The invisible passenger in your car
2026-08-21T20:51:46Z•fdf1f2836fe41b78374dd2ea7f7ff8a3becc06f8fdf7cf325d01ad53a73c867c
APTAiTMAnatsaAndroid-malwareArmored-LikhoCoolClientDNS-based-C2DNS-tunnelingGoogle-Apps-Script-C2Head-MareHoneyMyteIoT-securityKerberoastingMFA-bypassPhantomCorePhantomGraphTelegram-theftTrueConfWindows-backdooradwarecloud-phishingcyber-espionageeavesdroppingkernel-rootkitproxy-botnet
What happened
Kaspersky Securelist reporting from late July through August 2026 covering Android malware on vehicle head units, a HoneyMyte CoolClient backdoor with a kernel-level rootkit, Armored Likho cyber-espionage activity, Head Mare exploitation of unpatched TrueConf servers, Project CAV3RN C2 using Google Apps Script and DNS routing, phishing kits hosted on legitimate cloud platforms to bypass MFA, Anatsa mobile banking malware, and attack techniques including Kerberoasting and DNS tunneling. The collection represents active malware, APT, credential theft, evasion, and initial-access threats, but noC
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- fdf1f2836fe41b78374dd2ea7f7ff8a3becc06f8fdf7cf325d01ad53a73c867c
- Enrichment time
- 2026-08-21T20:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.