Skip to content

company

Kaspersky

Russian cybersecurity company offering antivirus and endpoint security products, plus threat intelligence via Securelist, GERT and ICS CERT.

Known aliases

  • GERT
  • Global Emergency Response Team
  • Kaspersky Endpoint Security
  • Kaspersky GERT
  • Kaspersky ICS CERT
  • Kaspersky Lab
  • Kaspersky security solutions
  • Securelist

Relationships

No evidence-backed relationships are recorded.

Current stories

security3 publishers

Microsoft says China-linked operators hand-install NeedyMantis to keep hold of breached networks

Microsoft says China-linked operators have used NeedyMantis since at least October 2025 to keep access to telecom, university and government-linked networks. It goes in after the break-in, so defenders have to hunt for it inside networks already breached.

Perspective Coverage

3 publishers
Builder
Builder 22%
Operator
Operator 67%
Investor
Investor 11%

Reality

Evidence62
Adoption
Insufficient
Hype gap+18
Incentives40
Confidence60
security4 publishers

Two TrueConf Server flaws hit KEV, and BOD 26-04 turns them into a compromise check

CISA says CVE-2026-72529 and CVE-2026-72530 are under active exploitation. For federal civilian agencies, patching an exposed instance is only half of the obligation.

Perspective Coverage

4 publishers
Builder
Builder 25%
Operator
Operator 68%
Investor
Investor 7%

Reality

Evidence72
Adoption
Insufficient
Hype gap+5
Incentives35
Confidence70
security8 publishers

The firmware updater in the dashboard: car head units enrolled into a proxy botnet

Kaspersky says malware reached Android car head units through the vendor's own update mechanism, using a flag that installs apps the device never had. The payload has no interface at all.

Perspective Coverage

8 publishers
Builder
Builder 36%
Operator
Operator 50%
Investor
Investor 14%

Reality

Evidence70
Adoption
Insufficient
Hype gap+20
Incentives45
Confidence68
security4 publishers

Dark Caracal's Ethereum fallback moves C2 recovery off the names defenders can seize

Arctic Wolf links a June 2026 intrusion in Venezuela to a new Go framework whose extended build reads replacement C2 addresses from a smart contract, and says the feature has been used.

Perspective Coverage

4 publishers
Builder
Builder 34%
Operator
Operator 57%
Investor
Investor 9%

Reality

Evidence60
Adoption
Insufficient
Hype gap+20
Incentives40
Confidence58
security4 publishers

Silver Fox delivered ValleyRAT through signed adware that users whitelist themselves

Kaspersky traced one submitted installer to a modified Chinese wallpaper tool whose signed executable sideloads a malicious libcef.dll, and the same installer switches Windows Defender off before it ever runs.

Perspective Coverage

4 publishers
Builder
Builder 24%
Operator
Operator 67%
Investor
Investor 9%

Reality

Evidence72
Adoption
Insufficient
Hype gap+15
Incentives30
Confidence66
security4 publishers

Mirage Kitten ships Node.js RATs through fake LinkedIn coding challenges

Kaspersky found two cross-platform JavaScript RATs, NodeRabbit and PollCat, reaching engineers in aviation and fintech through fake recruiters, from a group that until now shipped native C, C++ and Go.

Perspective Coverage

4 publishers
Builder
Builder 45%
Operator
Operator 49%
Investor
Investor 6%

Reality

Evidence70
Adoption
Insufficient
Hype gap+15
Incentives35
Confidence65
security6 publishers

DOJ extradites a Russian accused of pushing macro malware through 255 fake marketplace accounts

A Northern California freelance marketplace's own messaging system carried Excel macro lures to 80,000 of its users across 18 months. Microsoft closed that delivery step in 2022. The same platform lure now shows up in North Korean operations.

Perspective Coverage

6 publishers
Builder
Builder 17%
Operator
Operator 78%
Investor
Investor 5%

Reality

Evidence70
Adoption
Insufficient
Hype gap+20
Incentives
Insufficient
Confidence68
security5 publishers

FalconFlank PoC turns CrowdStrike's macro cleanup into a local privilege escalation

Chaotic Eclipse published working code that abuses Falcon's Office macro removal on fully patched Windows 11 25H2 and Server 2025. It is the fourth endpoint product the researcher has dropped exploit code for, and no CrowdStrike response is on record.

Perspective Coverage

5 publishers
Builder
Builder 36%
Operator
Operator 51%
Investor
Investor 13%

Reality

Evidence70
Adoption
Insufficient
Hype gap+10
Incentives55
Confidence68
security4 publishers

Check Point patches unauthenticated root code execution in Security Management and Log Server

CVE-2026-91843 lets an attacker with no credentials run code as root through the login process, and Check Point has published indicators of compromise while saying it has seen no exploitation in the wild.

Perspective Coverage

4 publishers
Builder
Builder 16%
Operator
Operator 75%
Investor
Investor 9%

Reality

Evidence80
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence78
security3 publishers

NightEagle is entering Russian corporate VPNs with valid stolen credentials

Kaspersky's incident response team says the group, previously seen working against targets in Asia, logged into VPNs from Cloudflare WARP and European hosting addresses, then ran the GhostContainer backdoor in memory on Exchange.

Perspective Coverage

3 publishers
Builder
Builder 20%
Operator
Operator 70%
Investor
Investor 10%

Reality

Evidence60
Adoption
Insufficient
Hype gap+5
Incentives40
Confidence58

Earlier coverage

  1. Tortoiseshell's 'uk1' and 'uk2': Iranian espionage crew now has servers in Britain

    Security · August 26, 2026 · 3 publishers

  2. Kaspersky's CVE surge has two sources, and only one of them lands in the CVE count

    Security · August 26, 2026 · 1 publisher

  3. QUICSILVER runs its C2 over QUIC, and most port-443 inspection is scoped to TCP

    Security · August 24, 2026 · 1 publisher

  4. CISA puts TrueConf Server in the exploited bucket, and port 4307/TCP does not care about your LAN

    Security · August 21, 2026 · 1 publisher

  5. Cavern's DNS Coin-Flip: When Google Apps Script Becomes Rotatable C2 Plumbing

    Security · August 18, 2026 · 1 publisher