Armored Likho expands its cyber-espionage toolkit

2026-08-13T20:51:46Z3ac1cd5808c3b16a1f0d6725e469588f2226e5a9a6b809458b8f324e0e723fb1
APTAndroidBrazilCentral AsiaDNS tunnelingESXiGoogle Apps ScriptIoTIsraelLinuxMFA bypassTelegram theftTrueConfWindowsadversary-in-the-middlebackdoorcredential dumpingcyber-espionagekeyloggingmacOSmalwarenetwork scanningphishingransomwareunpatched vulnerability

What happened

Kaspersky Securelist RSS feed covering recent threat intelligence, including cyber-espionage campaigns, APT activity, exploitation of unpatched TrueConf servers, modular backdoors, phishing and adversary-in-the-middle attacks bypassing MFA, ransomware targeting Windows/Linux/ESXi, DNS tunneling, and malware trends across desktop, mobile, and IoT environments. Featured threats include Armored Likho’s Still Toolkit, Head Mare’s PhantomCore and PhantomGraph, Project CAV3RN, OctLurk, SilkLurk, and Toy Ghouls’ GenieLocker.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
3ac1cd5808c3b16a1f0d6725e469588f2226e5a9a6b809458b8f324e0e723fb1
Enrichment time
2026-08-13T20:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.