Unit 42 analyzed 405 AI-enabled malware samples and found that only 12 (3%) appeared on production endpoints, while 97% existed solely in research repositories and sandboxes. The 12 production samples span five families: FunkSec ransomware, a trojanized AI application (Recipe Lister), Oyster backdoor, Rhadamanthys stealer, and a COM hijacking DLL. Existing behavioral detection, sandbox detonation, code-signing anomaly detection, and entropy analysis caught all production samples without requiring novel detection approaches. AI influences malware authoring velocity but does not alter runtime behavior or evade current defensive frameworks.
Rhadamanthys
5 posts
The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution Hot Take: Operation Endgame vs. SocGholish Operation Endgame successfully disrupted the SocGholish (TA569) initial access framework, which relies on compromised WordPress sites and Traffic Distribution Systems (TDS) to deliver fake browser updates. The threat actor utilizes domain shadowing and a multi-stage JScript payload to establish footholds, primarily targeting corporate environments during standard work weeks to facilitate follow-on ransomware deployment.
Latin America and the Caribbean Cybercrime Landscape In 2025, the Latin America and the Caribbean (LAC) region faced escalating cybercriminal activity driven by rapid digital adoption and economic instability. Threat actors heavily utilized Telegram and dark web forums to distribute ransomware, banking trojans, and infostealers, increasingly targeting the healthcare, manufacturing, and government sectors while adapting to law enforcement disruptions.
2025 Identity Threat Landscape Report The 2025 Identity Threat Landscape Report highlights a massive surge in credential theft driven by infostealer malware, with LummaC2 leading the ecosystem. A critical finding is the widespread theft of active session cookies, which allows attackers to bypass multi-factor authentication (MFA) and directly access high-value corporate systems, VPNs, and cloud platforms.
Iranian MOIS Actors & the Cyber Crime Connection Iranian Ministry of Intelligence and Security (MOIS) affiliated threat actors, including Void Manticore and MuddyWater, are increasingly integrating cybercriminal tools, infrastructure, and affiliate models into their operations. This strategic shift, which includes the use of commercial infostealers like Rhadamanthys and RaaS platforms like Qilin, enhances their operational capabilities while complicating attribution efforts.