Tag: kaspersky
-
Android Banking Droppers Surge as Malware Operators Change Packaging Tactics
Android banking malware operators are increasingly relying on dropper-based packaging to evade mobile app-store controls, shifting how threats are classified and delivered rather than simply expanding their overall distribution. Kaspersky telemetry for the second quarter of 2026 recorded 1,996,823 blocked attacks involving malware, adware, and potentially unwanted mobile software, down from 2,676,328 in Q1. Yet…
-
Android Banking Droppers Surge as Malware Operators Change Packaging Tactics
Android banking malware operators are increasingly relying on dropper-based packaging to evade mobile app-store controls, shifting how threats are classified and delivered rather than simply expanding their overall distribution. Kaspersky telemetry for the second quarter of 2026 recorded 1,996,823 blocked attacks involving malware, adware, and potentially unwanted mobile software, down from 2,676,328 in Q1. Yet…
-
TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore
Tags: attack, cybersecurity, exploit, flaw, kaspersky, programming, russia, software, threat, vulnerabilityThe threat actor known as Head Mare has been observed weaponizing security flaws in unpatched TrueConf servers once again in attacks targeting Russian companies spanning instrumentation, electronics, transport, energy, IT, and software development sectors.Russian cybersecurity vendor Kaspersky said it detected the attacks in July 2026.The activity involves exploiting a vulnerability chain First seen on thehackernews.com…
-
South Korea’s government overtakes telcos as top cyber attack target
Kaspersky researcher Sojun Ryu says ransomware crews have joined nation-state groups in going after South Korean organisations, as traces of LLM output start turning up inside malware First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366647735/South-Koreas-government-overtakes-telcos-as-top-cyber-attack-target
-
OctLurk and SilkLurk Windows Backdoors Target Governments in 6 Countries
Kaspersky links OctLurk and SilkLurk to cyberespionage attacks stealing passwords, emails and files from government systems in six countries since January 2025. First seen on hackread.com Jump to article: hackread.com/octlurk-silklurk-backdoors-target-6-countries/
-
Kaspersky to scan AI agents for backdoors as shadow AI spreads
The security supplier will release a tool this month that vets agent skills, models and artificial intelligence development components before they reach corporate networks to defend against threats from shadow AI First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366646680/Kaspersky-to-scan-AI-agents-for-backdoors-as-shadow-AI-spreads
-
Analyse von Kaspersky – Angriffe bleiben oft monatelang unentdeckt
First seen on security-insider.de Jump to article: www.security-insider.de/kaspersky-cyberangriffe-monatelang-unentdeckt-a-1ed3cf312d3413f4285acc0c6412cd0b/
-
GoSerpent Backdoor Drives a Patient Cyber Espionage Campaign Against Southeast Asian Governments
At a glance Malware family GoSerpent backdoor, plus McMx, Stowaway, ThumbcacheService, and TmcLoader/TmcPayload Threat actor Unconfirmed. Kaspersky notes First seen on securityonline.info Jump to article: securityonline.info/goserpent-backdoor/
-
New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage
Cybersecurity researchers have discovered a previously undocumented malware called GoSerpent that has been put to use in cyber attacks targeting entities in Southeast Asia since late 2025 with a focus on long-term access and intelligence gathering.Russian cybersecurity company Kaspersky, which uncovered the activity in February 2026, said it was aimed at government and diplomatic entities…
-
OkoBot greift Kryptowallets an und tarnt sich als legitime Software
Kaspersky warnt vor einem neuen Malware-Framework, das gezielt auf Kryptowährungsnutzer und Entwickler abzielt. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/okobot-kryptowallets-an
-
OkoBot Malware Uses ClickFix, Hidden Browser Extensions to Steal Crypto Data
Kaspersky says OkoBot targets crypto users through fake software, stealing wallet files, seed phrases and passwords while recording activity inside wallet apps. First seen on hackread.com Jump to article: hackread.com/okobot-malware-clickfix-browser-extensions-crypto-data/
-
Armored Likho Hits Government, Energy Sectors With BusySnake Stealer
Kaspersky details how the newly named Armored Likho APT uses BusySnake Stealer, AI-generated loaders, and phishing to target government and energy organizations. First seen on hackread.com Jump to article: hackread.com/armored-likho-government-energy-busysnake-stealer/
-
AI-Generated Malware Powers New Armored Likho APT Campaign
Armored Likho APT uses AI-generated malware, phishing, and BusySnake Stealer to target governments and power grids in Russia, Kazakhstan, and Brazil. Kaspersky’s threat research team has documented a previously unknown APT group they’re calling Armored Likho, also tracked under the name Eagle Werewolf. The group runs two parallel tracks: financially motivated attacks against private individuals…
-
Darknet-Handel mit Zugangsdaten: Warum KMU verstärkt in den Fokus von Cyberkriminellen geraten
Kleine und mittelständische Unternehmen stehen zunehmend im Fokus von Cyberkriminellen, die kompromittierte Zugangsdaten im Darknet anbieten. Eine Analyse von Kaspersky Digital Footprint Intelligence kommt zu dem Ergebnis, dass in den ersten vier Monaten des Jahres 2026 ein erheblicher Anteil entsprechender Darknet-Beiträge angebliche Zugänge zu KMU betraf [1]. Der Befund verdeutlicht, dass Angriffe auf Unternehmensidentitäten und……
-
Immer mehr Zugangsdaten von KMU landen im Darknet
Eine aktuelle Untersuchung von Kaspersky zeigt, dass im Darknet verstärkt Zugangsdaten von KMU zum Verkauf angeboten werden. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/zugangsdaten-kmu-landen-im-darknet
-
Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer
A previously undocumented threat actor known as Armored Likho has been attributed to cyber attacks targeting government agencies and the electric power sector across Russia, Brazil, and Kazakhstan.”Armored Likho blends financially motivated campaigns targeting private individuals with targeted cyber espionage aimed at organizations,” Kaspersky said in a technical analysis published today. “ First seen on…
-
Kaspersky-Umfrage: Online-Betrug betraf 2025 bereits 56 Prozent der Internetnutzer
First seen on datensicherheit.de Jump to article: www.datensicherheit.de/kaspersky-umfrage-online-betrug-2025-56-prozent-internetnutzer
-
ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API
The threat actor known as ToddyCat has been attributed to a new malware called Umbrij that’s designed to gain surreptitious access to a victim’s email correspondence via the Google API.”In this campaign, the attackers focused their attention on corporate email communications hosted on Gmail, targeting access compromise via APIs,” Kaspersky said in a detailed report…
-
Cyberkriminelle kapern Windows-Rechner über manipulierte Downloads
Kaspersky warnt vor einer Kampagne mit über 90 gefälschten Domains. Angreifer nutzen präparierte Software-Downloads zur Infektion mit AsyncRAT. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/windows-manipulierte-downloads
-
Mystery hackers use novel SharkLoader dropper against governments, software devs
Kaspersky researchers have uncovered a previously unknown cyberattack campaign that has compromised government organizations and software development companies in multiple … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/26/sharkloader-dropper-governments-software-developers/
-
WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool
Direct messages sent via WhatsApp are being used to distribute malicious Visual Basic Script (VBScript) files that lead to the installation of legitimate Remote Monitoring and Management (RMM) software.Per findings from Kaspersky, the active campaign is targeting users of WhatsApp Desktop and WhatsApp Web across Malaysia, Brazil, India, Mexico, Singapore, the U.K., Spain, Taiwan, Australia,…
-
WhatsApp Malware Campaign Hijacks Trust, Installs Legitimate Admin Tools
WhatsApp accounts were hijacked to spread fake debt notices that install remote access software, giving attackers control of victims’ PCs. Kaspersky published a technical analysis this week of an active malware campaign that spreads through WhatsApp messages and ends with a remote management tool silently installed on the victim’s machine. The campaign is still running…
-
WhatsApp Malware Campaign Hijacks Trust, Installs Legitimate Admin Tools
WhatsApp accounts were hijacked to spread fake debt notices that install remote access software, giving attackers control of victims’ PCs. Kaspersky published a technical analysis this week of an active malware campaign that spreads through WhatsApp messages and ends with a remote management tool silently installed on the victim’s machine. The campaign is still running…
-
Hackers Hide New Argamal Malware Inside Working Hentai Games
Kaspersky found Argamal malware hidden in hentai game installers, giving hackers remote access through working games shared on adult sites and torrents. First seen on hackread.com Jump to article: hackread.com/hackers-hide-argamal-malware-hentai-games/
-
NFC-Betrug explodiert: Opfer überweisen ihr Geld direkt an Kriminelle
NFC-Betrug nimmt drastisch zu: Kaspersky registriert 188 Prozent mehr Angriffe. Täter bringen Opfer dazu, Geld direkt an sie zu überweisen. First seen on tarnkappe.info Jump to article: tarnkappe.info/artikel/it-sicherheit/nfc-betrug-opfer-ueberweisen-geld-an-kriminelle-329667.html
-
Gesichtserkennung erkennt Personen trotz KI-veränderter Gesichter
Ein Experiment von Kaspersky auf dem Branchenevent <> am 19. Mai in Rom zeigte, dass Systeme der Gesichtserkennung Personen auch dann noch identifizieren können, wenn generative KI-Tools (GenAI) das Aussehen des Gesichts durch Alterungs- und Verjüngungseffekte drastisch verändert haben. Dies trifft auch dann zu, wenn dabei Bilder erzeugt wurden, die für das menschliche Auge […]…
-
Was deutsche Unternehmen und Behörden aus dem Daemon-Tools-Supply-Chain-Angriff mitnehmen sollten
Ein monatelanger Lieferketten-Angriff auf Daemon-Tools, ein weit verbreitetes Disk-Imaging-Tool, verdeutlicht: Kompromittierungen sind nach wie vor sehr schwer aufzudecken. Der von Kaspersky aufgedeckte Angriff lief ab dem 8. April und infizierte heimlich, still und leise Systeme in über 100 Ländern. Dabei wurden zunächst Systemdaten gesammelt, bevor anschließend bei ausgewählten Opfern in Handel, Verwaltung, Industrie und Forschung…
-
PyPI Packages Deliver ZiChatBot Malware via Zulip APIs on Windows and Linux
Cybersecurity researchers have discovered three packages on the Python Package Index (PyPI) repository that are designed to stealthily deliver a previously unknown malware family called ZiChatBot on Windows and Linux systems.”While these wheel packages do implement the features described on their PyPI web pages, their true purpose is to covertly deliver malicious files,” Kaspersky First…
-
Hackers compromise Daemon Tools in global supply-chain attack, researchers say
Researchers at Kaspersky said attackers tampered with installers for Daemon Tools, a popular program used to mount disk images as virtual drives, and distributed them through the software’s official website. First seen on therecord.media Jump to article: therecord.media/hackers-compromise-daemon-tools-global-supply-chain-attack
-
Attackers compromised Daemon Tools software to deliver backdoors
Kaspersky researchers uncovered another supply chain compromise involving a popular Windows tool: Daemon Tools, an app for mounting disk image files as virtual drives that is … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/05/06/daemon-tools-compromised-backdoors-supply-chain-attack/

