Operation Endgame has carried out some major disruptions in the last year and a half, taking down a multitude of campaigns from some of the biggest families in malware. And it’s starting to show in my OpenCTI feed. Under the category of ‘most active malware’, a pie chart representing the last three months of activity at a time, I’ve watched the fluctuations of Rhadamanthys, Lactrodectus, Venom RAT, SystemBC and others.
Prior to the third ‘season’ of the global law enforcement co-op, I was seeing the top players come in at over 100 incidents a day. At the start of October my chart expanded to include markers up to 200. Almost immediately after Operation Endgame’s newest win, I started to see that marker go down, first to 150 and now back to 100. Cobalt Strike has returned to the top spot at near 100 daily incidents after a brief bump by LummaStealer, which has since dropped significantly into fourth place (can’t wait to see why). Pretty much everything else is at 80 or below. And with all of these under high scrutiny and targeted disruption, new names are coming into the top ten.
Today’s new players are VShell, a cross-platform, open source remote access malware, and NetSupportRAT, another version of legitimate software weaponized into a remote access Trojan.
Tracking malware activity is comparable to watching the strains of the flu to see which ones will be a threat during the months in which the highest levels of infection abound. They never truly go away; one can get sick at any time of the year, and so can one’s digital devices. I have often likened cybersecurity to seeing a doctor, with antivirus software being a vaccine against infection and industry work being both preventative and mitigative care. We even call the first level of analysis ‘triage’.
Threat actors never stop. There is always some active campaign going on, be it phishing, exploitation of vulnerabilities, data breaches or ransomware attacks. The takedown of such malware as IceID and Latrodectus leaves a vacuum for threat actors who work with remote access as their vector. They aren’t going to stop looking for ways to infiltrate systems just because their favorite tool was taken away; they’ll simply find another one that has the same behavior.
And that’s where I come in as your friendly neighborhood WISP researcher. Aside from compiling the breaking news and seemingly endless parade of vulnerabilities and their patches, I keep track of what’s out there being used to exploit and attack. Threat monitoring is an essential part of staying ahead of that race. Because it is a race. It’s always a race to keep malicious activity out of a system; there are consistently new variables, new campaigns and too many tools to disrupt them all, with more evolving in real time. As an analyst I’m putting together a puzzle without knowing what the picture on the box is. My research at least gives me an idea of what the corner pieces are.
Posted on LinkedIn, 11/21/25