Angry Birds: Toy Ghouls’ new toys
2026-09-08T08:51:46Z•947489fd4db2422102d5d81c98dec8c47803d029cf43fdce38f7dd7df16ba779
APTAndroid malwareDNS tunnelingElementFinTechGoogle Apps ScriptICSJavaScriptMQTTMatrixMiddle East and AfricaNode.jsTelegramTrueConfaviationbackdoorscommand-and-controlexploitindustrial-control-systemskernel rootkitmalwareproxy botnetransomwarespywarethreat-intelligence
What happened
Kaspersky Securelist RSS collection covering threat intelligence from August–September 2026. Reported activity includes new backdoors and malware families, MQTT and Matrix/Element command-and-control, adware masquerading, Android proxy botnets, industrial control system threats, kernel-level rootkits, Telegram data theft, exploitation of unpatched TrueConf servers, and covert C2 using Google Apps Script and DNS. The feed also includes a quarterly review of vulnerabilities, exploits, C2 frameworks, and emerging risks in open-source AI agents and frameworks.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 947489fd4db2422102d5d81c98dec8c47803d029cf43fdce38f7dd7df16ba779
- Enrichment time
- 2026-09-08T08:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.