MacSync under the microscope: new delivery methods and a new payload
2026-09-24T20:51:46Z•662501fe32d7e2106fa046d4380da298046f0b6fa4e2829e8f1b77a5dc11cb81
AI-securityAPTActive DirectoryAndroidC2GitHubGroup Policy ObjectsICSJavaScriptMQTTMatrixNode.jsRDPSolanabackdoorexploitsindustrial-control-systemsinfostealermacOSmalwareproxy-botnetransomwarethreat-intelligencetorrent-distributionvulnerabilities
What happened
Kaspersky Securelist RSS entries covering September–August 2026 threat intelligence, including macOS infostealing with a backdoor, ransomware abusing Active Directory Group Policy, torrent-delivered multi-stage malware using Solana for C2 concealment, APT campaigns targeting Russian organizations and Middle Eastern and African sectors, MQTT/Matrix-based backdoors, ValleyRAT distribution, industrial control system threats, vulnerability and exploit trends including AI frameworks, and Android malware building an advertising proxy botnet.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 662501fe32d7e2106fa046d4380da298046f0b6fa4e2829e8f1b77a5dc11cb81
- Enrichment time
- 2026-09-24T20:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.