Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Kaspersky Securelist

11 articles

Kaspersky Securelist research 10h ago

Mirage Kitten targets Middle East and Africa region with new malware

Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ...

Kaspersky Securelist → Details

Kaspersky Securelist research Jul 21

A new extortion cocktail: office printers, small ransoms, and BitLocker

We cover two recent cases of BitLocker extortion using RDP, MSSQL, RMM tools, web shells, and printers. The story includes TTPs and recommendations.

T1190

Kaspersky Securelist → Details

Kaspersky Securelist research Microsoft Jul 21

New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery

Kaspersky GReAT experts describe a new Project CAV3RN C2 module. It uses Outlook calendar for communication via Microsoft Graph and has a backup connection v...

Kaspersky Securelist → Details

Kaspersky Securelist research Jul 16

HelloNet campaign — new malicious modules launched through the ViPNet update system

We identified targeted infection attempts against large Russian organizations using the ViPNet update system (a software suite for creating secure networks).

Kaspersky Securelist → Details

Kaspersky Securelist research Jul 16

GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration

Two-phase attacks with the GoSerpent backdoor, Stowaway RAT, ThumbcacheService and other tools aim to steal data from government entities in Southeast Asia.

T1041

Kaspersky Securelist → Details

Kaspersky Securelist research Jul 15

OkoBot: new sophisticated malware framework targets cryptocurrency users

Kaspersky GReAT experts dissect the new OkoBot campaign targeting cryptocurrency users. This complex framework employs TookPS, exfiltrates seed phrases, moni...

T1041

Kaspersky Securelist → Details

Kaspersky Securelist research Jul 7

Threat landscape for industrial automation systems. Q1 2026

This report contains industrial threat statistics for Q1 2026, including industrial threat distribution by type, source, region and industry.

Kaspersky Securelist → Details

Kaspersky Securelist research Microsoft Jul 6

When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft website

The OAuth 2.0 Device Authorization Grant specification was designed to streamline authentication for Smart TVs, IoT devices, and printers.

T1566

Kaspersky Securelist → Details

Kaspersky Securelist research Jul 3

Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign

An inside look at the active Armored Likho APT campaign. The attackers are using spear-phishing, AI-generated loaders, and a new Python-based tool, BusySnake...

T1566

Kaspersky Securelist → Details

Kaspersky Securelist research Jul 2

Missed incidents, persistent threats, and response gaps: Insights from compromise assessment projects

Kaspersky Compromise Assessment specialists analyze trends from the service's 2025 projects and provide tips on how to enhance your organization's security.

Kaspersky Securelist → Details

Kaspersky Securelist research Jul 1

The SOC Files: ScreenConnect masked as freeware. An inside look at a large-scale campaign

Kaspersky experts have uncovered a malicious network infrastructure for delivering AsyncRAT. The Trojan is dropped via compromised ScreenConnect software.

T1583

Kaspersky Securelist → Details

FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA