Network Anomaly Detection in KATA

2026-08-03T08:51:46Z6e9cd21130eb7b4abb54658afc8e04b1fe6b9fc2e1fadf1ecc18c6a18768a675
BitLocker-extortionCentral-Asia על?DNS-AAAA-C2DNS-tunnelingMSSQLMicrosoft-GraphOutlook-calendar-C2RDPRMMbackdoorbrowser-stealercredential-dumpingcryptocurrency-targetingcyber-espionagedata-exfiltrationindustrial-control-systemskeyloggingmemory-resident-malwarenetwork-scanningransomwareseed-phrase-theftsoftware-update-abusesupply-chain-compromisetargeted-attacksweb-shell

What happened

Kaspersky Securelist reporting from July 2026 covers targeted cyber-espionage campaigns, memory-resident backdoors, ransomware and BitLocker extortion, malware frameworks targeting cryptocurrency users, supply-chain abuse, DNS and cloud-based C2, and threats to industrial automation systems. Notable activity includes OctLurk and SilkLurk in Central Asia, Mirage Kitten tools targeting the Middle East and Africa, Project CAV3RN using Outlook and DNS for C2, HelloNet abuse of the ViPNet update system, and GenieLocker ransomware affecting Windows, Linux, and ESXi.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
6e9cd21130eb7b4abb54658afc8e04b1fe6b9fc2e1fadf1ecc18c6a18768a675
Enrichment time
2026-08-03T08:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.