Kaspersky researchers have identified a new type of malware specifically designed for car head units, which are the infotainment systems found in vehicles. This malware has been linked to the BadBox botnet, a network that has already compromised millions of devices. The malware's targeting of car systems raises significant concerns about the security of vehicle technology, as it could potentially allow attackers to control various functions of the car or access sensitive data. This incident emphasizes the growing vulnerability of modern vehicles to cyber threats, highlighting a need for stronger security measures in automotive technology. Car manufacturers and users alike should be aware of this emerging threat and take precautions to safeguard their systems.
Articles tagged "Kaspersky"
Found 54 articles
Mustang Panda, also known as HoneyMyte, has enhanced its CoolClient backdoor by deploying a signed kernel-mode driver that can conceal processes, files, and network activity. This upgrade makes it significantly harder for security software to detect and remove the malware from infected Windows systems. Kaspersky's recent analysis indicates that this new variant of CoolClient deepens the malware's integration into the operating system, raising concerns for users and organizations relying on Windows. The implications are serious, as this could allow attackers to maintain prolonged access to compromised systems while evading detection. Users and organizations need to remain vigilant and implement security measures to protect against this evolving threat.
Kaspersky researchers have identified a new cyber-espionage campaign linked to the group Armored Likho. This campaign masquerades as a fundraising initiative and uses a newly developed tool called the Still Toolkit, which is specifically designed to steal data from Telegram and eavesdrop on users. The implications of this attack are significant, particularly for individuals and organizations that rely on Telegram for communication. Users should be cautious about unsolicited fundraising requests and consider enhancing their security measures to protect sensitive information. This incident illustrates the ongoing risks posed by sophisticated cyber-espionage tactics, which continue to evolve and target popular communication platforms.
Securelist
Researchers at Kaspersky have identified a cybersecurity threat involving the Head Mare APT group, which is exploiting vulnerabilities in unpatched TrueConf servers. This group is using malicious software installers to deliver two backdoors, PhantomCore and PhantomGraph, to users participating in video conferences. The attack specifically targets systems that have not updated their TrueConf software, making them susceptible to these exploits. This situation raises significant concerns for organizations that rely on video conferencing tools for communication, as attackers could gain unauthorized access to sensitive information. Users and companies should prioritize patching their TrueConf installations to mitigate this risk.
The Hacker News
A group known as Head Mare has been exploiting vulnerabilities in unpatched TrueConf servers to carry out attacks against various Russian companies. These companies operate in sectors like instrumentation, electronics, transport, energy, IT, and software development. Kaspersky, a cybersecurity firm, reported detecting these attacks in July 2026. The attackers are reportedly replacing legitimate client installers with malicious software called PhantomCore, which could compromise the security of the affected organizations. This situation raises concerns for companies still using outdated versions of TrueConf, as failure to update could lead to severe security breaches.
Engineers at an Israeli food company faced a major setback when an intruder tampered with their refrigeration system. The attacker switched the gas cooler and receiver valves to manual and left them open, causing liquid carbon dioxide to flood the compressors and ultimately destroying them. The repair process took a week, as the new compressors were incompatible with the existing system, requiring a complete rework and gas recharge. This incident is part of a larger trend, with Kaspersky ICS CERT reporting around forty similar attacks recently. Such breaches highlight the vulnerabilities in industrial control systems and the potential for significant operational disruptions.
SCM feed for Latest
Kaspersky has issued a warning about the potential security risks posed by empty web pages, often seen as 'Coming Soon' placeholders. These pages might seem innocuous, but they can secretly gather sensitive information from visitors, including their IP addresses, approximate locations, User-Agent strings, and cookie identifiers. This data collection could be exploited by malicious actors for tracking or targeting users. As many businesses use such pages during website development or maintenance, it's crucial for them to understand these risks and implement measures to protect visitor data. Companies should consider disabling data collection features or ensuring robust privacy practices to mitigate these vulnerabilities.
A recent report from Kaspersky reveals that Brazilian educational institutions have been facing a range of cybersecurity incidents. The analysis includes various case studies that detail how schools and universities have responded to these threats. Kaspersky experts emphasize the need for improved security measures to protect sensitive data and maintain operational integrity. This is particularly crucial as educational institutions often handle personal information of students and staff, making them attractive targets for cybercriminals. The article also provides practical tips for schools and universities to bolster their defenses against future attacks, highlighting the importance of proactive cybersecurity strategies in the education sector.
This article examines how Kaspersky Anti Targeted Attack uses Network Anomaly Detection (NAD) to identify unusual network behavior, specifically through the lens of Kerberoasting and DNS tunneling attacks. Kerberoasting involves attackers obtaining service account credentials from Active Directory, while DNS tunneling allows data exfiltration through DNS queries. By analyzing these attack vectors, the article highlights the importance of NAD in detecting and mitigating such threats. Understanding these methods is crucial for organizations looking to strengthen their cybersecurity measures and protect sensitive information from targeted attacks. The insights provided could help security teams better prepare for and respond to similar incidents in the future.
Kaspersky researchers have identified a new strain of ransomware called GenieLocker, which targets Windows, Linux, and ESXi systems. This ransomware is associated with a group known as Toy Ghouls, which is primarily focused on financial extortion. The emergence of GenieLocker is concerning because it indicates a growing trend of customized ransomware that can impact multiple operating systems, making it a versatile threat for various organizations. Companies using affected systems should be vigilant and implement strong security measures to protect their data. With ransomware incidents on the rise, understanding the capabilities of threats like GenieLocker is crucial for effective defense strategies.
Kaspersky researchers have identified a new malware campaign attributed to a group known as Mirage Kitten, which primarily targets the Middle East and Africa. This campaign involves several previously undocumented tools, including the NightLedger backdoor and tunneling tools called ArcBridge and BridgeHead. These malicious tools can facilitate unauthorized access and data exfiltration from compromised systems. The emergence of this malware is concerning as it highlights the ongoing cyber threats facing organizations in these regions, emphasizing the need for heightened security measures. Companies should remain vigilant and implement robust defenses to protect against potential breaches.
The Hacker News
Researchers have identified a new malware strain named GoSerpent, which has been targeting government and diplomatic entities in Southeast Asia since late 2025. Discovered by Kaspersky in February 2026, GoSerpent is designed for long-term access and intelligence gathering, indicating a sophisticated level of espionage. The malware's specific targets include various Southeast Asian governments and their associated diplomatic missions, raising concerns about national security and the potential for sensitive information to be compromised. The emergence of GoSerpent highlights the ongoing cyber threats faced by government institutions in the region, emphasizing the need for enhanced cybersecurity measures. As attacks like these become more common, governments must prioritize their defenses against such persistent threats.
Hackread – Cybersecurity News, Data Breaches, AI and More
Kaspersky has reported a new malware called OkoBot that specifically targets cryptocurrency users. The malware masquerades as fake software, tricking users into downloading it. Once installed, OkoBot steals sensitive information such as wallet files, seed phrases, and passwords, while also recording user activity within wallet applications. This poses a significant risk to cryptocurrency holders, as their assets could be compromised. Users need to be cautious about the software they install and ensure they are using legitimate applications to protect their digital currencies.
Kaspersky's GReAT team has identified a new malware framework called OkoBot that specifically targets cryptocurrency users. This sophisticated malware utilizes a component known as TookPS to steal sensitive information, such as seed phrases, and monitor activities on Chromium-based browsers. Additionally, OkoBot can install various types of malware, including the Rilide stealer, which further compromises users' security. This threat is particularly concerning for those involved in cryptocurrency transactions, as it can lead to significant financial losses and privacy violations. Users need to be vigilant and consider enhancing their security measures to protect against these evolving threats.
Hackread – Cybersecurity News, Data Breaches, AI and More
Kaspersky has reported that the Armored Likho group, a previously identified advanced persistent threat (APT), is actively targeting government and energy sectors using a combination of techniques. They employ BusySnake Stealer, a type of malware designed to extract sensitive information, alongside AI-generated loaders and phishing methods to infiltrate systems. This campaign poses significant risks to organizations in these critical sectors, as the stolen data could lead to further exploitation or security breaches. The use of sophisticated tools and tactics highlights the evolving nature of cyber threats and the need for enhanced security measures within these industries. Organizations should remain vigilant and strengthen their defenses against such targeted attacks.