HelloNet campaign — new malicious modules launched through the ViPNet update system
posted
We identified targeted infection attempts against large Russian organizations using the ViPNet update system (a software suite for creating secure networks).
Powerful EDR solution that identifies and prevents advanced threats. It automatically detects suspicious activity, enables incident investigation, and equips security teams with the tools to respond quickly and effectively.
posted
We identified targeted infection attempts against large Russian organizations using the ViPNet update system (a software suite for creating secure networks).
posted
An inside look at the active Armored Likho APT campaign. The attackers are using spear-phishing, AI-generated loaders, and a new Python-based tool, BusySnake Stealer, to target organizations in Russia, Kazakhstan, and Brazil.
posted
updated UPD
Kaspersky experts have uncovered a malicious network infrastructure for delivering AsyncRAT. The Trojan is dropped via compromised ScreenConnect software. In this post, we break down the infection chain and analyze the C2 infrastructure.
posted
Hacktivist outfits, namely 4BID, Hakerskii Kit, and C.A.S., are now targeting organizations across Kazakhstan, the UAE, Egypt, and Syria.
posted
Over the past two months, the anonymous researcher Nightmare Eclipse has publicly released six Windows vulnerabilities complete with ready-to-use exploits, without prior coordination with Microsoft. The most critical of these is MiniPlasma.
posted
updated UPD
Targeted by threat actors: individuals and organizations across 100+ countries and territories, with the majority of victims located in Russia, Brazil, Turkey, Spain, Germany, France, Italy, and China.
posted
updated UPD
The vulnerability affects kernels released between 2017 and 2026. Both outdated server configurations and modern distributions are at risk: Ubuntu, RHEL etc.
posted
The Silver Fox group is targeting companies in Russia and India by impersonating tax authorities to distribute ValleyRAT and the new ABCDoor backdoor.
posted
Kaspersky researchers analyze the attack chain of a highly destructive Lotus Wiper that can be linked to a targeted attack on the energy and utilities sector.
posted
We examine how Kaspersky Anti Targeted Attack detects the network activity of AdaptixC2 agents across HTTP/S, TCP, SMB, and other protocols, and how EDR solutions identify post-exploitation activities on a host.
posted
updated UPD
In April 2026, cpuid.com delivered trojanized CPU-Z and HWMonitor installers with STX RAT. 150+ victims in Brazil, Russia, China.
posted
updated UPD
Kaspersky GReAT experts discovered previously undocumented infection chains used in the Notepad++ supply chain attacks. The article provides new IoCs related to those incidents which employ DLL sideloading and Cobalt Strike Beacon delivery.
posted
updated UPD
On January 20, Kaspersky solutions detected malware used in eScan antivirus supply chain attack. In this article we provide available information on the threat: indicators of compromise, threat hunting and mitigating tips, etc.
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
An in-depth analysis of Umbrij, a new tool used by the ToddyCat APT group to compromise corporate email communications in Gmail. The attack targeted OAuth authorization tokens, allowing threat actors to gain access to Google services.
Cloud Atlas attacks the public sector and diplomatic structures of Russia and Belarus, using ReverseSocks, SSH, and Tor for persistence in infected systems and its new tool, PowerCloud.
Kaspersky researchers analyze a range of new PebbleDash-based tools used in recent Kimsuky campaigns and reveal their connection to the AppleSeed malware cluster.