Group-IB says the RemControl Android banking trojan reaches bank customers in six countries and the Middle East via Meta ads and fake Google Play pages. Its server address sits in a Telegram dead-drop, so the operator can move infrastructure without a new build.
Perspective Coverage
4 publishers
- Builder
- Builder 34%
- Operator
- Operator 59%
- Investor
- Investor 7%
Reality
- Evidence65
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence65
Bitdefender says a China-nexus cluster hit Central Asian governments with seven RAT families, five undocumented. The AI fingerprint is in the workflow, not the code.
Reality
- Evidence60
- Adoption20
- Hype gap+10
- Incentives
- Insufficient
- Confidence58
Bitdefender ties seven remote access tool families to a single Central Asia espionage actor and finds traces of AI-assisted development. Its own numbers show where clustering still held.
Publishers:bitdefender.com · businessinsights.bitdefender.com · news.risky.biz Perspective Coverage
3 publishers
- Builder
- Builder 27%
- Operator
- Operator 55%
- Investor
- Investor 18%
Reality
- Evidence61
- Adoption42
- Hype gap+17
- Incentives71
- Confidence60
A year of Sophos managed detection cases shows the AI threat that actually landed was a lookalike download page. Claude appeared in 26 of 38 incidents.
Reality
- Evidence62
- Adoption58
- Hype gap−12
- Incentives58
- Confidence55
Rapid7's Operation ASTERIX report shows the cost of building convincing wallet malware collapsing while targeting stayed manual. The durable asset is the validated list, not the code.
Reality
- Evidence58
- Adoption32
- Hype gap+26
- Incentives62
- Confidence45