Angry Birds: Toy Ghouls’ new toys

2026-09-11T08:51:46Z2249ebd25d2149eb413b751d99f3762364258761b0134f8b227221a8657c20d2
APTAfricaAndroidDNS-C2ElementGoogle-Apps-Script-C2ICSMQTTMatrixMiddle-EastNode.js malware​TelegramTrueConfWindows-rootkitadwareaviationbackdoorscyber-espionagefinancial-servicesindustrial-control-systemskernel-mode-rootkitmalwareproxy-botnetransomwareunpatched-vulnerabilities

What happened

Kaspersky Securelist feed covering recent 2026 threat activity, including new backdoors and espionage toolkits, malware disguised as legitimate software, kernel-level rootkits, exploitation of unpatched TrueConf servers, MQTT/Matrix/Google Apps Script C2, DNS-based routing, Android proxy botnets, and threats targeting aviation, financial, industrial, and Middle Eastern organizations. The feed also includes quarterly vulnerability and exploit statistics, including emerging risks in AI agents and frameworks.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
2249ebd25d2149eb413b751d99f3762364258761b0134f8b227221a8657c20d2
Enrichment time
2026-09-11T08:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.