The invisible passenger in your car

2026-08-21T20:51:46Zfdf1f2836fe41b78374dd2ea7f7ff8a3becc06f8fdf7cf325d01ad53a73c867c
APTAiTMAnatsaAndroid-malwareArmored-LikhoCoolClientDNS-based-C2DNS-tunnelingGoogle-Apps-Script-C2Head-MareHoneyMyteIoT-securityKerberoastingMFA-bypassPhantomCorePhantomGraphTelegram-theftTrueConfWindows-backdooradwarecloud-phishingcyber-espionageeavesdroppingkernel-rootkitproxy-botnet

What happened

Kaspersky Securelist reporting from late July through August 2026 covering Android malware on vehicle head units, a HoneyMyte CoolClient backdoor with a kernel-level rootkit, Armored Likho cyber-espionage activity, Head Mare exploitation of unpatched TrueConf servers, Project CAV3RN C2 using Google Apps Script and DNS routing, phishing kits hosted on legitimate cloud platforms to bypass MFA, Anatsa mobile banking malware, and attack techniques including Kerberoasting and DNS tunneling. The collection represents active malware, APT, credential theft, evasion, and initial-access threats, but noC

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
fdf1f2836fe41b78374dd2ea7f7ff8a3becc06f8fdf7cf325d01ad53a73c867c
Enrichment time
2026-08-21T20:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.