirmed active ransomware exploitation of CVE-2026-33825 in Microsoft Defender, and Check Point linked CVE-2026-50751 zero-day exploitation to the Qilin ransomware group. The PayoutsKing group deploys hidden Alpine Linux VMs via QEMU to evade detection, and the FlutterShell macOS backdoor passed Apple notarization while enabling arbitrary payload execution through WebView bridge functions.
#0007KKaspersky10 days ago16 min▣LLM reportcritical The Gentlemen ransomware group operates a RaaS model targeting large corporations and critical infrastructure worldwide. The group gains initial access through internet-exposed VPN/firewall vulnerabilities and stolen credentials, conducts internal reconnaissance using custom and off-the-shelf tools, and deploys a custom Go-based backdoor for C2 prior to ransomware deployment. The ransomware uses GPO-based and PsExec-based lateral movement, BYOVD techniques to disable security software, and hybrid encryption (Curve25519+XChaCha20 in the Go variant, AES256-GCM+RSA in the emerging C variant). A new C-based variant is under active development, indicating the group is expanding its capabilities.
#0008KKaspersky10 days ago10 min▣LLM reporthigh Kaspersky's 2026 SMB threat report identifies a surge in attacks weaponizing trust in AI tools, with malware disguised as popular AI services increasing nearly fivefold year-over-year. Phishing campaigns abuse legitimate third-party platforms (Zoom Docs, OneDrive notifications, Google APIs) to bypass email security and harvest corporate credentials. Dark web initial access brokers disproportionately target SMBs, accounting for over half of all access offers analyzed, as SMBs serve as both direct victims and stepping stones to larger enterprises via trusted relationship attacks.
#0009KKaspersky15 days ago11 min▣LLM reporthigh Threat actors are systematically abusing legitimate cloud PaaS platforms and IPFS gateways to host multi-stage adversary-in-the-middle (AitM) phishing infrastructure that bypasses MFA. The attack chain uses compromised websites as disposable relays, Cloudflare Workers for core phishing content, browser service workers with the Ultraviolet proxy library to intercept all tab network traffic, and Browser-in-the-Browser (BitB) spoofing to display trusted URLs while silently capturing credentials and session tokens. Over 390,000 phishing pages on legitimate cloud platforms were identified in 12 months, with reputation-based blocklists proving ineffective against programmatically generated subdomains on trusted apex domains.
#0010KKaspersky15 days ago11 min▣LLM reporthigh Brazilian educational institutions face ransomware attacks primarily from DragonForce and LockBit 3 variants, with initial access gained through valid accounts, exposed applications, and insider threats. Attackers leverage Potato variants for privilege escalation, AnyDesk and PsExec for remote access and lateral movement, and batch scripts to disable Windows Defender and enable RDP. The use of outdated Windows 10 and unpatched Windows Server 2016 systems increases the attack surface, while shared accounts on multi-user machines enable insider keylogging attacks.
#0011KKaspersky19 days ago9 min▣LLM reportmedium The article details Kaspersky's Network Anomaly Detection (NAD) technology within the KATA platform, focusing on two detection scenarios: Kerberoasting and DNS tunneling via TXT records. NAD uses SQL-based behavioral analytics against network session data in ClickHouse to identify deviations from baseline host behavior, overcoming limitations of traditional signature-based IDS tools that cannot distinguish malicious Kerberos TGS requests or DNS tunneling from legitimate traffic. The approach correlates multiple indirect indicators — anomalous SPN request volume, unusual DNS query patterns, data transfer thresholds — into consolidated alerts with tunable infrastructure-specific variables.
#0012KKaspersky20 days ago11 min▣LLM reporthigh GenieLocker is a custom ransomware family deployed by the Toy Ghouls threat actor since March 2026, targeting Russian organizations primarily in manufacturing. It features Windows and Linux/ESXi variants using libsodium-based XChaCha20-Poly1305 and Curve25519-XSalsa20-Poly1305 cryptography. The Windows build includes anti-debugging, a secret argument for sandbox evasion, process/service termination, and file exclusion lists. The ESXi/Linux build targets /vmfs/volumes, supports daemonization, and modifies the ESXi welcome message. Unlike typical ransomware, no ransom notes are dropped; attackers deliver demands manually. No data exfiltration was observed, consistent with Toy Ghouls' non-double-extortion model.
#0013KKaspersky20 days ago16 min▣LLM reporthigh Kaspersky researchers identified two new backdoors, OctLurk and SilkLurk, used in a coordinated cyber-espionage campaign against government organizations in Central Asia since January 2025. OctLurk deploys via scheduled tasks and Windows services using a loader that decrypts its payload using the victim's C: drive serial number, while SilkLurk uses DLL side-loading of legitimate NVIDIA and Realtek binaries and decrypts payloads using the victim's computer name. Both backdoors support in-memory plugin loading for command shells, file management, keyboard/mouse simulation, and credential theft, with the actor also deploying LurkProxy for network traffic proxying, PlugX as a secondary RAT, and various post-exploitation tools including Impacket secretsdump, keyloggers, and browser password stealers.
#0014KKaspersky22 days ago10 min▣LLM reporthigh Mirage Kitten has expanded its malware arsenal with NightLedger, a Windows backdoor abusing DLL search-order hijacking via a malicious SspiCli.dll, and two WebSocket-based tunneling tools (ArcBridge and BridgeHead) that establish SOCKS5 proxy relays through victim networks. The tools employ anti-analysis techniques such as username-substring checks, enterprise proxy traversal with NTLM/Negotiate authentication, and a shift from Azure-hosted to Cloudflare-backed C2 infrastructure to complicate attribution.
#0015KKaspersky29 days ago12 min▣LLM reporthigh A series of extortion incidents in Latin America leveraged misconfigured internet-exposed services (RDP and MSSQL with xp_cmdshell) to gain initial access, then abused built-in Windows BitLocker to encrypt drives and demand small ransoms. The threat actor 'XEntry Team' deployed multiple legitimate RMM tools for persistence and lateral movement, used GPO to mass-deploy BitLocker encryption across domain-joined systems, and delivered ransom notes through corporate printers. The attacks succeeded due to disabled EPP, ignored security alerts, and inadequate incident response procedures.
#0016KKaspersky29 days ago12 min▣LLM reporthigh Project CAV3RN, a cyberespionage framework attributed to OilRig (APT34) with low confidence, has introduced a new .NET Native AOT communication module (AzureCommunication.dll) that abuses Microsoft Graph API to exchange C2 commands and results through Outlook calendar events scheduled in 2050. The module authenticates to Microsoft Entra ID using hardcoded application credentials and a compromised Israeli law firm's mailbox. When Graph authentication fails, it falls back to a novel DNS AAAA-based recovery mechanism using cloudlanecdn.com, where IPv6 address bytes encode replacement configuration values (TenantId, ClientId, ClientSecret, UserEmail) in 14-byte fragments. All command and result data is protected with RSA-OAEP-SHA256 and AES-256-GCM encryption.
#0017KKasperskyabout 1 month ago12 min▣LLM reporthigh The HelloNet campaign is an active APT operation targeting large Russian organizations through the ViPNet secure networking software suite. Attackers achieve persistence by placing a malicious wtsapi32.dll in the ViPNet Update System directory, which is sideloaded by itcsrvup64.exe at OS startup. The loader (HelloInjector) injects into svchost.exe and deploys a modular toolkit including a network proxy, command executor, log cleaner, and a Rust-based backdoor. The campaign uses renamed PuTTY/Plink utilities for SSH reverse tunneling to C2 servers and employs IOCTL hooking to evade user-mode security solutions.
#0018KKasperskyabout 1 month ago11 min▣LLM reporthigh The GoSerpent campaign is a sophisticated, multi-stage attack targeting government and diplomatic entities in Southeast Asia since at least 2021, with evolved variants deployed through 2026. The Go-based GoSerpent backdoor establishes persistent access and deploys ThumbcacheService for document collection, Mimikatz and QuarksDumpLocalHash for credential dumping, and later stages use Stowaway RAT and TmcLoader/TmcPayload to exfiltrate collected data via network shares using stolen credentials. The tight integration between collection, credential theft, and exfiltration components demonstrates advanced operational planning and long-term intelligence gathering objectives.
#0019KKasperskyabout 1 month ago13 min▣LLM reporthigh Kaspersky identified OkoBot, a sophisticated multi-stage malware framework delivered via the TookPS PowerShell downloader and orchestrated over an attacker-controlled SSH tunnel, targeting cryptocurrency users. The framework comprises over 20 interconnected payloads that perform UAC bypass, RDP hijacking, browser-extension based credential theft (Rilide), hardware-wallet seed-phrase phishing (SeedHunter), keylogging, and screen/video capture (OkoSpyware), all coordinated through a plugin dispatcher communicating over HTTP/HTTPS C2 channels. The campaign has been active since at least March 2025, continues to evolve its tooling, and shows indicators (geoblocking, Russian code comments, use of Rilide) consistent with Russian-speaking cybercriminal operators.
#0020KKasperskyabout 1 month ago4 min▣LLM reportmedium Kaspersky's Q1 2026 ICS threat landscape report indicates a continued overall decline in malware blocked on industrial automation systems, reaching 19.6%. However, specific regions like Southern Europe and industries like biometric systems saw notable increases in threats, particularly from malicious scripts, phishing, and spyware. The report highlights the persistent risk to OT environments from common threat vectors like internet browsing and email.