Mustang Panda Deploys Signed Windows Rootkit in Updated CoolClient Backdoor
Mustang Panda (aka HoneyMyte) has been observed deploying an updated version of the CoolClient backdoor that includes a signed Windows kernel-mode rootkit,…
Mustang Panda (aka HoneyMyte) has been observed deploying an updated version of the CoolClient backdoor that includes a signed Windows kernel-mode rootkit,…
Russian cybersecurity vendor Kaspersky has uncovered a new attack campaign by the threat actor known as Head Mare, targeting unpatched TrueConf videoconferencing…
A suspected Chinese-speaking threat actor has been conducting a series of cyber attacks against government organizations in Central Asia since January 2025.…
Iranian state-backed hacking group Nimbus Manticore (also known as GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been linked to…
Cybersecurity researchers at Kaspersky have uncovered a previously undocumented malware called GoSerpent, used since late 2025 in cyber attacks targeting government and…
A malware framework called OkoBot has been targeting Windows machines since April 2025, with a module named SeedHunter designed to steal cryptocurrency…
Kaspersky was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
Cybersecurity researchers have flagged a previously undocumented Rust-based remote access trojan (RAT) codenamed LabubaRAT that masquerades as NVIDIA software to blend into…
A previously undocumented threat actor, Armored Likho, has been attributed to cyber attacks targeting government agencies and the electric power sector across…
A new malware strain named Umbrij, attributed to the advanced persistent threat (APT) group ToddyCat, is abusing OAuth 2.0 tokens to gain…