#Securelist
MacSync's iCloud Calendar trick is pretty cool. One MacSync downloader analyzed by Securelist contains a URL such as: https://caldav.icloud[.]com/published/...

It retrieves a public .ics calendar, creates an anonymous pipe, launches zsh -s, sets the pipe as stdin, and feeds it into it line by line.
September 27, 2026 at 11:00 AM
MacSync maakt gebruik van complexe keten om cryptogeld en ontwikkelaars te targe

Onderzoekers van Securelist hebben in september 2026 een nieuwe, meer geavanceerde distributieketen ontdekt voor MacSync, een infostealer die gericht is op macOS-gebruikers. De malware richt zich specifiek op g...
MacSync maakt gebruik van complexe keten om cryptogeld en ontwikkelaars te targeten
Onderzoekers van Securelist hebben in september 2026 een nieuwe, meer geavanceerde distributieketen ontdekt voor MacSync, een infostealer die gericht is op macOS-gebruikers. De malware richt zich specifiek op gebruikers van cryptovaluta en ontwikkelaarstools. De distributieketen begint nu met schadelijke schijfkopiebestanden (DMG's) die zich voordoen als legitieme applicaties. Deze DMG's bevatten een applicatiebundel en zijn een significante verandering ten opzichte van eerdere methoden die voornamelijk vertrouwden op het plakken van Terminal-commando's. Slachtoffers kunnen de malware tegenkomen via valse of gekraakte software, zoals een fictieve crypto-portemonnee-applicatie genaamd Toria,...
newsfacts.info
September 25, 2026 at 8:30 AM
SecureList: APT trends report Q3 2024 https://securelist.com/apt-report-q3-2024/114623/

Notably, a new attack framework named P8 was identified, targeting Vietnamese financial institutions, showcasing sophisticated espionage capabilities. The report also discusses the emergence of Trojanized […]
Original post on swecyb.com
swecyb.com
November 28, 2024 at 12:15 PM
PAYLOAD ransomware attacks through Active Directory GPO | Securelist securelist.com/tr/payload-r...
PAYLOAD ransomware attacks through Active Directory GPO
Kaspersky GERT experts dive into the technical incident analysis of PAYLOAD ransomware: an encryptionless, binary-less operation that abused Active Directory mechanisms for managing Group Policy Objec...
securelist.com
September 22, 2026 at 10:16 AM
Industrial threat report for Q3 2025 | Securelist securelist.com/industrial-t...
Threat landscape for industrial automation systems in Q3 2025
The report contains statistics on various threats detected and blocked on ICS computers in Q3 2025, including miners, ransomware, spyware, etc.
securelist.com
December 26, 2025 at 6:59 AM
CVE-2024-2658 vulnerability in Schneider Electric software: risks to industrial control systems | Securelist securelist.com/tr/schneider...
CVE-2024-2658 vulnerability in Schneider Electric software: risks to industrial control systems
Analysis of CVE-2024-2658 as found in Schneider Electric's Floating License Manager. Discover how this FlexNet Publisher vulnerability potentially allows attackers to escalate to NT AUTHORITY\SYSTEM p...
securelist.com
June 28, 2026 at 5:01 AM
New GenieLocker ransomware for Windows, ESXi, and Linux | Securelist

Kaspersky experts dissect GenieLocker: new custom ransomware variants for Windows, Linux, and ESXi syste

Read more: https://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/120843/
July 31, 2026 at 6:18 AM
📢 Watering hole sur cpuid.com : installateurs CPU-Z et HWMonitor trojanisés avec STX RAT
📝 ## 🔍 Contexte

Source : Securelist (Kaspersky), publ…
https://cyberveille.ch/posts/2026-04-12-watering-hole-sur-cpuid-com-installateurs-cpu-z-et-hwmonitor-trojanises-avec-stx-rat/ #DLL_sideloading #Cyberveille
April 12, 2026 at 4:30 PM
Released a PowerSmell IoC triage script for detecting the Notepad++ supply chain attack, including the previously known @rapid7.com IoCs and now the newly released IoCs for chains 1 (ProShow) & 2 (Lua/Adobe) published by Securelist/Kaspersky:

github.com/moltenbit/No...

#potatosecurity
February 4, 2026 at 10:54 AM
📢 Dizaines de fonds d'écran malveillants sur Steam Workshop : comptes de joueurs compromis
📝 🗓️ **Source** : Securelist (Kaspersky) — Publication le…
https://cyberveille.ch/posts/2026-06-21-dizaines-de-fonds-d-ecran-malveillants-sur-steam-workshop-comptes-de-joueurs-compromis/ #DarkKomet #Cyberveille
June 21, 2026 at 7:30 PM
Stolen crypto accounts are selling for as little as $60 on the dark web (up to $400!), per SecureList. Phishing is the main attack vector, with Telegram now preferred for data sharing. Protect your 2FA! #crypto #security #phishing
December 28, 2025 at 11:46 PM
AmCache artifact: forensic value and a tool for data extraction | Securelist securelist.com/amcache-fore...
AmCache artifact: forensic value and a tool for data extraction
Kaspersky experts share insights into how AmCache may prove useful during incident investigation, and provide a command line tool to extract data from this artifact.
securelist.com
October 2, 2025 at 9:12 AM
Reviewing the trends in ransomware attacks in 2026 | Securelist securelist.com/state-of-ran...
Reviewing the trends in ransomware attacks in 2026
Kaspersky researchers are sharing insights into the main ransomware trends for 2026: EDR killers on the rise, switching from data encryption to data leaks, and more.
securelist.com
May 13, 2026 at 5:58 AM
New Mandrake Spyware Found in Google Play Store Apps After Two Years - The Hacker News: * New Mandrake Spyware Found in Google Play Store Apps After Two Years  The Hacker News
* New Mandrake Android spyware version discovered on Google Play  Securelist
* Mysterious family of malware hid in Google…
New Mandrake Spyware Found in Google Play Store Apps After Two Years - The Hacker News
* New Mandrake Spyware Found in Google Play Store Apps After Two Years  The Hacker News * New Mandrake Android spyware version discovered on Google Play  Securelist * Mysterious family of malware hid in Google Play for years  Ars Technica * Android…
dlvr.it
July 31, 2024 at 4:04 AM
The Solidity Language open-source package was used in a $500,000 crypto heist | Securelist securelist.com/open-source-...
The Solidity Language open-source package was used in a $500,000 crypto heist
Kaspersky GReAT experts uncover malicious extensions for Cursor AI that download the Quasar backdoor and a crypto stealer.
securelist.com
July 12, 2025 at 10:35 AM
GenieLocker : le ransomware sans note de rançon qui vise Windows, Linux et ESXi

Abandonner les rançongiciels clés en main du darknet pour concevoir leur propre arme : le groupe Toy Ghouls déploie GenieLocker sur...

https://goodtech.info/genielocker-ransomware-sur-mesure-windows-linux-esxi/
GenieLocker : le ransomware sans note de rançon qui vise Windows, Linux et ESXi
Abandonner les rançongiciels clés en main du darknet pour concevoir leur propre arme : le groupe Toy Ghouls déploie GenieLocker sur Windows, Linux et VMware ESXi. Un binaire furtif qui masque ses traces en supprimant les notes de rançon automatiques. Analyse. Les chercheurs de l'équipe Securelist chez Kaspersky viennent de détailler le fonctionnement de GenieLocker,...
goodtech.info
August 4, 2026 at 3:28 AM
📢 MovieReaper : framework modulaire distribué via torrents compromis, C2 sur blockchain Solana

📰 Source : Securelist (Kaspersky) — Publication le 17 septembre 2026, auteurs : Konstantin Isakov et Pavel Cheremushkin. 🎯 Contexte…

🟢 vérification factuelle haute
#MovieReaper #Solana #Cyberveille
MovieReaper : framework modulaire distribué via torrents compromis, C2 sur blockchain Solana
📰 Source : Securelist (Kaspersky) — Publication le 17 septembre 2026, auteurs : Konstantin Isakov et Pavel Cheremushkin. 🎯 Contexte Depuis mi-août 2026, Kaspersky a identifié une campagne de distribution massive de malware déguisé en films populaires via des trackers torrent. L'activité de l'acteur remonte à octobre 2025.
cyberveille.ch
September 18, 2026 at 10:30 AM
We included some great links to the broader cybersecurity community in the blog including @cyb3rops.bsky.social and
@rapid7.com. In addition, Securelist just released a detailed blog with additional IOCs and analysis that's worth checking out: securelist.com/notepad-supp...
The Notepad++ supply chain attack – unnoticed execution chains and new IoCs
Kaspersky GReAT experts discovered previously undocumented infection chains used in the Notepad++ supply chain attacks. The article provides new IoCs related to those incidents which employ DLL sidelo...
securelist.com
February 3, 2026 at 2:57 PM