CERT-UA says attackers planted fake Cloudflare checks on more than 100 legitimate websites to get visitors to install Lunex Stealer themselves. Ontinue says its browser components can keep file access after the stealer is deleted, so cleanup has to reach the browsers.
Perspective Coverage
3 publishers
- Builder
- Builder 30%
- Operator
- Operator 62%
- Investor
- Investor 8%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+10
- Incentives25
- Confidence70
RatHat's malware console now feeds stolen texts to Google's Gemini to estimate each victim's bank balance and rank who to rob first, security firm Cleafy says. Cleafy has traced nearly 100 deployments since April 2026 and found nothing that moves money.
Reality
- Evidence55
- Adoption25
- Hype gap+10
- Incentives
- Insufficient
- Confidence55
Ontinue says the Lunex stealer-for-rent loads a flawed AMD driver, CVE-2023-20598, to switch off security tools before robbing seven browsers. That driver step is rarely used ahead of an info stealer, and Lunex is rented to multiple criminal groups.
Reality
- Evidence55
- Adoption40
- Hype gap+10
- Incentives
- Insufficient
- Confidence55
Group-IB says the RemControl Android banking trojan reaches bank customers in six countries and the Middle East via Meta ads and fake Google Play pages. Its server address sits in a Telegram dead-drop, so the operator can move infrastructure without a new build.
Perspective Coverage
4 publishers
- Builder
- Builder 34%
- Operator
- Operator 59%
- Investor
- Investor 7%
Reality
- Evidence65
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence65
McAfee says the WeedHack stealer's control server is dead and its renter dashboard gone, but ten impersonation sites and the search rankings behind them are still delivering victims.
Perspective Coverage
3 publishers
- Builder
- Builder 18%
- Operator
- Operator 77%
- Investor
- Investor 5%
Reality
- Evidence55
- Adoption40
- Hype gap+15
- Incentives55
- Confidence60
Sekoia's comparison found the two ClickFix services' injected scripts near identical, while the Exvicy subscription climbed from $1,200 to $2,000 a month and its panel count reached about 80 hosts by late August.
Reality
- Evidence62
- Adoption35
- Hype gap+10
- Incentives40
- Confidence58
Kaspersky says the macOS stealer it first tracked as Mac.c has swapped script droppers for FAT Mach-O binaries in a chain found in September 2026, and its loader now reads shell commands out of a public iCloud calendar file.
Reality
- Evidence68
- Adoption32
- Hype gap0
- Incentives58
- Confidence58
AvisLoader statically links the reference Tox client, so its operator keeps the same identity after moving to a new server. The ClickFix page and Cloudflare tunnel that deliver it are still ordinary takedown targets.
Publishers:varonis.com
Reality
- Evidence66
- Adoption20
- Hype gap+18
- Incentives62
- Confidence57
LastPass and Delphos Labs say a single malware-as-a-service kit impersonated at least 40 companies on GitHub, and the kernel driver it delivered was Microsoft-attested and undetected by every engine on VirusTotal.
Publishers:blog.lastpass.com
Reality
- Evidence62
- Adoption48
- Hype gap+12
- Incentives68
- Confidence55
buildOne report1 publisher LastPass TIME and Delphos Labs analysed a malware-as-a-service kit that arrives as a padded ZIP from an SEO-boosted fake repository and ends with a signed driver terminating security processes from kernel mode.
Reality
- Evidence45
- Adoption30
- Hype gap+12
- Incentives55
- Confidence40
HP tracked the campaign from April to June 2026, in which a fake AI crypto trading agent shipped a genuine Microsoft utility to satisfy Windows reputation checks before the DLL loaded beside it stole browser wallet passwords.
Reality
- Evidence60
- Adoption40
- Hype gap+15
- Incentives70
- Confidence55
buildOne report1 publisher SOCRadar's teardown of the $250-a-month service puts the elevation step behind an administrator account and permissive UAC settings, so on a fleet of standard users the rental buys remote access and credential theft and stops there.
Reality
- Evidence58
- Adoption28
- Hype gap+30
- Incentives52
- Confidence55
The Windows implant, its Linux control server, the protocol between them and the licensing all came from one author, sold at $250 a month. SOCRadar puts the operator's undetected run at nearly four years.
Reality
- Evidence58
- Adoption60
- Hype gap+22
- Incentives65
- Confidence57
Intel 471 found an unauthenticated panel called AppPanda running fake streaming lures behind paid Facebook ads, with affiliate tooling that re-signs the Android payload every hour and tracks ad spend the way a growth team would.
Reality
- Evidence64
- Adoption74
- Hype gap+15
- Incentives58
- Confidence56
buildOne report1 publisher A Raxis post catalogues three campaigns that made GitHub the delivery host rather than the hiding place, which is why the 1,300 repositories flagged as open to RepoJacking matter more than the million-device headline above them.
Reality
- Evidence28
- Adoption45
- Hype gap+38
- Incentives65
- Confidence34
ReversingLabs counted 397 ACRStealer samples against 26 for the freshly updated AuraStealer. In a rented-malware market, the newest family is not the busiest one.
Reality
- Evidence42
- Adoption55
- Hype gap+32
- Incentives78
- Confidence48
Zimperium's 2026 heist report tracks 34 malware families against 1,243 financial brands. The capability mix has moved from stealing credentials to owning the handset and encrypting it.
Reality
- Evidence38
- Adoption54
- Hype gap+32
- Incentives82
- Confidence44