HP has released its latest Threat Insights Report, a report that analyzes real-world cyberattacks to help organizations stay up to date with the latest techniques used by cybercriminals to evade detection systems and compromise PCs in an ever-evolving threat landscape.
Based on millions of devices running HP Wolf Security, HP Wolf Security researchers have identified, among others, the following campaigns:
- Fake cryptocurrency trading AI agents lure users into a malware trap: Cybercriminals are taking advantage of the interest in agentic AI to promote fake cryptocurrency trading AI agents and trick users into installing malware on their own devices. Once downloaded, the malware scans victims’ browsers for cryptocurrency wallet extensions, such as Coinbase and MetaMask, and replaces them with malicious imitations capable of collecting entered credentials. Once obtained, attackers can access and steal cryptocurrency funds.
- Phishing using QR codes continues to be a common route to credential theft: attackers use QR codes to move victims from their PCs to mobile devices with lower levels of protection. Victims receive PDF documents whose content is supposedly “blurred for security reasons.” They are then asked to scan a QR code with their phone, which redirects them to phishing pages that may have been blocked on their PCs, thus putting their access credentials and, in certain cases, the accounts used to manage cryptocurrencies at risk.
- Phantom Stealer Ecosystem Expands: Researchers have identified Phantom Gate, a new malware loader that appears to extend the Phantom Stealer campaign. The combination of Phantom Stealer, openly marketed as legitimate penetration testing software, with Phantom Gate’s loading mechanism makes it easier for cybercriminals to create and scale attack campaigns. Possible targets also include users of cryptocurrency-related services, due to the economic value of the credentials and digital assets they can store.
Patrick Schläpfer, Principal Threat Researcher at HP Security Lab, explained: “Attackers are taking advantage of the adoption of agentic AI tools to develop new honeypots that trick users into downloading malicious software that looks legitimate. This tactic makes malware distribution more sophisticated and harder to detect. New attack tools like Phantom Gate reflect the expanding threat landscape. They allow cybercriminals to easily create dangerous infection chains, significantly increasing the risk of organizations being compromised.”
The risk also affects users who manage digital assets. Campaigns aimed at cryptocurrency theft can combine social engineering, malware and spoofing techniques to obtain the credentials necessary to access wallets. In this context, the protection of devices takes on special importance, since a compromise can facilitate both the theft of information and access to cryptocurrency funds.
Threats that evade detection
By isolating threats that have managed to evade PC detection tools, while allowing malware to run safely within protected containers, HP Wolf Security gains insight into the latest techniques used by cybercriminals. To date, HP Wolf Security customers have clicked on 60 billion email attachments, web pages, and downloaded files without any security breaches.
The protection of devices takes on special importance, since a compromise can facilitate both the theft of information and access to cryptocurrency funds.
The report, which analyzes data for the period between April and June 2026, details how cybercriminals continue to diversify their attack methods to bypass security tools and reveals that:
- At least 10% of email threats identified by HP Sure Click bypassed one or more email gateway scanners.
- Executable files were the most used method to distribute malware (40%), followed by compressed files (38%) and PDF documents (7.5%).
James Wright, global director of Personal Systems Security at HP, says: “Users are constantly moving between devices and applications, such as browsers or new AI tools, and attackers are quick to follow. Security must work across all those interactions without interfering with people’s experience. This means organizations need a Zero Trust approach based on isolation and containment, to prevent untrusted clicks and downloads from becoming a risk.”
The evolution of these campaigns shows that cybercriminals seek to take advantage of new digital interests and habits to build more convincing lures. The rise of agentic AI and the growing use of services linked to cryptocurrencies thus expand the attack surface and force organizations to strengthen the protection of devices and digital identities.
