Microsoft says China-linked operators have used NeedyMantis since at least October 2025 to keep access to telecom, university and government-linked networks. It goes in after the break-in, so defenders have to hunt for it inside networks already breached.
Perspective Coverage
3 publishers
- Builder
- Builder 22%
- Operator
- Operator 67%
- Investor
- Investor 11%
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+18
- Incentives40
- Confidence60
Microsoft says China-aligned NeedyMantis malware, active since at least October 2025, is installed after attackers already have access, to keep it long term. Because entry routes vary, organisations in the five sectors it targets need to look for copies already installed.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap0
- Incentives40
- Confidence60
Securelist says the newest CoolClient deploys a signed kernel-mode driver as a Windows service to hide its process, files and registry keys. It was seen in Pakistan, Mongolia and Myanmar.
Reality
- Evidence62
- Adoption30
- Hype gap+10
- Incentives35
- Confidence60
Bitdefender says a China-nexus cluster hit Central Asian governments with seven RAT families, five undocumented. The AI fingerprint is in the workflow, not the code.
Reality
- Evidence60
- Adoption20
- Hype gap+10
- Incentives
- Insufficient
- Confidence58
CISA says CVE-2026-72529 and CVE-2026-72530 are under active exploitation. For federal civilian agencies, patching an exposed instance is only half of the obligation.
Perspective Coverage
4 publishers
- Builder
- Builder 25%
- Operator
- Operator 68%
- Investor
- Investor 7%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+5
- Incentives35
- Confidence70
Kaspersky says malware reached Android car head units through the vendor's own update mechanism, using a flag that installs apps the device never had. The payload has no interface at all.
Perspective Coverage
8 publishers
- Builder
- Builder 36%
- Operator
- Operator 50%
- Investor
- Investor 14%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+20
- Incentives45
- Confidence68
Arctic Wolf links a June 2026 intrusion in Venezuela to a new Go framework whose extended build reads replacement C2 addresses from a smart contract, and says the feature has been used.
Perspective Coverage
4 publishers
- Builder
- Builder 34%
- Operator
- Operator 57%
- Investor
- Investor 9%
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+20
- Incentives40
- Confidence58
Kaspersky traced one submitted installer to a modified Chinese wallpaper tool whose signed executable sideloads a malicious libcef.dll, and the same installer switches Windows Defender off before it ever runs.
Perspective Coverage
4 publishers
- Builder
- Builder 24%
- Operator
- Operator 67%
- Investor
- Investor 9%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+15
- Incentives30
- Confidence66
Kaspersky found two cross-platform JavaScript RATs, NodeRabbit and PollCat, reaching engineers in aviation and fintech through fake recruiters, from a group that until now shipped native C, C++ and Go.
Perspective Coverage
4 publishers
- Builder
- Builder 45%
- Operator
- Operator 49%
- Investor
- Investor 6%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+15
- Incentives35
- Confidence65
A Northern California freelance marketplace's own messaging system carried Excel macro lures to 80,000 of its users across 18 months. Microsoft closed that delivery step in 2022. The same platform lure now shows up in North Korean operations.
Perspective Coverage
6 publishers
- Builder
- Builder 17%
- Operator
- Operator 78%
- Investor
- Investor 5%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence68
Microsoft Defender Experts says fake Kaspersky, Razer and Calibre download sites all funnel to one delivery host that rebuilds the installer per request, which leaves hash blocking almost nothing durable to match.
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+12
- Incentives40
- Confidence70
Chaotic Eclipse published working code that abuses Falcon's Office macro removal on fully patched Windows 11 25H2 and Server 2025. It is the fourth endpoint product the researcher has dropped exploit code for, and no CrowdStrike response is on record.
Perspective Coverage
5 publishers
- Builder
- Builder 36%
- Operator
- Operator 51%
- Investor
- Investor 13%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+10
- Incentives55
- Confidence68
CVE-2026-91843 lets an attacker with no credentials run code as root through the login process, and Check Point has published indicators of compromise while saying it has seen no exploitation in the wild.
Perspective Coverage
4 publishers
- Builder
- Builder 16%
- Operator
- Operator 75%
- Investor
- Investor 9%
Reality
- Evidence80
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence78
Kaspersky's incident response team says the group, previously seen working against targets in Asia, logged into VPNs from Cloudflare WARP and European hosting addresses, then ran the GhostContainer backdoor in memory on Exchange.
Perspective Coverage
3 publishers
- Builder
- Builder 20%
- Operator
- Operator 70%
- Investor
- Investor 10%
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+5
- Incentives40
- Confidence58
Kaspersky says a new MacSync variant hides its payload commands in public iCloud calendar events and downloads the next stage from iCloud. Both the instructions and the download ride trusted Apple domains, past defenses that block known-bad hosts.
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence68
Kaspersky says the macOS stealer it first tracked as Mac.c has swapped script droppers for FAT Mach-O binaries in a chain found in September 2026, and its loader now reads shell commands out of a public iCloud calendar file.
Reality
- Evidence68
- Adoption32
- Hype gap0
- Incentives58
- Confidence58
Kaspersky says a previously unknown multi-stage loader has spread since mid-August through a compromised public torrent archive. It reaches its command server through the Solana blockchain. Victims include government and transport organisations.
Reality
- Evidence32
- Adoption30
- Hype gap+35
- Incentives85
- Confidence50
Kaspersky's responders found no encrypted files and no malware on disk across the Windows estate of a Middle East manufacturer in April 2026. The impact arrived through one Group Policy Object linked at the domain root.
Reality
- Evidence62
- Adoption35
- Hype gap+12
- Incentives72
- Confidence58
Kaspersky says the trojanized torrents come from itorrents.org, the file archive many trackers pull from, and that the archive was still returning substituted files when the report went out. Organizations are among the several hundred victims.
Reality
- Evidence62
- Adoption52
- Hype gap+6
- Incentives58
- Confidence55
Kaspersky's Q2 2026 industrial telemetry puts the global figure at 19.15%, with Africa at 27.9%, Northern Europe at 8.1%, and the biometrics sector worse than every region but one.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+8
- Incentives68
- Confidence55