The invisible passenger in your car

2026-08-25T20:51:46Zb10b4898b62f85d0359ae248075576b6d6982e1c2ed90c73e8f8d6e49dec7372
.NET NativeAOTAPTAndroid malwareArmored LikhoCoolClientDNS-based C2Google Apps Script C2Head MareHoneyMyteKerberoasting(DNS tunneling)MFA bypassPhantomCorePhantomGraphTelegram theftTrueConfWindowsadversary-in-the-middle phishingadwareautomotive head unitscloud abusecyber espionageeavesdroppingkernel rootkitproxy botnetunpatched vulnerabilities

What happened

Kaspersky Securelist reporting from July–August 2026 covering Android head-unit malware used for advertising and proxy botnet activity; a HoneyMyte CoolClient variant with a kernel-level Windows rootkit; Armored Likho cyber-espionage targeting Telegram data and audio; Head Mare exploitation of unpatched TrueConf servers to deploy PhantomCore and PhantomGraph; Project CAV3RN using Google Apps Script and DNS-based C2; MFA-bypassing adversary-in-the-middle phishing hosted on legitimate cloud platforms; and broader malware, incident-response, Kerberoasting, and DNS-tunneling trends.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
b10b4898b62f85d0359ae248075576b6d6982e1c2ed90c73e8f8d6e49dec7372
Enrichment time
2026-08-25T20:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.