Cybereason is a cybersecurity company that analyzed the use of PoolParty Variant 7 in fake installer attack chains delivering ValleyRAT. Researcher Hajime Takai noted similarities with SADBRIDGE and GOSAR, suggesting possible shared threat actor origins.