VIRUS-NEWS
How legitimate cloud platforms enable phishers to bypass MFA
by Olga Altukhova4 Aug 2026 at 12:00pm
We cover a cloud-based AitM attack scenario leveraging service workers and Ultraviolet, and provide detailed phishing hosting statistics across platforms like Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS.
An analysis of incidents at Brazilian educational institutions
by Cristian Souza3 Aug 2026 at 1:00pm
Kaspersky expert provides statistics and details on several incident response cases at educational institutions in Brazil, as well as tips for schools and universities on how to stay safe.
Network Anomaly Detection in KATA
by Arseny Vesnovsky, Valery Akulenko, Dmitry Sabadash31 Jul 2026 at 10:00am
An analysis of how Network Anomaly Detection (NAD) rules work within Kaspersky Anti Targeted Attack, using Kerberoasting and DNS tunneling attacks as examples.
OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage ...
by Saurabh Sharma, Yaroslav Kikel30 Jul 2026 at 11:00am
Our experts discovered OctLurk and SilkLurk, backdoors operating primarily in memory, targeting Central Asia. They inject plugins to launch shells, scan networks, dump credentials, and keylogging.
Toy Ghouls? new toy: the GenieLocker ransomware
by Fedor Sinitsyn, Yanis Zinchenko30 Jul 2026 at 8:00am
Kaspersky experts dissect GenieLocker: new custom ransomware variants for Windows, Linux, and ESXi systems. We found this family in attacks by Toy Ghouls, a financially motivated extortion group.
Mirage Kitten targets Middle East and Africa region with new malware
by Omar Amin, Vasily Berdnikov28 Jul 2026 at 8:00am
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
A new extortion cocktail: office printers, small ransoms, and BitLocker
by Eduardo Ovalle21 Jul 2026 at 1:00pm
We cover two recent cases of BitLocker extortion using RDP, MSSQL, RMM tools, web shells, and printers. The story includes TTPs and recommendations.
New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA ...
by GReAT21 Jul 2026 at 8:40am
Kaspersky GReAT experts describe a new Project CAV3RN C2 module. It uses Outlook calendar for communication via Microsoft Graph and has a backup connection via DNS AAAA responses.
HelloNet campaign: new malicious modules launched through the ViPNet update s...
by Konstantin Isakov, Georgy Kucherin, Anton Kargin16 Jul 2026 at 1:05pm
We identified targeted infection attempts against large Russian organizations using the ViPNet update system (a software suite for creating secure networks).
GoSerpent: a persistent threat evolves with sophisticated data collection and...
by Noushin Shabab16 Jul 2026 at 12:00pm
Two-phase attacks with the GoSerpent backdoor, Stowaway RAT, ThumbcacheService and other tools aim to steal data from government entities in Southeast Asia.
