The invisible passenger in your car
2026-08-24T20:51:46Z•fe2d4ffd3963ae4acc065247683df03d01bdfd5111a5cc0b2570c92429d0caf1
APTAiTMAndroid malwareArmored LikhoCoolClientDNS tunnelingGoogle Apps Script C2Head MareHoneyMyteKerberoastingMFA phishingPhantomCorePhantomGraphProject CAV3RNStill ToolkitTelegram theftTrueConf exploitationWindowsautomotive head unitcloud abusecyber espionageeducation sectorkernel rootkitmacOSproxy botnet
What happened
Kaspersky Securelist reporting from July–August 2026 covers diverse threats, including Android malware embedded in legitimate DoFun vehicle head-unit software that serves ads and builds a proxy botnet; HoneyMyte’s CoolClient backdoor with a kernel-mode rootkit; Armored Likho espionage using the Still Toolkit to steal Telegram data and conduct eavesdropping; Head Mare exploitation of unpatched TrueConf servers to deliver PhantomCore and PhantomGraph; Project CAV3RN using Google Apps Script relays and DNS-based C2 selection; cloud-hosted adversary-in-the-middle phishing designed to bypass MFA; Q
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- fe2d4ffd3963ae4acc065247683df03d01bdfd5111a5cc0b2570c92429d0caf1
- Enrichment time
- 2026-08-24T20:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.