Symantec says Warlock operators ran an AV/EDR killer across at least 40 machines in roughly two hours after a suspected SharePoint compromise. The ransomware payloads moved between domain controllers through SYSVOL replication.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence55
Zscaler ThreatLabz says 2CLoader, found in August 2026, drops the Vidar and Remus stealers and XWorm RAT while routing six ntdll calls around EDR's inline hooks. Detection tuned only to those payloads misses the loader stage.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+10
- Incentives30
- Confidence58
An affiliate entered through an MFA-less SonicWall VPN, then used Safe Mode with Networking to kill endpoint controls. The encryptor ran out of virtual memory instead of running.
Perspective Coverage
3 publishers
- Builder
- Builder 30%
- Operator
- Operator 65%
- Investor
- Investor 5%
Reality
- Evidence72
- Adoption15
- Hype gap+5
- Incentives40
- Confidence70
LastPass and Delphos Labs say a single malware-as-a-service kit impersonated at least 40 companies on GitHub, and the kernel driver it delivered was Microsoft-attested and undetected by every engine on VirusTotal.
Publishers:blog.lastpass.com
Reality
- Evidence62
- Adoption48
- Hype gap+12
- Incentives68
- Confidence55
Alinubx.sys terminates security agents from kernel mode under a Microsoft Windows Hardware Compatibility Publisher signature dated March 2023, and nothing in the driver has to be exploited for that to work.
Reality
- Evidence62
- Adoption40
- Hype gap+8
- Incentives55
- Confidence55
LastPass TIME and Delphos Labs analysed a malware-as-a-service kit that arrives as a padded ZIP from an SEO-boosted fake repository and ends with a signed driver terminating security processes from kernel mode.
Reality
- Evidence45
- Adoption30
- Hype gap+12
- Incentives55
- Confidence40
LastPass and Delphos Labs traced SEO-tuned GitHub repositories impersonating at least 40 software brands to a new stealer called Rapuncel, shipped alongside a signed kernel driver that opens protected security processes as kernel code and terminates them.
Reality
- Evidence58
- Adoption30
- Hype gap+15
- Incentives62
- Confidence57
On a September 10 podcast, Eclypsium researchers walked from vulnerable signed UEFI shells to Fire Ant binaries wearing EDR agent names. The common thread is verification: a defender can check very little of that stack alone.
Publishers:eclypsium.com
Reality
- Evidence30
- Adoption30
- Hype gap+15
- Incentives78
- Confidence45
Cisco Talos found the loader running from a WebDAV UNC path at a Ukrainian government organisation in April 2026, delivered by a ClickFix prompt whose JavaScript was stored on BNB Smart Chain. The primary payload is Amatera stealer.
Reality
- Evidence68
- Adoption38
- Hype gap−12
- Incentives55
- Confidence60
Group-IB puts the Qilin affiliate cut at up to 80 percent, and KELA logged a change that routes victim payments through affiliate wallets first, which says more about the operation's incentives than its thin public tradecraft record does.
Publishers:blog.bushidotoken.net
Reality
- Evidence54
- Adoption63
- Hype gap+14
- Incentives71
- Confidence57