Kaspersky

Tech Optimizer
August 31, 2026
Silver Fox is linked to the distribution of a backdoor malware called ValleyRAT, disguised as the legitimate QN Wallpaper adware application. Once installed, ValleyRAT provides complete control over the compromised machine. The malware uses DLL sideloading to operate under the guise of a legitimate process, bypassing security measures. It disables Windows Defender and adds itself to autorun entries, and can mark its process as critical, causing system crashes if terminated. Kaspersky has identified specific indicators of compromise (IoCs) including hashes, command-and-control servers, and associated domains. In 2026, Kaspersky recorded over 100,000 detections of ValleyRAT affecting more than 1,500 unique users, mainly in China and India.
AppWizard
August 21, 2026
A new strain of Android malware has emerged, targeting automotive head units responsible for infotainment, connectivity, and navigation in vehicles. Discovered by Kaspersky in June, this is the first documented instance of malware affecting car head units, specifically within the firmware updaters of Android-based software developed by DoFun, a Hong Kong company. The malware, disguised as an application called JarService, infiltrates devices without user awareness. It is delivered through a legitimate system application called TWCore, which collects analytics and updates software. The malware aims to convert the head unit into a botnet, equipped with commands to download and execute code and display advertisements, potentially for online ad fraud. Kaspersky notified DoFun, which addressed the vulnerabilities, and noted similarities between this malware and a previous threat called BadBox, which affected various Android devices.
Tech Optimizer
August 18, 2026
Executing files directly from the temporary download folder is the primary gateway for infostealers targeting Windows systems, accounting for approximately 35% of analyzed infections. The second most common entry point is C:WindowsMicrosoft.NETFramework, appearing in 32% of cases and associated with advanced tactics like process injection. The findings are based on a report by Kaspersky, which analyzed five million records from the dark web. Malicious files often disguise themselves as legitimate software, such as fake codecs or program activators. Kaspersky recommends monitoring exposed assets and not disabling antivirus software during installations.
Search