logo

Securelist by Kaspersky

ID: 7acde381-77f7-5839-9aa3-97396d60a4fa

STIX ID: identity--7acde381-77f7-5839-9aa3-97396d60a4fa

Feed Type: rss

Earliest post: 2023-12-12

Latest post: 2026-08-27

Threat research, malware & APT analyses, and cyber-crime reports from experts — providing data-driven insight on emerging threats, ransomware, phishing, and targeted attacks worldwide.

01/01/2020
08/28/2026
Title Date Published Describes IncidentAuthorVisible
Threat landscape for industrial automation systems. Q2 20262026-08-27TrueKaspersky ICS CERTTrue
Exploits and vulnerabilities in Q2 20262026-08-26TrueAlexander KolesnikovTrue
The invisible passenger in your car2026-08-21TrueDmitry KalininTrue
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit2026-08-14TrueFareed RadziTrue
Armored Likho expands its cyber-espionage toolkit2026-08-13TrueKonstantin IsakovTrue
Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants2026-08-11TrueKasperskyTrue
Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection2026-08-11TrueGReATTrue
IT threat evolution in Q2 2026. Non-mobile statistics2026-08-10TrueAMRTrue
IT threat evolution in Q2 2026. Mobile statistics2026-08-10TrueAnton KivvaTrue
How legitimate cloud platforms enable phishers to bypass MFA2026-08-04TrueOlga AltukhovaTrue
An analysis of incidents at Brazilian educational institutions2026-08-03TrueCristian SouzaTrue
Network Anomaly Detection in KATA2026-07-31TrueArseny Vesnovsky, Valery Akulenko, Dmitry SabadashTrue
OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia2026-07-30TrueSaurabh Sharma, Yaroslav KikelTrue
Toy Ghouls’ new toy: the GenieLocker ransomware2026-07-30TrueFedor Sinitsyn, Yanis ZinchenkoTrue
Mirage Kitten targets Middle East and Africa region with new malware2026-07-28TrueOmar Amin, Vasily BerdnikovTrue
A new extortion cocktail: office printers, small ransoms, and BitLocker2026-07-21TrueEduardo OvalleTrue
New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery2026-07-21TrueGReATTrue
HelloNet campaign — new malicious modules launched through the ViPNet update system2026-07-16TrueKonstantin Isakov, Georgy Kucherin, Anton KarginTrue
GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration2026-07-16TrueNoushin ShababTrue
OkoBot: new sophisticated malware framework targets cryptocurrency users2026-07-15TrueYaroslav KikelTrue
Threat landscape for industrial automation systems. Q1 20262026-07-07TrueKaspersky ICS CERTTrue
When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft website2026-07-06TrueRoman DedenokTrue
Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign2026-07-03TrueKasperskyTrue
Missed incidents, persistent threats, and response gaps: Insights from compromise assessment projects2026-07-02TrueVictor Sergeev, Amged WagehTrue
The SOC Files: ScreenConnect masked as freeware. An inside look at a large-scale campaign2026-07-01TrueDenis KulikTrue
OpenClaw: risks for the users and how to mitigate them2026-07-01TrueKasperskyTrue
ToddyCat: your hidden email assistant. Part 22026-06-30TrueAndrey GunkinTrue
The Gentlemen are knocking: сustom backdoors and evolving tactics2026-06-29TrueFatih Şensoy, Maher YamoutTrue
Beware of the license manager: how a Schneider Electric software vulnerability puts industrial facilities at risk2026-06-26TrueValery AkulenkoTrue
Inside the 2026 SMB threat landscape: From phishing and scams to fake AI tools2026-06-25TrueVasily Kolesnikov, Olga Altukhova, Anna Lazaricheva, Ekaterina BeloborodovaTrue
StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader2026-06-24TrueFareed RadziTrue
A VBScript campaign distributed through WhatsApp deploying RMM software2026-06-22TrueFareed RadziTrue
Dozens of malicious wallpapers found on Steam Workshop: gamers’ accounts at risk2026-06-16TrueMaxim Starodubov, Denis BrylevTrue
From cause to cash: a cross-border look at hacktivist activity2026-06-08TrueKasperskyTrue
Argamal: Malware hidden in hentai games2026-06-03TrueMikhail ReznichenkoTrue
Containers on fire: from container escapes to supply chain attacks2026-06-01TrueAlexander ChudnovTrue
What’s in the container? Analyzing vulnerabilities, risks and protection with Kaspersky Container Security and the KIRA AI assistant2026-05-29TrueYaroslav Shmelev, Anton Kivva, Denis Parinov, Vladimir Kuskov, Yanina Balandyuk-OpalinskayaTrue
Pirates in the crosshairs: how one cybercrime gang has been infecting book, movie, and TV show fans for years2026-05-28TrueKonstantin Krasilnikov, Valery Akulenko, Artem SnegirevTrue
Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload2026-05-22TrueKasperskyTrue
How an image could compromise your Mac: understanding an ExifTool vulnerability (CVE-2026-3102)2026-05-20TrueLucas TayTrue
IT threat evolution in Q1 2026. Mobile statistics2026-05-18TrueAnton KivvaTrue
IT threat evolution in Q1 2026. Non-mobile statistics2026-05-18TrueAMRTrue
Kimsuky targets organizations with PebbleDash-based tools2026-05-14TrueSojun RyuTrue
State of ransomware in 20262026-05-12TrueFabio Assolini, Marc Rivero, Maher Yamout, Darya GorodilovaTrue
CVE-2025-68670: discovering an RCE vulnerability in xrdp2026-05-08TrueDenis Skvortsov, Dmitry ShmoylovTrue
Exploits and vulnerabilities in Q1 20262026-05-07TrueAlexander KolesnikovTrue
OceanLotus suspected of using PyPI to deliver ZiChatBot malware2026-05-06TrueGReATTrue
Websites with an undefined trust level: avoiding the trap2026-05-06TrueLama Saqqour, Anna LarkinaTrue
“Legitimate” phishing: how attackers weaponize Amazon SES to bypass email security2026-05-04TrueRoman DedenokTrue
Silver Fox uses the new ABCDoor backdoor to target organizations in Russia and India2026-04-30TrueAnton Kargin, Vladimir Gursky, Victoria Vlasova, Anna LazarichevaTrue

1–50 of 216