Kaspersky Securelist (GReAT)
kaspersky-securelist · B · active
Kaspersky GReAT research. RSS at https://securelist.com/feed/ is a usable backup. 2026-05-08 audit: 5 dated articles latest 2026-05-07 on xrdp RCE, OceanLotus. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → rss: python3 tools/fetch_source.py feed https://securelist.com/feed/ 5 (then webfetch per-article URL for body). AVOID: WebFetch on the HTML index renders the article list but strips publication dates, use the /feed/ RSS for clean dates, then webfetch the article for the body.. | 2026-07-05 admiralty audit: B, GReAT original APT/malware research from own telemetry; use /feed/ for clean dates. HIGH->B, stays active. | 2026-07-18 weekly audit: the securelist.com LISTING renders several post titles with NO visible publish date on a plain fetch, silently pushing new in-window posts below the visible fold (caused the GoSerpent 07-16 miss, recovered by the audit). For discovery, sweep the RSS feed (https://securelist.com/feed/) which carries dates, or WebSearch-cross-check undated listing titles; never assume an undated listing title is old.
Cited in 25 entries
Citation cadence
Citation days per ISO week (20 weeks of coverage span, total 22).
- MovieReaper: a modular crimeware framework distributed via a torrent-file-repository supply-chain compromise, using the Solana blockchain as a C2 dead-drop resolver2026-09-18
- Recorded Future's H1 2026 Malware and Vulnerability Trends: two clusters reuse an identical post-exploitation tool stack across thirteen and ten unrelated initial CVEs2026-09-07
- Mirage Kitten (Nimbus Manticore/UNC1549) debuts Node.js and JavaScript RATs (NodeRabbit and PollCat) delivered through fake LinkedIn technical-hiring assessments2026-09-02
- ValleyRAT (Winos 4.0) hides inside a re-signed Chinese wallpaper app: DLL sideloading, a self-restoring svchost injection, and a Windows Defender kill switch2026-09-01
- CVE-2026-72529 and CVE-2026-72530, a pre-auth chain on TrueConf Server's port 4307 reaches SYSTEM, and the operators use it to replace the client installer the server hands to everyone who joins a meeting2026-08-23
- Mustang Panda's CoolClient backdoor gains a kernel driver signed with a 2013 certificate that expired in 2014, and it hides the malware's own C2 traffic by hooking the driver Windows uses to report network state2026-08-15
- Phishing kits are registering browser service workers to build in-page transparent proxies, relaying credentials and live MFA codes from a fake browser window on trusted cloud hosting2026-08-05
- OctLurk and SilkLurk, sibling plugin backdoors whose loaders key their payload decryption to the victim machine itself, deployed against Central Asian and Syrian government bodies2026-07-31
- GenieLocker; a Windows and ESXi ransomware built to leave no ransom note on disk, gated behind a hashed command-line secret so it will not run in a sandbox2026-07-31
- Mirage Kitten (UNC1549) fields the NightLedger backdoor and two WebSocket tunnelers, one of them built to negotiate through corporate proxies with the victim's own SSO2026-07-29
- TELESHIM / MIXEDKEY / BINDCLOAK, DLL side-loading under a legitimate vendor binary, Telegram-API C2 and volume-serial environmental keying against government networks2026-07-26
- Kaspersky documents living-off-the-land BitLocker extortion across two Latin America incidents; the second self-identifies as 'XEntry Team'2026-07-22
- HOLLOWGRAPH: a Cavern-framework backdoor that turns a compromised Microsoft 365 calendar into a Graph-API dead-drop C22026-07-21
- GoSerpent evolves: staged collect-then-return espionage against Southeast Asian government and diplomatic targets2026-07-18
- Kaspersky: the HelloNet campaign blinds user-mode security tools by hooking raw AFD IOCTLs, persisting via DLL-sideload into a secure-network product's own auto-updater2026-07-17
- Armored Likho: new APT hits government and electric-power targets with an AI-generated loader and the Python 'BusySnake' stealer2026-07-11
- Kaspersky MDR: SEO-poisoned fake-installer sites trojanize ScreenConnect to deploy AsyncRAT2026-07-02
- Kaspersky: community AI-agent "skills" are an emerging supply-chain surface, OpenClaw marketplace still distributing malicious skills2026-07-02
- Kaspersky GReAT: ToddyCat's "Umbrij" automates Gmail/Workspace OAuth-token theft via Chromium remote-debugging abuse2026-07-01
- Kaspersky GReAT: "StrikeShark" loader deploys Cobalt Strike via "Perfect DLL Hijacking" against government targets2026-06-27
- WhatsApp-borne VBScript silently installs a ManageEngine RMM agent for living-off-the-land remote control2026-06-24
- Kaspersky GReAT documents Kimsuky's Rust-based HelloDoor and TryCloudflare-tunnel C2 added to the PebbleDash toolkit2026-05-17
- CVE-2025-68670, xrdp pre-authentication stack overflow, arbitrary code execution2026-05-09
- Kaspersky Q1 2026 Exploits and Vulnerabilities Report: document-based exploits resurge; RaaS acquires zero-days2026-05-08
- Amazon SES weaponised for authenticated phishing and BEC (Kaspersky, 2026-05-04, ~96 h)2026-05-08