
Findings and evidence
Kaspersky describes several incidents involving valid VPN credentials, the GhostContainer backdoor on Exchange and network-tunneling tools. The report distinguishes observed artifacts from its assessment of how the backdoor reached the servers.
Why it matters
An investigation should join identity events, server evidence and outbound network records into one timeline. Retaining only workstation alerts can leave gaps when the activity is concentrated on shared infrastructure.
Scope and limits
The researchers could not determine the precise delivery method in every case. Their proposed explanation and attribution remain assessments, not independently proven facts about every affected environment.
Primary source
Kaspersky / Securelist: original publication. Source published 2026-09-16. Brief prepared by websec.gr on 26 September 2026. This is an editorial research summary, not a claim of independent replication.