Malware activity surged in Q3 2025, with the Center for Internet Security (CIS) reporting a 38% increase in notifications compared to the previous quarter. SocGholish remained the most prevalent malware, accounting for 26% of detections, and was often used to deliver additional payloads such as NetSupport and AsyncRAT. The quarter also saw the re-emergence of Gh0st, Lumma Stealer, and TeleGrab, as well as the debut of Jinupd, a downloader distributed via phishing and compromised websites. Lumma Stealer, notable for its infostealing and evasion capabilities, returned after law enforcement action against its infrastructure. Infection vectors tracked included dropped malware, malspam, and malvertising.
Separately, eSentire identified a November 2025 campaign leveraging ClickFix as an initial access vector to deploy Amatera Stealer and NetSupport RAT. Amatera Stealer, a rebranded version of ACR (AcridRain) Stealer, is capable of exfiltrating data from crypto-wallets, browsers, and messaging apps, and uses advanced evasion techniques to bypass security products. The campaign highlights the continued evolution and rebranding of stealer malware, as well as the persistent use of remote access tools like NetSupport in active threat campaigns.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
CIS published its Top 10 Malware Q3 2025 report, detailing leading malware families, infection vectors, and defensive coverage claims. The report also included indicators of compromise such as domains and SHA256 hashes to support detection and prevention efforts.
eSentire published research on the EVALUSION campaign, describing delivery of Amatera Stealer and NetSupport RAT. The reference indicates a newly documented campaign and associated technical findings, though no earlier event date is provided in the source excerpt.
During Q3 2025, MS-ISAC monitoring services recorded a 38% increase in malware notifications compared with the previous quarter. SocGholish accounted for 26% of detections and continued to serve as a common JavaScript downloader leading to follow-on payloads such as NetSupport and AsyncRAT.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 116 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.