Angry Birds: Toy Ghouls’ new toys
2026-09-11T08:51:46Z•2249ebd25d2149eb413b751d99f3762364258761b0134f8b227221a8657c20d2
APTAfricaAndroidDNS-C2ElementGoogle-Apps-Script-C2ICSMQTTMatrixMiddle-EastNode.js malwareTelegramTrueConfWindows-rootkitadwareaviationbackdoorscyber-espionagefinancial-servicesindustrial-control-systemskernel-mode-rootkitmalwareproxy-botnetransomwareunpatched-vulnerabilities
What happened
Kaspersky Securelist feed covering recent 2026 threat activity, including new backdoors and espionage toolkits, malware disguised as legitimate software, kernel-level rootkits, exploitation of unpatched TrueConf servers, MQTT/Matrix/Google Apps Script C2, DNS-based routing, Android proxy botnets, and threats targeting aviation, financial, industrial, and Middle Eastern organizations. The feed also includes quarterly vulnerability and exploit statistics, including emerging risks in AI agents and frameworks.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 2249ebd25d2149eb413b751d99f3762364258761b0134f8b227221a8657c20d2
- Enrichment time
- 2026-09-11T08:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.