< Back to situation

[REVISION HISTORY]

Global malware and cyber threat evolution

Updated 1 time since CLSTR started tracking revisions of this situation.

What changed

2026-08-16 21:53 UTC → 2026-08-19 18:43 UTC · added removed

Global malware activity has seen a surge in continues to surge, driven by remote access trojans (RATs), information stealers, and loaders. AsyncRAT remains a dominant threat, with approximately 211 weekly sample uploads observed; it frequently delivered via phishing and utilizing utilizes trusted cloud infrastructure infrastructure, such as Cloudflare, to evade detection. Remcos RAT has also increased seen a sharp rise in activity, with newer variants capable of focusing on real-time surveillance such as capabilities like live webcam streaming and instant keystroke transmission. Additionally, attackers Attackers are increasingly employing sophisticated delivery methods, such as using Visual Basic Script (VBS) and PowerShell to deploy malicious script chains. These chains often utilize DuckDNS hosts to distribute scripts that employ mimic legitimate Windows activity, employing AES-256 encryption and process hollowing to bypass security defenses. defenses and steal browser data, keystrokes, and clipboard contents. Parallel to these technical delivery methods, shifts, threat actors are investing millions of dollars to acquire expired heavily in “dropcatch” domains to facilitate malware distribution distribution, illegal gambling, and scams. By purchasing these domains, attackers exploit inherited reputation and web traffic to bypass reputation-based security algorithms. In the first half of 2026, approximately 65,000 re-registered domains were observed daily. daily, accounting for nearly 20% of all newly observed domains. High rates of this activity are noted in .net and .xyz extensions, where nearly 30% of new registrations are previously registered domains. By acquiring these, attackers exploit inherited reputation, backlinks, and web traffic to bypass security algorithms. Specific actors have been identified using these methods: Sable Squirrel is estimated to have spent over $7 million to acquire more than 10,000 expired domains to support ecosystems involving illegal streaming and malware. Other actors, including Sable Squirrel, Shady Squirrel, Stuffy Squirrel, and Swiping Squirrel, have been identified using utilize these methods to support criminal ecosystems, infrastructures for SocGholish “fake update” campaigns, advertising fraud, and fake update infrastructures. scams.

Versions

  1. 2026-08-19 18:43 UTC Global malware and cyber threat evolution
  2. 2026-08-16 21:53 UTC Global malware and cyber threat evolution

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.