HP Inc. has unveiled its most recent Threat Insights Report, offering a comprehensive analysis of current cybersecurity threats. This detailed report aims to assist organisations in staying abreast of the latest cyberattack methods used by criminals to bypass detection and jeopardise PCs within the ever-evolving cybercrime environment. Drawing on data from millions of endpoints protected by HP Wolf Security, the report highlights significant findings from HP Wolf Security's threat researchers, including novel cyberattack techniques and strategies.
One highlighted tactic involves the exploitation of AI tools, where cybercriminals are using counterfeit AI trading agents to deceive crypto users into malware traps. These fraudulent agents entice users to download malicious software, which subsequently scans browsers for crypto wallet extensions such as Coinbase and MetaMask, replacing them with deceptive replicas designed to capture entered credentials. This allows attackers straightforward access to steal digital assets.
Ongoing threats in QR phishing
Another identified trend is the persistent use of QR phishing as a method for credential theft. Cybercriminals disseminate PDFs with allegedly "blurred for security" content, urging victims to scan a QR code using their mobile devices. This scan redirects users to phishing websites, potentially vulnerable on mobile due to reduced security measures compared with PCs, thus risking the exposure of login credentials.
Expansion of the phantom stealer ecosystem
Another identified trend is the persistent use of QR phishing as a method for credential theft
The report also sheds light on the Phantom Stealer ecosystem’s growth with the introduction of Phantom Gate, a new malware loader. This development appears to enhance the existing Phantom Stealer campaign, combining advertised penetration-testing software with the Phantom Gate loader to simplify the construction and scaling of attack campaigns.
Patrick Schläpfer, Principal Threat Researcher at HP Security Lab, remarked: “Attackers are tapping into Agentic AI tool adoption to invest in new lures that trick users into downloading malicious software that looks legitimate. This tactic makes malware delivery more polished and harder to detect. New attack tools such as Phantom Gate reflect the expanding threat landscape. They enable threat actors to easily compose dangerous infection chains, which greatly increases the risk of compromise for organizations.”
HP's approach to threat isolation
HP Wolf Security enhances its threat analysis by isolating undetected threats on PCs, allowing malware to be executed safely within secure environments. To date, users have interacted with 60 billion email attachments, web pages, and files without reported breaches, demonstrating the efficacy of HP Wolf Security’s containment strategies.
The report, focusing on data from April to June 2026, highlights the diversification of attack methods by cybercriminals to bypass security technology. It was discovered that a minimum of 10% of email threats identified by HP Sure Click managed to pass through one or more email gateway scanners. Moreover, executable files represented the leading form of malware delivery at 40%, followed by archive files at 38% and PDF documents at 7.5%.
James Wright, HP’s Global Head of Security for Personal Systems, expressed: “Users move constantly between devices and applications, like browsers or new AI tools – and attackers are quick to follow. Security needs to work across all of those interactions, without getting in people’s way. That means organizations need a zero-trust approach built around isolation and containment, so untrusted clicks and downloads don’t become a risk.”
