Zscaler ThreatLabz says 2CLoader, found in August 2026, drops the Vidar and Remus stealers and XWorm RAT while routing six ntdll calls around EDR's inline hooks. Detection tuned only to those payloads misses the loader stage.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+10
- Incentives30
- Confidence58
HP tracked the campaign from April to June 2026, in which a fake AI crypto trading agent shipped a genuine Microsoft utility to satisfy Windows reputation checks before the DLL loaded beside it stole browser wallet passwords.
Reality
- Evidence60
- Adoption40
- Hype gap+15
- Incentives70
- Confidence55
The Windows implant, its Linux control server, the protocol between them and the licensing all came from one author, sold at $250 a month. SOCRadar puts the operator's undetected run at nearly four years.
Reality
- Evidence58
- Adoption60
- Hype gap+22
- Incentives65
- Confidence57
Insikt Group counted 215 actively exploited CVEs in six months, up 34% year on year, and describes attackers running them through remote access utilities, package registries and payment flows defenders already permit.
Reality
- Evidence61
- Adoption63
- Hype gap−7
- Incentives71
- Confidence57
Microsoft says the technique now reaches thousands of enterprise and end-user devices every day. Because the employee is the one who runs the code, the control that binds is a rule about pasting into shells rather than another agent.
Reality
- Evidence61
- Adoption71
- Hype gap+14
- Incentives70
- Confidence58
Unit 42 says the C++ loader reads encrypted commands from immutable smart contracts over public RPC endpoints, which turns takedown work into traffic monitoring.
Reality
- Evidence62
- Adoption28
- Hype gap+16
- Incentives72
- Confidence55