Network Anomaly Detection in KATA
2026-07-31T20:51:46Z•0bc2776485818cd5cc66f585c6d80ba341d51fae8bfe948e7e72bd1359430358
BitLocker-extortionCentral-Asia Middle-East-Africa Southeast-Asia RussiaDNS-AAAA-C2DNS-tunnelingGenieLockerICS-securityMSSQLMicrosoft-Graph-C2Outlook-calendar-C2RDPRMM-toolsbackdoorsbrowser-stealercredential-theftcryptocurrency-theftcyber-espionagein-memory-malwareindustrial-control-systemskeyloggingnetwork-scanningransomwareseed-phrase-theftsoftware-update-abusetargeted-attacksweb-shells
What happened
Kaspersky Securelist reporting from July 2026 covering targeted cyber-espionage campaigns, custom backdoors, ransomware and BitLocker extortion, malicious software-update abuse, credential and cryptocurrency theft, covert C2 over Microsoft Graph and DNS, and threats to industrial automation systems. Notable activity includes Central Asia espionage using in-memory OctLurk and SilkLurk backdoors, Mirage Kitten tooling against Middle East and Africa, GoSerpent operations in Southeast Asia, and HelloNet targeting Russian organizations via ViPNet updates.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 0bc2776485818cd5cc66f585c6d80ba341d51fae8bfe948e7e72bd1359430358
- Enrichment time
- 2026-07-31T20:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.