IT threat evolution in Q1 2026. Mobile statistics

2026-05-19T20:51:54Z6e1732cd44c876614aa292c3dd75fa68bccf9578aa69111261ec210d3edc1003
ABCDoorAPTAmazon-SESAppleSeedCVE-2025-68670EDR-killersIoTKimsukyOceanLotusPebbleDashPyPI-supply-chainSilver-FoxSparkCatTriadaUSB-RedirectorValleyRATZiChatBotdata-leak-extortionexploitsmobile-malwarephishingransomwarevulnerabilitiesxrdp

What happened

Kaspersky Securelist Q1 2026 collection: quarterly telemetry for mobile, PC and IoT threats (including new SparkCat and Triada variants); an industry-wide ransomware overview noting rise of EDR-killers and shift toward data-leak extortion; disclosure of a pre-auth remote code execution in xrdp (CVE-2025-68670) found during USB Redirector assessment and promptly patched; analysis of active APT activity — Kimsuky using PebbleDash tools linked to the AppleSeed cluster, OceanLotus abusing PyPI to deliver ZiChatBot via malicious wheels, and Silver Fox distributing ValleyRAT and a new ABCDoor backdo

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
6e1732cd44c876614aa292c3dd75fa68bccf9578aa69111261ec210d3edc1003
Enrichment time
2026-05-19T20:51:54Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.