Skip to content

Kaspersky vulnerabilities

In this reporting period, Kaspersky features prominently through threat discoveries by its GReAT team and security research. Key themes include the Project CAV3RN module abusing Outlook calendar for C2, the OkoBot malware framework targeting cryptocurrency users, and a large-scale campaign delivering AsyncRAT via compromised ScreenConnect software. Analysis also covers new malware (NightLedger, ArcBridge) from the Mirage Kitten group and GenieLocker ransomware from Toy Ghouls. Defenders should focus on stealthy C2 channels leveraging legitimate cloud services (Microsoft Graph, EC2) and remain vigilant against supply chain threats and targeted ransomware attacks.

Azərbaycanca: Hesabat dövründə Kaspersky, əsasən öz GReAT komandasının kəşf etdiyi mürəkkəb təhdidlər və təhlükəsizlik araşdırmaları ilə diqqət mərkəzindədir. Əsas diqqətçəkən mövzular sırasına Outlook təqvimini C2 rabitəsi üçün istismar edən Project CAV3RN modulu, kriptovalyuta istifadəçilərini hədəfləyən OkoBot zərərli proqramı və AsyncRAT yaymaq üçün ScreenConnect proqramını sui-istifadə edən genişmiqyaslı kampaniya daxildir. Bundan əlavə, Mirage Kitten qrupuna aid yeni zərərli proqramlar (NightLedger, ArcBridge) və Toy Ghouls qrupunun GenieLocker ransomware-i təhlil edilib. Müdafiəçilər xüsusilə qanuni bulud xidmətləri (Microsoft Graph, EC2) üzərindən gizli C2 infrastrukturlarının qurulması və təchizat zənciri təhdidlərinə qarşı sayıq olmalıdırlar.

This hub is built from skopnix's own reporting on Kaspersky: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.