Darktrace A.I CyberSecurity Scoring
Darktrace
Company Information
Website:http://www.darktrace.com
Employees number:2,616
Number of followers:258,539
NAICS:541514
Industry Type:Computer and Network Security
Homepage:darktrace.com
Darktrace Risk Score (AI oriented)
Between 700 and 749
DarktraceComputer and Network Security
Updated:
21/08/2026
21/08/2026
749/1000
Moderate
Ba
Darktrace Global Score (TPRM)
xxxx
DarktraceComputer and Network Security
Score locked

DarktraceModerate
Current Score
749Ba (MODERATE)
01000
3 incidents
-10 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
OCTOBER 2026
750
SEPTEMBER 2026
750
AUGUST 2026
749
JULY 2026
767
Cyber Attack
01 Jul 2026 • Darktrace
Darktrace and Google: Hackers Use Fake Google Gemini Installer to Deploy Vidar Stealer and Steal Browser Credentials
Cybercriminals Exploit AI Hype to Distribute Vidar Stealer via Fake Google Gemini Installer
748
LOW-19
GOODAR1787295076
Cybercriminals Exploit AI Hype to Distribute Vidar Stealer via Fake Google Gemini Installer
In July 2026, threat actors leveraged the growing interest in generative AI to distribute the Vidar information stealer through a fake Google Gemini installer hosted on Google Colab. Darktrace uncovered the campaign after investigating a compromise in an EMEA-based customer environment, where a user downloaded and executed a malicious file named Download_Google_Gemini_For_Windows.exe.
Unlike traditional phishing attacks, this campaign exploited trust in Google’s branding and cloud services. Victims searching for AI tools were directed to a Google Colab page a legitimate Jupyter notebook service displaying a download prompt. The page redirected users to micronsoftwares[.]com, a spoofed "Windows Software Hub" offering the fake installer. While the full download chain couldn’t be reconstructed, SSL sessions to Google Colab preceded the execution of the malicious binary, strongly suggesting the Colab page as the initial infection vector.
The downloaded ZIP archive contained the executable and a README file instructing users to run the binary with administrator privileges and disable antivirus exclusions classic social engineering tactics to bypass security controls. Darktrace identified the payload as a Go-compiled Vidar variant, communicating with Telegram-based command-and-control (C2) infrastructure via dtm[.]kijangturbo88[.]top. Post-execution, the malware connected to 91.98.98[.]86 and 91.98.111[.]49 over TCP/443, exfiltrating browser credentials, session cookies, autofill data, and cryptocurrency wallet artifacts.
Darktrace detected the compromise through behavioral analytics, identifying suspicious process execution from the Downloads folder, anomalous encrypted outbound traffic, and credential-harvesting indicators. Its Autonomous Response capability blocked C2 communications and quarantined the infected endpoint.
The incident highlights a shift in malware distribution tactics, where attackers abuse trusted cloud platforms and AI branding to reduce victim suspicion. By repackaging commodity malware as a legitimate AI tool, threat actors exploit enterprise adoption trends, making detection harder. Organizations are advised to restrict software installations to approved sources, monitor execution from Downloads/temporary directories, and hunt for Gemini-themed installers from unofficial channels.
Indicators of Compromise (IoCs):
- Files: Download_Google_Gemini_For_Windows.exe, GoogleAppInstaller.exe
- IPs: 91.98.98[.]86, 91.98.111[.]49
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2026
767
MAY 2026
767
APRIL 2026
766
MARCH 2026
766
FEBRUARY 2026
767
Vulnerability
10 Feb 2026 • Darktrace
Docker and Darktrace: Threat Actors Exploiting React2Shell Vulnerability Using AI-Generated Malware
AI-Generated Malware Exploits 'React2Shell' in Low-Skill Cyberattack Campaign
766
LOW-1
DARDOC1770731539
AI-Generated Malware Exploits "React2Shell" in Low-Skill Cyberattack Campaign
Darktrace’s CloudyPots honeypot network recently uncovered an active malware campaign leveraging AI-generated tools to exploit the React2Shell vulnerability, marking a concerning evolution in cybercrime tactics. The attack, detected in a misconfigured Docker environment, demonstrates how large language models (LLMs) are lowering the barrier for threat actors to deploy sophisticated exploits with minimal technical expertise.
The intrusion began when attackers targeted an exposed Docker daemon a common cloud misconfiguration via its API. The threat actor deployed a container named "python-metrics-collector" to blend in with legitimate services, then installed tools like curl, wget, and python3 to fetch payloads. The attack unfolded in two stages:
1. Dependency Retrieval: A Pastebin URL delivered a list of required Python packages.
2. Payload Execution: A Python script, hosted on a GitHub Gist under the banned user "hackedyoulol", was executed after redirecting from smplu[.]link.
Analysis revealed the script was likely AI-generated, featuring verbose comments and an "educational" disclaimer a tactic to bypass LLM safety filters. Tools like GPTZero confirmed 76% of the code was machine-written, with a clean, structured design that exploited React2Shell by forcing exceptions to expose command output.
Despite its advanced delivery, the campaign’s goal was simple: cryptocurrency mining. The script deployed XMRig (v6.21.0) to mine Monero (XMR) via the supportxmr pool. While the financial gain was minimal 0.015 XMR (~£5) from 91 infected hosts the operational impact was significant: a low-skilled attacker compromised nearly 100 systems using AI-generated tools.
Unlike typical Docker threats, the malware lacked self-propagation capabilities, relying instead on a centralized "spreader server" linked to a residential IP (49[.]36.33.11) in India. This suggests manual or scripted management of the campaign.
The incident underscores a critical shift in cyber threats, where AI-driven "vibecoding" enables rapid, custom malware development. For defenders, this highlights the need for behavioral detection and proactive patching, as static signatures may struggle against the endless variations LLMs can produce.
Indicators of Compromise (IoCs):
- Spreader IP: 49[.]36.33.11
- Malware host: smplu[.]link
- Hashes:
- 594ba70692730a7086ca0ce21ef37ebfc0fd1b0920e72ae23eff00935c48f15b
- d57dda6d9f9ab459ef5cc5105551f5c2061979f082e0c662f68e8c4c343d667d
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
JANUARY 2026
767
DECEMBER 2025
767
NOVEMBER 2025
767
APRIL 2018
767
Vulnerability
01 Apr 2018 • Darktrace
Darktrace
Casino Hacked Through IoT Thermometer
766
LOW-1
DAR20521622
Hackers are increasingly targeting unprotected 'internet of things' devices such as air condition systems and CCTV to get into corporate networks.
A casino was hacked through the thermometer in its lobby aquarium.
It expands the attack surface and most of this isn't covered by traditional defenses.
INCIDENT DETAILS -
TYPE
MOTIVATION
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Darktrace ??
What was Darktrace's A.I Rankiteo Cyber Score in September 2026 ??
What was Darktrace's A.I Rankiteo Cyber Score in August 2026 ??
What was Darktrace's A.I Rankiteo Cyber Score in July 2026 ??
What was Darktrace's A.I Rankiteo Cyber Score in June 2026 ??
What was Darktrace's A.I Rankiteo Cyber Score in May 2026 ??
What was Darktrace's A.I Rankiteo Cyber Score in April 2026 ??
What was Darktrace's A.I Rankiteo Cyber Score in March 2026 ??
What was Darktrace's A.I Rankiteo Cyber Score in February 2026 ??
What was Darktrace's A.I Rankiteo Cyber Score in January 2026 ??
What was Darktrace's A.I Rankiteo Cyber Score in December 2025 ??
What was Darktrace's A.I Rankiteo Cyber Score in November 2025 ??
What is the average per-incident point impact on Darktrace's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Darktrace ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Darktrace's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?