VIRUS-NEWS
MacSync under the microscope: new delivery methods and a new payload
by Sergey Puzan24 Sep 2026 at 10:00am
We look at a new version of the MacSync macOS stealer with a backdoor module that targets crypto enthusiasts and developers.
Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO
by Ahmad Zaidi Said, Elsayed Elrefaei, Kaspersky Security Services21 Sep 2026 at 10:00am
Kaspersky GERT experts dive into the technical incident analysis of PAYLOAD ransomware: an encryptionless, binary-less operation that abused Active Directory mechanisms for managing Group Policy Objects.
The Odyssey and Trojans again: MovieReaper attacks users in multiple countrie...
by Konstantin Isakov, Pavel Cheremushkin17 Sep 2026 at 1:00pm
Kaspersky experts have discovered a new MovieReaper campaign. The multi-stage Trojan spreads through movie torrents, such as The Odyssey, and uses the Solana blockchain to hide its C2 infrastructure.
NightEagle targets Russian companies
by Stanislav Larinsky, Kaspersky Security Services16 Sep 2026 at 10:00am
Kaspersky GERT experts have uncovered a new campaign by the NightEagle APT, featuring the GhostContainer backdoor and tools hosted on GitHub. The group is also exploiting vulnerabilities in Active Directory and RDP.
Angry Birds: Toy Ghouls? new toys
by Kaspersky GERT, Kaspersky Security Services4 Sep 2026 at 10:00am
Kaspersky GERT experts have discovered new backdoors used by the Toy Ghouls group. One version of the backdoor uses the HiveMQ MQTT broker as its command-and-control server; the other uses the Matrix-based Element messenger.
Mirage Kitten targeting aviation and FinTech sectors across the Middle East a...
by Omar Amin1 Sep 2026 at 7:00am
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
ValleyRAT masquerading as adware
by Pavel Bukhtenko31 Aug 2026 at 10:00am
Threat actors are distributing the ValleyRAT backdoor disguised as adware. We analyze the infection chain, from the malicious installer to the final payload.
Threat landscape for industrial automation systems. Q2 2026
by Kaspersky ICS CERT27 Aug 2026 at 10:05am
The report contains statistics on industrial threats for Q2 2026, including ransomware, miners, spyware and other threats that were detected and blocked on industrial control systems.
Exploits and vulnerabilities in Q2 2026
by Alexander Kolesnikov26 Aug 2026 at 10:00am
This report covers statistics on vulnerabilities, exploits, and C2 frameworks in Q2 2026. For the first time ever, we aggregate data on vulnerabilities in open-source AI agents and AI frameworks.
The invisible passenger in your car
by Dmitry Kalinin21 Aug 2026 at 8:00am
Kaspersky expert has discovered new Android malware designed to serve ads and build a proxy botnet. It's delivered through legitimate software for DoFun head units.
