SOCRadar tied 5,434 infostealer records for AI tools to 1,500 corporate email addresses at 482 large enterprises. The report says those AI accounts belong under the same sign-on and session controls as a company's identity provider and code repositories.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+35
- Incentives85
- Confidence40
SOCRadar found captured ChatGPT sessions at 358 of the 482 companies whose AI accounts turned up in 90 days of infostealer logs. The firm ties the spread to shadow AI, with employees opening work-email accounts that IT never sees.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence45
A ReliaQuest employee gave up a password and an MFA push five days after the company named the .claims campaign. Device trust, not training, kept the session worthless.
Perspective Coverage
5 publishers
- Builder
- Builder 29%
- Operator
- Operator 56%
- Investor
- Investor 15%
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+25
- Incentives70
- Confidence62
SOCRadar's teardown of the AnonyMousKIT service found 200 AI-voiced calls at about $0.10 each, most of them to Brazil. The skill in phone social engineering is now a script file.
Perspective Coverage
4 publishers
- Builder
- Builder 19%
- Operator
- Operator 76%
- Investor
- Investor 5%
Reality
- Evidence70
- Adoption40
- Hype gap+35
- Incentives40
- Confidence65
SOCRadar says the toolkit needs administrative or code execution access first, then writes itself into Chrome and Edge profiles with integrity values the browser accepts and bridges to a native host binary that runs shell commands.
Reality
- Evidence58
- Adoption10
- Hype gap+12
- Incentives
- Insufficient
- Confidence55
CISA says all four are under active exploitation, and three of them are unauthenticated flaws in edge and management appliances. Its own alert cites BOD 26-04 and prints no due date for any of them.
Perspective Coverage
4 publishers
- Builder
- Builder 14%
- Operator
- Operator 80%
- Investor
- Investor 6%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence70
Hudson Rock and ADAMnetworks link the ads to an operation they call PasteSwitch, which hands Windows and macOS visitors different paste-this-command lures and swaps payloads on the backend depending on who arrives.
Perspective Coverage
5 publishers
- Builder
- Builder 29%
- Operator
- Operator 65%
- Investor
- Investor 6%
Reality
- Evidence74
- Adoption
- Insufficient
- Hype gap+8
- Incentives50
- Confidence72
Huntress worked two Settra intrusions, in July and September, and found MeshAgent installed for remote control, Windows event logs cleared and recovery partitions removed. SOCRadar counts 93 victims claimed since June.
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+5
- Incentives40
- Confidence70
Checkmarx says a fake sorted-btree clone reached 2 million weekly downloads with clean install scripts, starting its loader only when an application calls BTree.prototype.set with a particular key. Nine related packages have been pulled.
Perspective Coverage
3 publishers
- Builder
- Builder 43%
- Operator
- Operator 45%
- Investor
- Investor 12%
Reality
- Evidence62
- Adoption45
- Hype gap+20
- Incentives45
- Confidence60
SOCRadar's teardown of the $250-a-month service puts the elevation step behind an administrator account and permissive UAC settings, so on a fleet of standard users the rental buys remote access and credential theft and stops there.
Reality
- Evidence58
- Adoption28
- Hype gap+30
- Incentives52
- Confidence55
The Windows implant, its Linux control server, the protocol between them and the licensing all came from one author, sold at $250 a month. SOCRadar puts the operator's undetected run at nearly four years.
Reality
- Evidence58
- Adoption60
- Hype gap+22
- Incentives65
- Confidence57
SOCRadar says two previously unreported RATs pull their next-stage commands out of FTP greetings. It is a first in the wild, and noisier than the web dead drops it replaces.
Reality
- Evidence60
- Adoption38
- Hype gap+12
- Incentives58
- Confidence55
SOCRadar says attackers have used FTP server login banners as dead-drop resolvers since early July 2026 to stage two undocumented remote access trojans, E4del and PINHOLE.
Reality
- Evidence58
- Adoption24
- Hype gap+18
- Incentives62
- Confidence60
SOCRadar says LNK files are pulling PowerShell out of FTP pre-login greetings to stage two RATs. The retrieval finishes before any login, so there is nothing for a transfer log to record.
Reality
- Evidence54
- Adoption22
- Hype gap+16
- Incentives62
- Confidence48
TheHatman's claimed Entra haul and the FortiBleed spraying wave share one detectable seam: a successful authentication landing just behind a spike of failures.
Reality
- Evidence46
- Adoption58
- Hype gap+12
- Incentives78
- Confidence44
SOCRadar's record-level data puts 95 percent of identified victims before the poisoned LiteLLM packages ever hit PyPI. Anyone who rotated only what LiteLLM touched is still exposed.
Reality
- Evidence52
- Adoption68
- Hype gap+12
- Incentives66
- Confidence55