HP Inc. has unveiled its latest Threat Insights Report, delivering an in-depth analysis of contemporary cyberattack strategies utilized by cybercriminals to infiltrate PCs while avoiding detection. Based on data from HP Wolf Security's extensive network, the report highlights innovative tactics, such as exploiting AI models and QR phishing, that pose increasing risks to organizations in the dynamic realm of cybercrime.
Innovative Cyberattack Strategies
Among the notable campaigns analyzed, HP Wolf Security threat researchers have detailed how scammers are using fake AI trading agents to deceive cryptocurrency enthusiasts. These malicious agents trick users into downloading harmful software that mimics legitimate tools. Once installed, the software scans victims’ browsers for cryptocurrency wallet extensions, such as Coinbase and MetaMask, and replaces them with deceptive versions designed to harvest login credentials.
Additionally, criminals are leveraging QR codes as a phishing tool, prompting users to scan codes on less-secure mobile devices. This tactic directs victims to phishing sites that can compromise login credentials, especially when users are lured with PDFs marked "blurred for security."
Expanding Threat Ecosystem
The report also highlights the emergence of Phantom Gate, a new malware loader enlarging the Phantom Stealer ecosystem. Marketed under the guise of legitimate penetration-testing software, Phantom Stealer, in combination with Phantom Gate, simplifies the process for attackers to design and deploy sophisticated attack campaigns.
"Attackers are tapping into Agentic AI tool adoption to invest in new lures that trick users into downloading malicious software that looks legitimate," stated Patrick Schläpfer, Principal Threat Researcher at HP Security Lab. "New attack tools such as Phantom Gate reflect the expanding threat landscape. They enable threat actors to easily compose dangerous infection chains, which greatly increases the risk of compromise for organizations."
Data Insights and Recommendations
HP Wolf Security users have interacted with approximately 60 billion email attachments
HP Wolf Security's approach of isolating threats that bypass detection tools allows malware to be safely contained within secure environments, offering valuable insights into current cyber adversary strategies. The report notes that, so far, HP Wolf Security users have interacted with approximately 60 billion email attachments, websites, and file downloads without security breaches being reported.
According to the report, during the period from April to June 2026, cybercriminals persist in diversifying tactics to circumvent protective measures. It was found that 10% of email threats intercepted by HP Sure Click had managed to bypass at least one email gateway scanner. Executable files represented the most common method of malware delivery at 40%, followed by archive files at 38%, and PDF documents at 7.5%.
"Users move constantly between devices and applications, like browsers or new AI tools – and attackers are quick to follow," remarked James Wright, HP’s Global Head of Security for Personal Systems. "Security needs to work across all of those interactions, without getting in people’s way. That means organizations need a zero-trust approach built around isolation and containment, so untrusted clicks and downloads don’t become a risk."
