Threat Brief — 2026-09-02 — Agentic attacks and per-click evasion
A new Android banking trojan dubbed StreamRat is being distributed through Meta ads targeting Spanish-speaking users, granting near-complete device control. Unit 42 published a detailed investigation of an AI-assisted cyber attack where autonomous agents breached an enterprise network within hours, adding to this week's flood of agentic-AI threat reporting. Separately, researchers disclosed a malware delivery technique that generates a unique Trojan binary for every click, defeating hash-based detection. Microsoft is also investigating Defender for Office 365 false positives that are blocking legitimate Google search links.
Top items
- StreamRat Android banking trojan distributed via Meta ads. A new Android trojan called StreamRat was promoted through a fake television-streaming campaign on Meta, targeting Spanish-speaking users. The malware grants operators near-complete control of infected devices. No CVE or actor identifier has been assigned. This is a fresh disclosure with no prior reporting. (src: The Hacker News)
- Unit 42 details AI-assisted cyber attack using autonomous agents. An attacker used autonomous AI agents to breach an enterprise network in a matter of hours, according to a Unit 42 investigation. The write-up describes how agentic attacks were executed and offers defensive guidance. This adds a concrete incident-level case study to the broader pattern of AI-enabled offensive tooling reported over the past week. (src: Unit 42)
- Per-click Trojan generation defeats hash-based detection. Researchers describe a server-side malware delivery model that builds a unique Trojan binary for every victim click, resulting in zero hash matches across samples. Windows Defender reportedly failed to detect the payloads due to each build being distinct. No CVE or actor identifier is associated. (src: SecurityLab)
- Microsoft Defender for Office 365 blocks legitimate Google search links. Microsoft is investigating an issue causing Defender for Office 365 to mistakenly flag legitimate Google search URLs as malicious, disrupting user access. This is an operational false-positive issue, not an attack, but may generate helpdesk volume and erode trust in alerts. (src: BleepingComputer)
- Charity-themed social engineering scam targets banking credentials. A new scam campaign uses a fabricated story about a friend requesting money for children's medical treatment to lure victims into transferring savings to attackers. This is a social-engineering development worth noting for user-awareness programmes. (src: SecurityLab)
Themes
Agentic AI on both sides. Today's Unit 42 investigation joins a week-long stream of agentic-AI threat reporting — autonomous agents breaching networks, AI porting PLC exploits, and AI assembling ransomware. The offensive AI narrative is shifting from proof-of-concept to documented incident.
Evasion through uniqueness. The per-click Trojan generation technique underscores that commodity malware is increasingly built to evade static signatures by design, pressuring defenders toward behavioural and heuristic detection.
