
유진 카스퍼스키
@e_kaspersky · 유럽
이스라엘국은 유럽 섹션의 러시아 관련 연구·분야별 전문지식 보도를 위해 유진 카스퍼스키를 팔로우합니다.
The financially motivated Toy Ghouls group, which has been attacking Russian organizations since 2025, is expanding its toolkit: in addition to the GenieLocker ransomware, we’ve detected use of its own backdoor for the first time – two versions at once, with non-standard C2 channels (the HiveMQ MQTT broker and the Element messenger). Details: https://t.co/jMfcMePzw4
The Mirage Kitten APT’s toolkit is evolving: we’re exploring its two previously undocumented cross-platform RATs – NodeRabbit and PollCat – that are targeting aviation and FinTech sectors across the Middle East and Africa. Spear-phishing (fake recruiters and trojanized coding challenges) is the key attack vector. These RATs mark the group's first documented use of Node.js/JavaScript malware. Full analysis: https://t.co/nnvf1gxYeT
A while ago we were tasked to analyze a file with an initial classification as adware. A deeper research turned up suspicious network activity - the sample did far more than serve ads. In fact, its advertising functionality doesn’t even work; instead, it triggers an infection chain that delivers the ValleyRAT backdoor. More details 👉 https://t.co/O9gjknTxdP
An in-depth research of the malware spread through the built-in updaters of Android-based automotive head unit firmware. This is the first documented case of malware found on a car head unit with an infection chain specific to that type of device. 👉 https://t.co/G0xYchaFTF https://t.co/WLP4NASxHo