Zscaler found Ledger phishing ads running under a verified Google advertiser, with Vercel redirect domains rotating every 15 to 20 minutes. The ad displayed google.com and the pages sat on Google and Vercel hosting, so domain reputation and the verified badge gave defenders little to catch.
Reality
- Evidence65
- Adoption
- Insufficient
- Hype gap+20
- Incentives55
- Confidence65
Zscaler ThreatLabz logged 20.1% fewer ransomware payments in the year to March 2026, worth $327.8M in total, while the average payment rose 5.3% to $431,995. Leak-site listings fell just 3% over the same period, so the decline is in how many victims pay.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+25
- Incentives80
- Confidence50
Zscaler ThreatLabz says 2CLoader, found in August 2026, drops the Vidar and Remus stealers and XWorm RAT while routing six ntdll calls around EDR's inline hooks. Detection tuned only to those payloads misses the loader stage.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+10
- Incentives30
- Confidence58
Zscaler ThreatLabz traced August 2026 attacks on Indian and Afghan government and defense targets to a new Rust backdoor that takes orders from private GitHub repositories. Its encryption key is a hash of a token sitting in cleartext in the sample.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+5
- Incentives40
- Confidence64
Zscaler ThreatLabz says the Pakistan-aligned group worked government and defense targets in India and Afghanistan with four undocumented tools, one of them a Rust backdoor that takes its orders from files in a private repo.
Reality
- Evidence40
- Adoption25
- Hype gap+18
- Incentives65
- Confidence45
Zscaler tracked three changes to Vidar's string encryption between early May and early September 2026, ending in a per-build virtual machine and stream cipher that make a key pulled from one sample useless against the next.
Reality
- Evidence70
- Adoption45
- Hype gap+10
- Incentives55
- Confidence60
Zscaler's ThreatLabz found SloppyRAT in June 2026 at the end of a ClickFix chain whose live hosts are all ordinary domains, with a Polygon JSON-RPC lookup held in reserve for when those domains stop answering.
Reality
- Evidence62
- Adoption18
- Hype gap+18
- Incentives60
- Confidence55
The Threat Hunter Team says the technique has hit government departments, technology firms and hotels since February 2026. In one case, the operators moved to node.exe only after their Cobalt Strike beacons kept getting blocked.
Reality
- Evidence57
- Adoption58
- Hype gap+16
- Incentives66
- Confidence56
Zscaler says a Rust backdoor tied to ransomware activity moved its command channel onto GitHub. The first version beaconed once a second to a bare HTTP endpoint. The second one does not need a domain at all.
Reality
- Evidence58
- Adoption24
- Hype gap+12
- Incentives68
- Confidence52