Angry Birds: Toy Ghouls’ new toys
2026-09-14T20:51:46Z•8ece204a623d67f53508296bb8ebef41d9c47e3a10184ca9052f3f9a75ba04fa
APTAndroid malwareArmored LikhoCoolClientElementHead MareHiveMQHoneyMyteMQTTMatrixMirage KittenNodeRabbitPhantomCorePhantomGraph詬?PollCatStill ToolkitTrueConfValleyRATbackdoorcommand-and-controlcyber-espionagekernel rootkitmalwareproxy botnetthreat-intelligence
What happened
Kaspersky reporting from August–September 2026 describes multiple campaigns and malware developments, including MQTT- and Matrix-based backdoors, new Mirage Kitten malware, ValleyRAT disguised as adware, Android proxy-botnet malware, a kernel-level CoolClient rootkit, Telegram-stealing tooling, exploitation of unpatched TrueConf servers, and Google Apps Script/DNS-based C2. The collection also covers industrial-control-system threats and broader vulnerability and exploit trends, including AI framework vulnerabilities.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 8ece204a623d67f53508296bb8ebef41d9c47e3a10184ca9052f3f9a75ba04fa
- Enrichment time
- 2026-09-14T20:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.