TrendAI has tied ASHVEIN, a previously undocumented .NET RAT, to UAC-0099 attacks on Ukrainian government personnel, citing five builds from October 2025. The group has fielded newer tools since, so detection that lasts has to target how it delivers and tasks its implants.
Reality
- Evidence50
- Adoption25
- Hype gap+10
- Incentives35
- Confidence50
Microsoft says China-linked operators have used NeedyMantis since at least October 2025 to keep access to telecom, university and government-linked networks. It goes in after the break-in, so defenders have to hunt for it inside networks already breached.
Perspective Coverage
3 publishers
- Builder
- Builder 22%
- Operator
- Operator 67%
- Investor
- Investor 11%
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+18
- Incentives40
- Confidence60
Huntress traced a RAT campaign that hides its first-stage lure in a ChatGPT Custom GPT on the real chatgpt.com, across at least 40 incidents. Because the page sits on a trusted domain, blocking the ClickFix PowerShell paste is the control that works.
Perspective Coverage
8 publishers
- Builder
- Builder 30%
- Operator
- Operator 64%
- Investor
- Investor 6%
Reality
- Evidence70
- Adoption20
- Hype gap+30
- Incentives40
- Confidence68
Sophos linked ClickFix lures that open Windows Terminal, not the Run dialog, to STAC4924, a campaign it has tracked since at least March. The intrusions plant Lorem Ipsum Loader and a Python reverse-tunnel implant that relays attacker traffic through the victim host.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap−5
- Incentives
- Insufficient
- Confidence58
Microsoft says China-aligned NeedyMantis malware, active since at least October 2025, is installed after attackers already have access, to keep it long term. Because entry routes vary, organisations in the five sectors it targets need to look for copies already installed.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap0
- Incentives40
- Confidence60
Securelist says the newest CoolClient deploys a signed kernel-mode driver as a Windows service to hide its process, files and registry keys. It was seen in Pakistan, Mongolia and Myanmar.
Reality
- Evidence62
- Adoption30
- Hype gap+10
- Incentives35
- Confidence60
Bitdefender says a China-nexus cluster hit Central Asian governments with seven RAT families, five undocumented. The AI fingerprint is in the workflow, not the code.
Reality
- Evidence60
- Adoption20
- Hype gap+10
- Incentives
- Insufficient
- Confidence58
Microsoft's TerminalFix writeup shows the same fake CAPTCHA lure now feeding multi-line PowerShell into Windows Terminal, where it sideloads a signed binary, pulls payloads out of PNG files and leaves a reverse tunnel behind.
Perspective Coverage
4 publishers
- Builder
- Builder 20%
- Operator
- Operator 75%
- Investor
- Investor 5%
Reality
- Evidence65
- Adoption
- Insufficient
- Hype gap+20
- Incentives30
- Confidence65
Kaspersky traced one submitted installer to a modified Chinese wallpaper tool whose signed executable sideloads a malicious libcef.dll, and the same installer switches Windows Defender off before it ever runs.
Perspective Coverage
4 publishers
- Builder
- Builder 24%
- Operator
- Operator 67%
- Investor
- Investor 9%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+15
- Incentives30
- Confidence66
Black Lotus Labs counted about a dozen compromised enterprises, mostly in Asia and South America, on a framework that has been publishing operator commands to infected hosts through IoT message brokers since 2024.
Perspective Coverage
3 publishers
- Builder
- Builder 27%
- Operator
- Operator 62%
- Investor
- Investor 11%
Reality
- Evidence66
- Adoption18
- Hype gap+20
- Incentives
- Insufficient
- Confidence64
Elastic Security Labs says the Brazilian crew it calls REF9334 has been running this since at least May 2025, writing its extension into Chromium's Secure Preferences and reading C2 addresses out of an Ethereum smart contract.
Reality
- Evidence62
- Adoption42
- Hype gap+12
- Incentives55
- Confidence58
Cisco Talos found the loader running from a WebDAV UNC path at a Ukrainian government organisation in April 2026, delivered by a ClickFix prompt whose JavaScript was stored on BNB Smart Chain. The primary payload is Amatera stealer.
Reality
- Evidence68
- Adoption38
- Hype gap−12
- Incentives55
- Confidence60
Field Effect logged three ClickFix chains between mid-June and July 2026, two of them landing on the same hidden file pair in ProgramData, and in one case the operator phoned the victim to open the lure.
Publishers:fieldeffect.com
Reality
- Evidence60
- Adoption34
- Hype gap−8
- Incentives58
- Confidence55
Microsoft Threat Intelligence says this ClickFix variant ends in Active Directory reconnaissance and a reverse-tunnel implant, giving a single tricked employee a route into the network.
Reality
- Evidence55
- Adoption35
- Hype gap+15
- Incentives70
- Confidence60