IT threat evolution in Q1 2026. Mobile statistics
2026-05-20T08:51:55Z•06553b07d71fb84ca0e2715b0a5fe4ca9bf5e90bb08c0729cec3adf5abd156f5
ABCDoorAmazon-SESAppleSeedBECCVE-2025-68670EDR-killerIoTKimsukyOceanLotusPebbleDashPyPISilver-FoxSparkCatTriadaValleyRATWindows-macOS-LinuxZiChatBotdata-leakexploitsmobile-malwarephishingransomwaresupply-chainvulnerabilitiesxrdp
What happened
Kaspersky published multiple Q1 2026 security reports and advisories covering mobile, PC and IoT malware trends and notable campaigns. Highlights include new versions of mobile malware SparkCat and Triada; Kimsuky using PebbleDash-based tools linked to the AppleSeed cluster; OceanLotus distributing ZiChatBot via malicious PyPI wheels targeting Windows and Linux; and Silver Fox using ValleyRAT and a new ABCDoor backdoor in tax‑themed lures targeting Russia and India. The ransomware landscape is shifting toward EDR-killers and data‑exfiltration/leak-focused extortion. Researchers also disclosed:
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 06553b07d71fb84ca0e2715b0a5fe4ca9bf5e90bb08c0729cec3adf5abd156f5
- Enrichment time
- 2026-05-20T08:51:55Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.