Kaspersky Securelist (GReAT)
kaspersky-securelist · B · active
Kaspersky GReAT research. RSS at https://securelist.com/feed/ is a usable backup. 2026-05-08 audit: 5 dated articles latest 2026-05-07 on xrdp RCE, OceanLotus. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → rss: python3 tools/fetch_source.py feed https://securelist.com/feed/ 5 (then webfetch per-article URL for body). AVOID: WebFetch on the HTML index renders the article list but strips publication dates — use the /feed/ RSS for clean dates, then webfetch the article for the body.. | 2026-07-05 admiralty audit: B — GReAT original APT/malware research from own telemetry; use /feed/ for clean dates. HIGH->B, stays active. | 2026-07-18 weekly audit: the securelist.com LISTING renders several post titles with NO visible publish date on a plain fetch, silently pushing new in-window posts below the visible fold (caused the GoSerpent 07-16 miss, recovered by the audit). For discovery, sweep the RSS feed (https://securelist.com/feed/) which carries dates, or WebSearch-cross-check undated listing titles — never assume an undated listing title is old.
Cited in 27 entries
Citation cadence
Citation days per ISO week (14 weeks of coverage span, total 21).
- Phishing kits are registering browser service workers to build in-page transparent proxies — relaying credentials and live MFA codes from a fake browser window on trusted cloud hosting2026-08-05
- This week's tradecraft was built against the analyst's environment, not the endpoint agent — samples that refuse to run without a keyed argument, loaders that cannot decrypt away from the host they infected, and operators driving the victim's own logged-in session2026-08-02
- OctLurk and SilkLurk — sibling plugin backdoors whose loaders key their payload decryption to the victim machine itself, deployed against Central Asian and Syrian government bodies2026-07-31
- GenieLocker — a Windows and ESXi ransomware built to leave no ransom note on disk, gated behind a hashed command-line secret so it will not run in a sandbox2026-07-31
- Mirage Kitten (UNC1549) fields the NightLedger backdoor and two WebSocket tunnelers, one of them built to negotiate through corporate proxies with the victim's own SSO2026-07-29
- This week's tradecraft converged on hiding command-and-control inside trusted services and native tooling — Graph-API calendars, DNS, the Telegram API, a browser the malware never connects through, and BitLocker instead of a ransomware binary2026-07-26
- Kaspersky documents living-off-the-land BitLocker extortion across two Latin America incidents; the second self-identifies as 'XEntry Team'2026-07-22
- Kaspersky corroborates the Cavern/HOLLOWGRAPH cluster, associates it (low confidence) with OilRig (APT34), and details a DNS AAAA-record C2 config-recovery fallback2026-07-22
- State-nexus tradecraft this week targeted defenders' own visibility — HelloNet blinds user-mode network EDR by intercepting raw AFD IOCTLs from a trusted-updater sideload, and GoSerpent shows weeks-long silent collection as deliberate design2026-07-19
- GoSerpent evolves: staged collect-then-return espionage against Southeast Asian government and diplomatic targets2026-07-18
- Kaspersky: the HelloNet campaign blinds user-mode security tools by hooking raw AFD IOCTLs, persisting via DLL-sideload into a secure-network product's own auto-updater2026-07-17
- Government and public administration across Switzerland and Europe took a broad spread of attacks this week — ransomware, espionage watering-holes, AI-tooled APTs and credential-phishing2026-07-12
- AI as operator, not target: this week's research showed adversaries using AI to run attacks faster, evade AI defences, and generate tooling2026-07-12
- Armored Likho: new APT hits government and electric-power targets with an AI-generated loader and the Python 'BusySnake' stealer2026-07-11
- The week's tradecraft converged on abusing trusted primitives — OAuth tokens, signed binaries, native auth APIs and legitimate SaaS2026-07-05
- This week AI crossed from attack target to attack operator — agentic ransomware, coerced coding agents, and LLM-output poisoning2026-07-05
- Kaspersky MDR: SEO-poisoned fake-installer sites trojanize ScreenConnect to deploy AsyncRAT2026-07-02
- Kaspersky: community AI-agent "skills" are an emerging supply-chain surface — OpenClaw marketplace still distributing malicious skills2026-07-02
- Kaspersky GReAT: ToddyCat's "Umbrij" automates Gmail/Workspace OAuth-token theft via Chromium remote-debugging abuse2026-07-01
- Threat-actor developments: Russia-nexus espionage broadens; new China-nexus and DPRK clusters2026-06-29
- Kaspersky GReAT: "StrikeShark" loader deploys Cobalt Strike via "Perfect DLL Hijacking" against government targets2026-06-27
- WhatsApp-borne VBScript silently installs a ManageEngine RMM agent for living-off-the-land remote control2026-06-24
- Kaspersky GReAT documents Kimsuky's Rust-based HelloDoor and TryCloudflare-tunnel C2 added to the PebbleDash toolkit2026-05-17
- CVE-2025-68670 — xrdp pre-authentication stack overflow, arbitrary code execution2026-05-09
- Kaspersky Q1 2026 Exploits and Vulnerabilities Report: document-based exploits resurge; RaaS acquires zero-days2026-05-08
- Amazon SES weaponised for authenticated phishing and BEC (Kaspersky, 2026-05-04, ~96 h)2026-05-08
- Kaspersky Q1 2026 Exploits and Vulnerabilities Report2026-05-04