Acronis says the operator borrowed a security vendor's own uninstall driver to shut down Defender on Cambodian machines, and the loader keeps three further ways to blind an agent if the kernel route fails.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence60
Kaspersky traced one submitted installer to a modified Chinese wallpaper tool whose signed executable sideloads a malicious libcef.dll, and the same installer switches Windows Defender off before it ever runs.
Perspective Coverage
4 publishers
- Builder
- Builder 24%
- Operator
- Operator 67%
- Investor
- Investor 9%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+15
- Incentives30
- Confidence66
Kaspersky found two cross-platform JavaScript RATs, NodeRabbit and PollCat, reaching engineers in aviation and fintech through fake recruiters, from a group that until now shipped native C, C++ and Go.
Perspective Coverage
4 publishers
- Builder
- Builder 45%
- Operator
- Operator 49%
- Investor
- Investor 6%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+15
- Incentives35
- Confidence65
A Northern California freelance marketplace's own messaging system carried Excel macro lures to 80,000 of its users across 18 months. Microsoft closed that delivery step in 2022. The same platform lure now shows up in North Korean operations.
Perspective Coverage
6 publishers
- Builder
- Builder 17%
- Operator
- Operator 78%
- Investor
- Investor 5%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence68
Malwarebytes found Kothamine, an undocumented Windows RAT hidden in malicious npm packages, that takes its 30-plus commands over Tailscale's tailcat. The encrypted channel leaves no command-and-control domain to block, pushing detection onto the endpoint.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence58
Blackpoint says a fake Spotify MSI, launched through msiexec.exe, ends with a Node.js agent that reads its live C2 address off a Polygon contract. The same implant has also shipped as Zoom and Teams.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence66
Huntress found the same one-megabyte PIF in two customer environments, pulled down by a link that promised a PNG. Everything after it is the 2024 DarkMe chain, down to the rundll32 /sta GUID from that campaign.
Reality
- Evidence72
- Adoption22
- Hype gap+14
- Incentives66
- Confidence68
The Windows implant, its Linux control server, the protocol between them and the licensing all came from one author, sold at $250 a month. SOCRadar puts the operator's undetected run at nearly four years.
Reality
- Evidence58
- Adoption60
- Hype gap+22
- Incentives65
- Confidence57
Zscaler's ThreatLabz found SloppyRAT in June 2026 at the end of a ClickFix chain whose live hosts are all ordinary domains, with a Polygon JSON-RPC lookup held in reserve for when those domains stop answering.
Reality
- Evidence62
- Adoption18
- Hype gap+18
- Incentives60
- Confidence55
Huntress took apart an ISO sold as a leaked pre-release copy and found two RATs, a Discord-webhook infostealer and a Chaos build that overwrites anything above 200MB. All of it is old enough for Defender to catch.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+14
- Incentives55
- Confidence58
SOCRadar says two previously unreported RATs pull their next-stage commands out of FTP greetings. It is a first in the wild, and noisier than the web dead drops it replaces.
Reality
- Evidence60
- Adoption38
- Hype gap+12
- Incentives58
- Confidence55
SOCRadar says attackers have used FTP server login banners as dead-drop resolvers since early July 2026 to stage two undocumented remote access trojans, E4del and PINHOLE.
Reality
- Evidence58
- Adoption24
- Hype gap+18
- Incentives62
- Confidence60