Palo Alto's Unit 42 says an Iranian state-aligned actor it tracks as CL-STA-1178 posed as the Dubai Airports IT department to deliver trojanized coding challenges to high-value targets. Its report ties attacks other vendors reported one at a time into one campaign that hit Iraqi critical infrastructure in March 2026.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+15
- Incentives60
- Confidence45
Bitdefender says a China-nexus cluster hit Central Asian governments with seven RAT families, five undocumented. The AI fingerprint is in the workflow, not the code.
Reality
- Evidence60
- Adoption20
- Hype gap+10
- Incentives
- Insufficient
- Confidence58
Elastic Security Labs describes a Brazilian banking operation that edits a Chrome or Edge profile and then signs its own edit using the OSCrypt and App-Bound keys sitting on the same machine. The browser loads the extension as approved.
Reality
- Evidence62
- Adoption35
- Hype gap−10
- Incentives45
- Confidence58
Elastic Security Labs tied 1,515 infections, almost all in Brazil, to a loader that waits for Chrome to close and then writes its own extension into the profile directory with integrity hashes the browser accepts.
Reality
- Evidence58
- Adoption32
- Hype gap+10
- Incentives62
- Confidence55
Elastic Security Labs says the Brazilian crew it calls REF9334 has been running this since at least May 2025, writing its extension into Chromium's Secure Preferences and reading C2 addresses out of an Ethereum smart contract.
Reality
- Evidence62
- Adoption42
- Hype gap+12
- Incentives55
- Confidence58
Elastic documented four programs that stay in the user profile after the stealer wipes itself. The credential rotation that closes the ticket does not restore the update services or clear the Defender exclusions.
Reality
- Evidence60
- Adoption45
- Hype gap−10
- Incentives70
- Confidence58