MacSync under the microscope: new delivery methods and a new payload

2026-09-26T08:51:46Z•334358f29064205240675d7d98cfba833a2b30a88e4e7d492d713665cbcd61b1
active-directoryandroidaptaviationbackdoorbinaryless-attackblockchain-c2fintechgithubgroup-policyindustrial-control-systems-vulnerabilitiesinfostealerjavascriptmacosmalwarematrixmqttnodejsproxy-botnetransomwareransomwarelessrdpsolanathreat-intelligencetorrent-distribution

What happened

Kaspersky Securelist RSS entries covering recent threat activity, including macOS information stealers, ransomware abuse of Active Directory Group Policy, torrent-delivered Trojans using blockchain-based C2 concealment, APT campaigns, MQTT and Matrix-backed backdoors, targeted malware against aviation and financial sectors, ValleyRAT, industrial control system threats, vulnerability and exploit trends, and Android proxy-botnet malware. The collection describes multiple active campaigns and novel attack techniques across endpoints, enterprises, OT, and mobile platforms.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
334358f29064205240675d7d98cfba833a2b30a88e4e7d492d713665cbcd61b1
Enrichment time
2026-09-26T08:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.