AtlasCross RAT spreads via 11 fake domains registered October 27, 2025, enabling encrypted C2 control and persistence.
DeepLoad exploits ClickFix and WMI persistence to steal credentials, enabling stealth reinfection after three days.