HabrSeptember 18, 2026🇷🇺Translated from Russian

Network Traffic Analysis Reveals 75% Malware Threats Over 10 Months of Monitoring

Positive Technologies examined anonymized network traffic data collected over ten months to identify the most prevalent cyber threats. The analysis combined public incident reports, internal expertise, and results from PT Sandbox and PT Network Attack Discovery, covering the period from October 2025 to July 2026.

Malware Dominates Detected Threats

Malicious software represented 75% of all threats observed in network traffic. This category remains the primary attack method used against organizations regardless of industry. Within the malware samples, 50% were generic trojans, while 24% were information-stealing trojans. Of the spyware samples, 85% targeted credential theft and 15% focused on user activity monitoring.

Loaders and droppers accounted for 15% of malware detections, with 78% of that subset functioning as downloaders. Remote access trojans (RATs) made up 7%, including Remcos RAT and Async RAT. Ransomware comprised approximately 4% of samples, while worms were detected in only 2% of cases.

Potentially Unwanted Tools and Living-off-the-Land Binaries

Potentially unwanted tools represented 8% of detections. The most frequently observed utilities included PsExec, ProcDump, Mimikatz, and components from the NirSoft suite. These tools allow attackers to perform reconnaissance, credential dumping, and lateral movement while blending with legitimate administrative activity.

PowerShell-based frameworks such as PowerSploit and remote monitoring tools like UltraVNC were also identified. Network scanners such as Advanced IP Scanner appeared in reconnaissance phases.

Legacy Vulnerabilities and Delivery Methods

More than 96% of detected CVEs were at least three years old. Attackers continued to exploit CVE-2017-0199 and CVE-2017-11882 in Microsoft Office documents. Executable files accounted for 29% of detections, while Microsoft Office documents represented 26%.

Sector Distribution and Threat Actor Activity

The highest number of detections occurred in the financial sector (25%), followed by manufacturing (24%) and IT (24%). Signs of activity from known groups such as MustangPanda, TA505, and APT37 were recorded in the monitored traffic.

Related articles

BoletimSecMalware & Botnets

HEAVYGRAM Spyware Uses Telegram Bots for Command and Control Against Iranian Targets

Researchers at Group-IB have published a detailed analysis of HEAVYGRAM, a spyware family that abuses the Telegram messaging platform as its command-and-control infrastructure. The malware family was first observed in the second half of 2023 and has since been linked with moderate confidence to the Handala Hack group. Instead of operating dedicated servers, the operators rely on Telegram bots, accounts, and groups to register infected hosts, receive commands, exfiltrate stolen data, and deliver additional payloads. Once active, HEAVYGRAM captures screenshots, records audio, harvests cached files, and steals data from Telegram Desktop installed on the victim machine. The campaign primarily targets Iranian journalists, dissidents, and individuals opposed to the Iranian government. Infection vectors include malicious files distributed via messengers, disguised as legitimate applications such as Pictory, KeePass, or Telegram-related tools, sometimes delivered as HTML applications or scripts.

BoletimSecMalware & Botnets

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens in Brazil

Elastic Security Labs researchers have detailed the operations of the KREMLIN banking malware, tracked under the identifier REF9334, which targets Chrome and Edge browsers to harvest credentials and session tokens. The campaign focuses almost exclusively on Brazil, with 98 percent of the 1,515 identified infections located in the country and impersonating a dozen Brazilian banks. Infection begins with multi-stage JavaScript loaders disguised as banking documents, invoices, or corporate papers that require manual execution by the victim. The loaders then deploy C++ installers and malicious browser extensions that modify the Secure Preferences file, enable developer mode, and overwrite protection objects with forged metadata using a technique called Phantom Extension. Once active, the extension collects session tokens, cookies, sessionStorage and localStorage data, 15 days of browsing history, screenshots, open tab information, and full HTML of visited pages. The operation has run since May 2025 across seven distinct campaigns and began using Ethereum smart contracts for infrastructure on 19 May 2026.

BoletimSecMalware & Botnets

Malicious Twitch Extension Steals OAuth Tokens from Nearly 31,000 Users

A browser extension posing as an enhancement for Twitch has been stealing OAuth authentication tokens from approximately 31,000 users across Chrome and Firefox. The extension, known as Twitch Enhanced Viewer or JeetBot, was discovered by researcher Kush Pandya of Socket. It promised 1080p streaming in restricted regions and an ad-free experience while covertly exfiltrating session tokens to attacker-controlled servers. The tokens were transmitted in plaintext via network-layer redirects, allowing full access to chat functions, private messages, and account settings. Both the Chrome version with around 30,000 installations since June 26, 2025, and the Firefox version with 604 users since July 7, 2025, remained available in official stores at the time of reporting. Users are advised to immediately disable the extension and revoke active Twitch sessions to invalidate stolen tokens.

BoletimSecMalware & Botnets

Casbaneiro Banking Trojan Targets Financial Institutions in Argentina, Peru, Colombia and Mexico

Fortinet researchers identified a Casbaneiro campaign in August that specifically targets bank customers across four Latin American countries. The infection begins with a PDF attachment that displays the recipient's own email address to build credibility and creates urgency around an unpaid invoice or judicial notice. The PDF link performs IP-based geofencing, redirecting non-target visitors to Google or YouTube while delivering a Base64-encoded ZIP only to victims in the selected countries. Inside the archive, an HTA file downloads the legitimate AutoIt interpreter along with a compiled script and compressed payload, helping evade binary-focused defenses. The malware stays dormant until the victim visits a monitored banking website, at which point it activates its C2 channel, exfiltrates Outlook contact data, and can display bank-specific credential-harvesting overlays. Additional remote-access capabilities allow operators to control the keyboard, manipulate the clipboard, and execute arbitrary commands on the infected system.