MacSync under the microscope: new delivery methods and a new payload
2026-09-26T08:51:46Z•334358f29064205240675d7d98cfba833a2b30a88e4e7d492d713665cbcd61b1
active-directoryandroidaptaviationbackdoorbinaryless-attackblockchain-c2fintechgithubgroup-policyindustrial-control-systems-vulnerabilitiesinfostealerjavascriptmacosmalwarematrixmqttnodejsproxy-botnetransomwareransomwarelessrdpsolanathreat-intelligencetorrent-distribution
What happened
Kaspersky Securelist RSS entries covering recent threat activity, including macOS information stealers, ransomware abuse of Active Directory Group Policy, torrent-delivered Trojans using blockchain-based C2 concealment, APT campaigns, MQTT and Matrix-backed backdoors, targeted malware against aviation and financial sectors, ValleyRAT, industrial control system threats, vulnerability and exploit trends, and Android proxy-botnet malware. The collection describes multiple active campaigns and novel attack techniques across endpoints, enterprises, OT, and mobile platforms.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 334358f29064205240675d7d98cfba833a2b30a88e4e7d492d713665cbcd61b1
- Enrichment time
- 2026-09-26T08:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.