Sponsor of the Day:
Jerkmate
https://securelist.com/soc-files-web-shell-chase/115714/
Kaspersky SOC analyzes an incident involving a web shell used as a backdoor | Securelist
Sep 8, 2025 - Kaspersky SOC analysts discuss a recent incident where the well-known Behinder web shell was used as a post-exploitation backdoor, showing how web shells have...
incident involvingweb shellbackdoor securelistkasperskysoc
https://securelist.com/how-we-protect-against-sunburst-backdoor/99959/
How we protect our users against the Sunburst backdoor | Securelist
May 17, 2021 - The detection logic has been improved in all our solutions to ensure our customers protection.
backdoor securelistprotectuserssunburst
https://securelist.com/mysterysnail-new-version/116226/
New version of MysterySnail RAT and lightweight MysteryMonoSnail backdoor | Securelist
Oct 6, 2025 - MysterySnail RAT attributed to IronHusky APT group hasn’t been reported since 2021. Recently, Kaspersky GReAT detected new versions of this implant in...
new versionbackdoor securelistratlightweight
https://securelist.com/tag/backdoor/
Tag: Backdoor | Securelist
backdoor securelisttag
https://securelist.com/pipemagic/117270/
PipeMagic in 2025: How the backdoor operators’ tactics have changed | Securelist
Aug 25, 2025 - We examine the evolution of the PipeMagic backdoor and the TTPs of its operators – from the RansomExx incident in 2022 to attacks in Brazil and the Middle...
2025backdoortacticschangedsecurelist
https://securelist.com/ghostcontainer/116953/
GhostContainer backdoor for Exchange servers | Securelist
Jul 23, 2025 - In an incident response case in Asia, Kaspersky researchers discovered a new backdoor for Microsoft Exchange servers, based on open-source tools and dubbed...
exchange serversbackdoorsecurelist
https://securelist.com/loki-agent-for-mythic/113596/
A new version of the Loki backdoor for the Mythic framework attacks Russian companies | Securelist
Sep 9, 2024 - Kaspersky experts have discovered a new version of the Loki agent for the open-source Mythic framework, which uses DLLs to attack Russian companies.
new versionrussian companieslokibackdoormythic