Threat landscape for industrial automation systems. Q2 2026
2026-08-28T08:51:47Z•ae95ac7cd2f51bdaefb415878f2d24bd6fb8ae781c37fbf029877053fa4d1119
AI-framework-securityAndroid-malwareArmored-LikhoCoolClientHead-MareHoneyMyteICSOT-securityPhantomCorePhantomGraph、Google-Apps-Script-C2,DNS-based-C2,.NET-NativeAOT,云Q2-2026Telegram-targetingTrueConfadwarecryptominingcyber-espionageexploitsindustrial-control-systemskernel-rootkitproxy-botnetransomwarerootkitspywarethreat-landscapevulnerabilities
What happened
Kaspersky Securelist threat-intelligence feed covering Q2 2026 industrial, enterprise, mobile, IoT, vulnerability, phishing, and advanced persistent threat activity. Highlights include ransomware and other threats against industrial control systems; vulnerabilities in traditional software and open-source AI frameworks; Android adware/proxy botnet malware; HoneyMyte’s CoolClient kernel-level rootkit; Armored Likho espionage targeting Telegram data; Head Mare exploitation of unpatched TrueConf servers; Google Apps Script and DNS-based C2 evasion; and cloud-hosted adversary-in-the-middle phishing
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- ae95ac7cd2f51bdaefb415878f2d24bd6fb8ae781c37fbf029877053fa4d1119
- Enrichment time
- 2026-08-28T08:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.