The invisible passenger in your car
2026-08-24T08:51:47Z•9cec284cfe6d4098ff22900c22bebc6a649c79e9fa75549207fc8b19feaf96e0
AiTM-phishingAndroidArmored-LikhoCoolClientDNS-based-C2DNS-tunnelingGoogle-Apps-Script-C2Head-MareHoneyMyteKerberoastingMFA-bypassPhantomCorePhantomGraphTelegram-theftTrueConfautomotive-head-unitscloud-platform-abusecyber-espionageeavesdroppingeducation-sectorkernel-rootkitmalwareproxy-botnetservice-workersthreat-intelligence
What happened
Kaspersky Securelist threat intelligence feed covering August 2026 reporting on Android malware targeting automotive head units, HoneyMyte’s kernel-level CoolClient rootkit, Armored Likho cyber-espionage activity, Head Mare exploitation of unpatched TrueConf servers, Project CAV3RN C2 techniques, quarterly malware statistics, cloud-hosted adversary-in-the-middle phishing that bypasses MFA, Brazilian education-sector incidents, and detection of Kerberoasting and DNS tunneling. The collection describes active malware, espionage campaigns, rootkits, server exploitation, phishing, and covert C2,,但
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 9cec284cfe6d4098ff22900c22bebc6a649c79e9fa75549207fc8b19feaf96e0
- Enrichment time
- 2026-08-24T08:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.