VIRUS-NEWS

A new extortion cocktail: office printers, small ransoms, and BitLocker

by Eduardo Ovalle
21 Jul 2026 at 1:00pm
We cover two recent cases of BitLocker extortion using RDP, MSSQL, RMM tools, web shells, and printers. The story includes TTPs and recommendations.

New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA ...

by GReAT
21 Jul 2026 at 8:40am
Kaspersky GReAT experts describe a new Project CAV3RN C2 module. It uses Outlook calendar for communication via Microsoft Graph and has a backup connection via DNS AAAA responses.

HelloNet campaign ? new malicious modules launched through the ViPNet update ...

by Konstantin Isakov, Georgy Kucherin, Anton Kargin
16 Jul 2026 at 1:05pm
We identified targeted infection attempts against large Russian organizations using the ViPNet update system (a software suite for creating secure networks).

GoSerpent: a persistent threat evolves with sophisticated data collection and...

by Noushin Shabab
16 Jul 2026 at 12:00pm
Two-phase attacks with the GoSerpent backdoor, Stowaway RAT, ThumbcacheService and other tools aim to steal data from government entities in Southeast Asia.

OkoBot: new sophisticated malware framework targets cryptocurrency users

by Yaroslav Kikel
15 Jul 2026 at 10:00am
Kaspersky GReAT experts dissect the new OkoBot campaign targeting cryptocurrency users. This complex framework employs TookPS, exfiltrates seed phrases, monitors Chromium-based browsers, and installs various malware strains, including the Rilide stealer.

Threat landscape for industrial automation systems. Q1 2026

by Kaspersky ICS CERT
7 Jul 2026 at 10:00am
This report contains industrial threat statistics for Q1 2026, including industrial threat distribution by type, source, region and industry.

When checking the URL isn?t enough: a Device Code Phishing attack via a Micro...

by Roman Dedenok
6 Jul 2026 at 9:00am
The OAuth 2.0 Device Authorization Grant specification was designed to streamline authentication for Smart TVs, IoT devices, and printers. Today, threat actors are weaponizing it.

Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign

by Kaspersky
3 Jul 2026 at 10:00am
An inside look at the active Armored Likho APT campaign. The attackers are using spear-phishing, AI-generated loaders, and a new Python-based tool, BusySnake Stealer, to target organizations in Russia, Kazakhstan, and Brazil.

Missed incidents, persistent threats, and response gaps: Insights from compro...

by Victor Sergeev, Amged Wageh
2 Jul 2026 at 9:00am
Kaspersky Compromise Assessment specialists analyze trends from the service's 2025 projects and provide tips on how to enhance your organization's security.

The SOC Files: ScreenConnect masked as freeware. An inside look at a large-sc...

by Denis Kulik
1 Jul 2026 at 10:00am
Kaspersky experts have uncovered a malicious network infrastructure for delivering AsyncRAT. The Trojan is dropped via compromised ScreenConnect software. In this post, we break down the infection chain and analyze the C2 infrastructure.

powered by dotcombinat



 

TOP Referrer

spamfan.de
apple.com
dotcombinat.net

TOP Downloads

Mac OSX Widget
Screensaver
Flash-Code

   

Spam-O-Shirts

spam shirt

Partner Sites

spamfan.de
apple.com
dotcombinat.net
protectpiracy.de
berlinshirts.de