VIRUS-NEWS
Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server t...
by Kaspersky11 Aug 2026 at 12:00pm
Kaspersky experts have discovered malicious TrueConf software installers. The Head Mare APT group uses them to deliver the PhantomCore and PhantomGraph backdoors to target systems by exploiting vulnerabilities in an unpatched TrueConf server.
Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 cha...
by GReAT11 Aug 2026 at 10:00am
Project CAV3RN targets Israel with Google Apps Script C2 relays and DNS-based routing. Modular .NET NativeAOT framework blends C2 traffic with legitimate Google services to evade detection.
IT threat evolution in Q2 2026. Non-mobile statistics
by AMR10 Aug 2026 at 10:00am
The report presents key trends and statistics on malware that targeted personal computers running Windows and macOS, as well as internet of things (IoT) devices, during Q2 2026.
IT threat evolution in Q2 2026. Mobile statistics
by Anton Kivva10 Aug 2026 at 10:00am
This report contains mobile threat statistics for Q2 2026, along with noteworthy discoveries and quarterly trends: the Anatsa banker and a transition to droppers.
How legitimate cloud platforms enable phishers to bypass MFA
by Olga Altukhova4 Aug 2026 at 12:00pm
We cover a cloud-based AitM attack scenario leveraging service workers and Ultraviolet, and provide detailed phishing hosting statistics across platforms like Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS.
An analysis of incidents at Brazilian educational institutions
by Cristian Souza3 Aug 2026 at 1:00pm
Kaspersky expert provides statistics and details on several incident response cases at educational institutions in Brazil, as well as tips for schools and universities on how to stay safe.
Network Anomaly Detection in KATA
by Arseny Vesnovsky, Valery Akulenko, Dmitry Sabadash31 Jul 2026 at 10:00am
An analysis of how Network Anomaly Detection (NAD) rules work within Kaspersky Anti Targeted Attack, using Kerberoasting and DNS tunneling attacks as examples.
OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage ...
by Saurabh Sharma, Yaroslav Kikel30 Jul 2026 at 11:00am
Our experts discovered OctLurk and SilkLurk, backdoors operating primarily in memory, targeting Central Asia. They inject plugins to launch shells, scan networks, dump credentials, and keylogging.
Toy Ghouls? new toy: the GenieLocker ransomware
by Fedor Sinitsyn, Yanis Zinchenko30 Jul 2026 at 8:00am
Kaspersky experts dissect GenieLocker: new custom ransomware variants for Windows, Linux, and ESXi systems. We found this family in attacks by Toy Ghouls, a financially motivated extortion group.
Mirage Kitten targets Middle East and Africa region with new malware
by Omar Amin, Vasily Berdnikov28 Jul 2026 at 8:00am
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
