company · 12 records
Kaspersky

Russian hackers exploit Zimbra vulnerability to steal email data
A Russian state-supported espionage group exploited a zero-day vulnerability in Zimbra's webmail client to steal email data and authentication codes from Western government and commercial organizations between July 2025 and early 2026.

BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory
Researchers identified BraZetsu, a Python-based Windows malware framework used by Initial Access Brokers to facilitate the sale of compromised system access on an underground marketplace.

Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
A threat group identified as Silver Fox is distributing malware through fake software download websites to target Chinese-speaking users and organizations.

New Ted backdoor found in trojanized HAProxy binaries targeting South Korean firms
A previously undocumented backdoor named ted has been discovered embedded in trojanized HAProxy binaries used to intercept web traffic in South Korean organizations.

Silver Fox distributes ValleyRAT malware disguised as signed Chinese adware
Threat actor Silver Fox is distributing ValleyRAT backdoor disguised as signed Chinese adware, QN Wallpaper, to bypass antivirus exclusions and compromise user systems.

Iranian hackers use fake coding tests to deliver cross-platform malware
Iranian hacker group Nimbus Manticore has attributed two new cross-platform malware families, NodeRabbit and PollCat, which use disguised coding tests delivered via social engineering to compromise developers on Windows, Linux, and macOS systems.

United States charges Russian national over global Excel malware campaign
The U.S. Department of Justice charged a Russian national extradited from Cyprus with an Excel malware campaign that infected thousands of computers using fake freelance platform accounts between 2016 and 2017.

Researcher discloses zero day privilege escalation vulnerability in CrowdStrike Falcon Sensor
Researcher Chaotic Eclipse disclosed a zero-day privilege escalation vulnerability in CrowdStrike Falcon Sensor dubbed FalconFlank, while also detailing prior disclosures affecting Kaspersky endpoint security and Microsoft Defender.

Suspected Chinese hackers target Central Asian and Syrian government organizations
A Chinese-speaking threat actor is suspected of targeting government organizations in Central Asia and Syria with new malware backdoors OctLurk and SilkLurk since January 2025.

State-sponsored hackers exploit AnySign4PC vulnerability to deploy backdoors
State-sponsored attackers exploited a zero-day vulnerability in AnySign4PC via compromised Korean websites to install SIGNBT and COPPERHEDGE backdoors.

Iranian hacking group deploys new malware against targets in South Asia
The Iranian state-backed hacking group Nimbus Manticore deployed the new NightLedger backdoor and tunneling tools against targets across the Middle East, Africa, and South Asia.

Researchers uncover new GoSerpent malware targeting Southeast Asian government entities
Cybersecurity researchers have uncovered GoSerpent, a previously undocumented malware used in espionage campaigns targeting Southeast Asian government and diplomatic entities since late 2025, with links to the TetrisPhantom threat actor; a separate DoNot Team operation targeting Bangladesh's military was also detailed.