Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Kaspersky Securelist

20 articles

Kaspersky Securelist research 6h ago

Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO

Kaspersky GERT experts dive into the technical incident analysis of PAYLOAD ransomware: an encryptionless, binary-less operation that abused Active Directory...

Kaspersky Securelist → Details

Kaspersky Securelist research 4d ago

The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents

Kaspersky experts have discovered a new MovieReaper campaign. The multi-stage Trojan spreads through movie torrents, such as "The Odyssey," and uses the Sola...

T1583

Kaspersky Securelist → Details

Kaspersky Securelist research GitHub Docker 5d ago

NightEagle targets Russian companies

Kaspersky GERT experts have uncovered a new campaign by the NightEagle APT, featuring the GhostContainer backdoor and tools hosted on GitHub. The group is al...

Kaspersky Securelist → Details

Kaspersky Securelist research Sep 4

Angry Birds: Toy Ghouls’ new toys

Kaspersky GERT experts have discovered new backdoors used by the Toy Ghouls group. One version of the backdoor uses the HiveMQ MQTT broker as its command-and...

Kaspersky Securelist → Details

Kaspersky Securelist research Oracle Sep 1

Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set

Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.

Kaspersky Securelist → Details

Kaspersky Securelist research Aug 31

ValleyRAT masquerading as adware

Threat actors are distributing the ValleyRAT backdoor disguised as adware. We analyze the infection chain, from the malicious installer to the final payload.

Kaspersky Securelist → Details

Kaspersky Securelist research Aug 27

Threat landscape for industrial automation systems. Q2 2026

The report contains statistics on industrial threats for Q2 2026, including ransomware, miners, spyware and other threats that were detected and blocked on i...

Kaspersky Securelist → Details

Kaspersky Securelist research Aug 26

Exploits and vulnerabilities in Q2 2026

This report covers statistics on vulnerabilities, exploits, and C2 frameworks in Q2 2026. For the first time ever, we aggregate data on vulnerabilities in op...

Kaspersky Securelist → Details

Kaspersky Securelist research Google Aug 21

The invisible passenger in your car

Kaspersky expert has discovered new Android malware designed to serve ads and build a proxy botnet. It's delivered through legitimate software for DoFun head...

Kaspersky Securelist → Details

Kaspersky Securelist research Microsoft Linux Aug 14

APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit

Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections fro...

Kaspersky Securelist → Details

Kaspersky Securelist research Aug 13

Armored Likho expands its cyber-espionage toolkit

Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram dat...

Kaspersky Securelist → Details

Kaspersky Securelist research Aug 11

Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants

Kaspersky experts have discovered malicious TrueConf software installers. The Head Mare APT group uses them to deliver the PhantomCore and PhantomGraph backd...

Kaspersky Securelist → Details

Kaspersky Securelist research Google Aug 11

Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection

Project CAV3RN targets Israel with Google Apps Script C2 relays and DNS-based routing. Modular .

Kaspersky Securelist → Details

Kaspersky Securelist research Microsoft Apple Aug 10

IT threat evolution in Q2 2026. Non-mobile statistics

The report presents key trends and statistics on malware that targeted personal computers running Windows and macOS, as well as internet of things (IoT) devi...

Kaspersky Securelist → Details

Kaspersky Securelist research Aug 10

IT threat evolution in Q2 2026. Mobile statistics

This report contains mobile threat statistics for Q2 2026, along with noteworthy discoveries and quarterly trends: the Anatsa banker and a transition to drop...

Kaspersky Securelist → Details

Kaspersky Securelist research Cloudflare GitHub Aug 4

How legitimate cloud platforms enable phishers to bypass MFA

We cover a cloud-based AitM attack scenario leveraging service workers and Ultraviolet, and provide detailed phishing hosting statistics across platforms lik...

T1566 T1557

Kaspersky Securelist → Details

Kaspersky Securelist research Aug 3

An analysis of incidents at Brazilian educational institutions

Kaspersky expert provides statistics and details on several incident response cases at educational institutions in Brazil, as well as tips for schools and un...

Kaspersky Securelist → Details

Kaspersky Securelist research Jul 31

Network Anomaly Detection in KATA

An analysis of how Network Anomaly Detection (NAD) rules work within Kaspersky Anti Targeted Attack, using Kerberoasting and DNS tunneling attacks as examples.

T1572

Kaspersky Securelist → Details

Kaspersky Securelist research Jul 30

OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia

Our experts discovered OctLurk and SilkLurk, backdoors operating primarily in memory, targeting Central Asia. They inject plugins to launch shells, scan netw...

Kaspersky Securelist → Details

Kaspersky Securelist research Microsoft VMware Linux Jul 30

Toy Ghouls’ new toy: the GenieLocker ransomware

Kaspersky experts dissect GenieLocker: new custom ransomware variants for Windows, Linux, and ESXi systems. We found this family in attacks by Toy Ghouls, a ...

Kaspersky Securelist → Details

1 2 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA