IT threat evolution in Q1 2026. Mobile statistics

2026-05-19T08:51:51Z30c2a341a992798de7153986b9b53136aad298606765ff5cf61dacc1b0b1769c
ABCDoorAmazon SESAppleSeedBECEDR evasionKimsukyOceanLotusPebbleDashPyPI supply‑chainSilver FoxSparkCatTriadaUSB RedirectorValleyRATZiChatBotdata‑leak extortionmobile malwarephishingpre‑auth RCEransomwarexrdp

What happened

Kaspersky Securelist roundup (Q1 2026 and related posts) covering mobile and non-mobile threat statistics and multiple active threats and vulnerabilities. Highlights include new mobile malware variants (SparkCat, Triada), Kimsuky campaigns using PebbleDash tooling linked to the AppleSeed cluster, OceanLotus supply‑chain abuse via malicious PyPI wheels delivering ZiChatBot (Windows/Linux), Silver Fox campaigns distributing ValleyRAT and a new ABCDoor backdoor via tax‑themed lures, and a trend report on ransomware showing rising EDR‑killer techniques and a shift from encryption to data leaks. A

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
30c2a341a992798de7153986b9b53136aad298606765ff5cf61dacc1b0b1769c
Enrichment time
2026-05-19T08:51:51Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.