GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration

Two-phase attacks with the GoSerpent backdoor, Stowaway RAT, ThumbcacheService and other tools aim to steal data from government entities in Southeast Asia. Continue reading GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration

GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration

Two-phase attacks with the GoSerpent backdoor, Stowaway RAT, ThumbcacheService and other tools aim to steal data from government entities in Southeast Asia. Continue reading GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration

Tomiris wreaks Havoc: New tools and techniques of the APT group

Kaspersky discloses new tools and techniques discovered in 2025 Tomiris activities: multi-language reverse shells, Havoc and AdaptixC2 open-source frameworks, communications via Discord and Telegram. Continue reading Tomiris wreaks Havoc: New tools and techniques of the APT group

HZ Rat backdoor for macOS attacks users of China’s DingTalk and WeChat

Kaspersky experts discovered a macOS version of the HZ Rat backdoor, which collects user data from WeChat and DingTalk messengers. Continue reading HZ Rat backdoor for macOS attacks users of China’s DingTalk and WeChat