- The HoneyMyte APT evolves with a kernel-mode rootkit and a ToneShell backdoorby Noushin Shabab on December 29, 2025 at 10:00 am
Kaspersky discloses a 2025 HoneyMyte (aka Mustang Panda or Bronze President) APT campaign, which uses a kernel-mode rootkit to deliver and protect a ToneShell backdoor.
- Threat landscape for industrial automation systems in Q3 2025by Kaspersky ICS CERT on December 25, 2025 at 10:00 am
The report contains statistics on various threats detected and blocked on ICS computers in Q3 2025, including miners, ransomware, spyware, etc.
- Evasive Panda APT poisons DNS requests to deliver MgBotby Fatih Şensoy on December 24, 2025 at 7:00 am
Kaspersky GReAT experts analyze the Evasive Panda APT’s infection chain, including shellcode encrypted with DPAPI and RC5, as well as the MgBot implant.
- Assessing SIEM effectivenessby Andrey Tamoykin on December 23, 2025 at 12:00 pm
We share the results of assessing the effectiveness of Kaspersky SIEM in real-world infrastructures and explore common challenges and solutions to these.
- From cheats to exploits: Webrat spreading via GitHubby Maxim Starodubov on December 23, 2025 at 8:00 am
We dissect the new Webrat campaign where the Trojan spreads via GitHub repositories, masquerading as critical vulnerability exploits to target cybersecurity researchers.
- Cloud Atlas activity in the first half of 2025: what changedby Kaspersky on December 19, 2025 at 10:00 am
Kaspersky expert describes new malicious tools employed by the Cloud Atlas APT, including implants of their signature backdoors VBShower, VBCloud, PowerShower, and CloudAtlas.
- Yet another DCOM object for lateral movementby Haidar Kabibo on December 19, 2025 at 8:00 am
Kaspersky expert describes how DCOM interfaces can be abused to load malicious DLLs into memory using the Windows Registry and Control Panel.
- Operation ForumTroll continues: Russian political scientists targeted using plagiarism reportsby Georgy Kucherin on December 17, 2025 at 10:00 am
Kaspersky’s GReAT experts have uncovered a new wave of cyberattacks by the ForumTroll APT group, targeting Russian political scientists and delivering the Tuoni framework to their devices.
- God Mode On: how we attacked a vehicle’s head unit modemby Alexander Kozlov, Sergey Anufrienko, Kaspersky ICS CERT on December 16, 2025 at 10:00 am
Kaspersky researchers describe how they gained access to a vehicle’s head unit by exploiting a single vulnerability in its modem.
- Frogblight threatens you with a court case: a new Android banker targets Turkish usersby Georgy Bubenok on December 15, 2025 at 7:00 am
Kaspersky researchers have discovered a new Android banking Trojan targeting Turkish users and posing as an app for accessing court case files via an official government webpage. The malware is being actively developed and may become MaaS in the future.
Securelist
We are an ethical website cyber security team and we perform security assessments to protect our clients.

















