Network Anomaly Detection in KATA
2026-08-03T08:51:46Z•6e9cd21130eb7b4abb54658afc8e04b1fe6b9fc2e1fadf1ecc18c6a18768a675
BitLocker-extortionCentral-Asia על?DNS-AAAA-C2DNS-tunnelingMSSQLMicrosoft-GraphOutlook-calendar-C2RDPRMMbackdoorbrowser-stealercredential-dumpingcryptocurrency-targetingcyber-espionagedata-exfiltrationindustrial-control-systemskeyloggingmemory-resident-malwarenetwork-scanningransomwareseed-phrase-theftsoftware-update-abusesupply-chain-compromisetargeted-attacksweb-shell
What happened
Kaspersky Securelist reporting from July 2026 covers targeted cyber-espionage campaigns, memory-resident backdoors, ransomware and BitLocker extortion, malware frameworks targeting cryptocurrency users, supply-chain abuse, DNS and cloud-based C2, and threats to industrial automation systems. Notable activity includes OctLurk and SilkLurk in Central Asia, Mirage Kitten tools targeting the Middle East and Africa, Project CAV3RN using Outlook and DNS for C2, HelloNet abuse of the ViPNet update system, and GenieLocker ransomware affecting Windows, Linux, and ESXi.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 6e9cd21130eb7b4abb54658afc8e04b1fe6b9fc2e1fadf1ecc18c6a18768a675
- Enrichment time
- 2026-08-03T08:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.