VIRUS-NEWS
Angry Birds: Toy Ghouls? new toys
by Kaspersky GERT, Kaspersky Security Services4 Sep 2026 at 10:00am
Kaspersky GERT experts have discovered new backdoors used by the Toy Ghouls group. One version of the backdoor uses the HiveMQ MQTT broker as its command-and-control server; the other uses the Matrix-based Element messenger.
Mirage Kitten targeting aviation and FinTech sectors across the Middle East a...
by Omar Amin1 Sep 2026 at 7:00am
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
ValleyRAT masquerading as adware
by Pavel Bukhtenko31 Aug 2026 at 10:00am
Threat actors are distributing the ValleyRAT backdoor disguised as adware. We analyze the infection chain, from the malicious installer to the final payload.
Threat landscape for industrial automation systems. Q2 2026
by Kaspersky ICS CERT27 Aug 2026 at 10:05am
The report contains statistics on industrial threats for Q2 2026, including ransomware, miners, spyware and other threats that were detected and blocked on industrial control systems.
Exploits and vulnerabilities in Q2 2026
by Alexander Kolesnikov26 Aug 2026 at 10:00am
This report covers statistics on vulnerabilities, exploits, and C2 frameworks in Q2 2026. For the first time ever, we aggregate data on vulnerabilities in open-source AI agents and AI frameworks.
The invisible passenger in your car
by Dmitry Kalinin21 Aug 2026 at 8:00am
Kaspersky expert has discovered new Android malware designed to serve ads and build a proxy botnet. It's delivered through legitimate software for DoFun head units.
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Win...
by Fareed Radzi14 Aug 2026 at 9:00am
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
Armored Likho expands its cyber-espionage toolkit
by Konstantin Isakov13 Aug 2026 at 8:00am
Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.
Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server t...
by Kaspersky11 Aug 2026 at 12:00pm
Kaspersky experts have discovered malicious TrueConf software installers. The Head Mare APT group uses them to deliver the PhantomCore and PhantomGraph backdoors to target systems by exploiting vulnerabilities in an unpatched TrueConf server.
Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 cha...
by GReAT11 Aug 2026 at 10:00am
Project CAV3RN targets Israel with Google Apps Script C2 relays and DNS-based routing. Modular .NET NativeAOT framework blends C2 traffic with legitimate Google services to evade detection.
