HP Research: Cybercriminals Leaning into Agentic AI Momentum to Steal Crypto Wallets

  •  

    – HP Inc. (NYSE: HPQ) today released its latest Threat Insights Report, providing analysis of real-world cyberattacks, helping organizations keep up with the latest techniques cybercriminals are using to evade detection and breach PCs in the fast-changing cybercrime landscape. Based on millions of endpoints running HP Wolf Security*, notable campaigns identified by HP Wolf Security threat researchers include:

          Fake AI Trading Agents Lure Crypto Users into Malware Trap: Cybercriminals are capitalizing on interest in Agentic AI by advertising fake AI trading agents to trick users into infecting themselves with malware. Once downloaded, victims’ browsers are scanned for crypto wallet extensions like Coinbase and MetaMask, replacing them with malicious lookalikes that harvest any credentials entered.  Once harvested, attackers have easy access to steal crypto holdings.

     

          QR Phishing Remains a Common Credential Theft Route: Attackers are using QR codes to move victims from PCs to less-protected mobile devices. Victims receive PDFs with content supposedly “blurred for security”. They are then prompted to scan a QR code with their phone which redirects to phishing sites that may otherwise be blocked on their PCs, putting login credentials at risk.

     

          Phantom Stealer Ecosystem Expands: Researchers identified Phantom Gate, a new malware loader, that appears to extend the Phantom Stealer campaign. Combining Phantom Stealer malware, which is openly marketed as legitimate penetration-testing software, with the Phantom Gate loader mechanism, makes it easier for threat actors to build and scale attack campaigns.

     

    Patrick Schläpfer, Principal Threat Researcher, HP Security Lab, comments: “Attackers are tapping into Agentic AI tool adoption to invest in new lures that trick users into downloading malicious software that looks legitimate. This tactic makes malware delivery more polished and harder to detect. New attack tools such as Phantom Gate reflect the expanding threat landscape. They enable threat actors to easily compose dangerous infection chains, which greatly increases the risk of compromise for organizations.”

     

    By isolating threats that have evaded detection tools on PCs – but still allowing malware to detonate safely inside secure containers – HP Wolf Security has insight into the latest techniques used by cybercriminals. To date, HP Wolf Security customers have clicked on 60 billion email attachments, web pages and downloaded files with not reported breaches.

     

    The report, which examines data from April-June 2026, details how cybercriminals continue to diversify attack methods to bypass security tools, revealing that:

     

          At least 10% of email threats identified by HP Sure Click bypassed one or more email gateway scanner.

          Executable files were the most popular malware delivery type (40%), followed by archive files (38%) and PDF documents (7.5%).

     

    James Wright, HP’s Global Head of Security for Personal Systems comments: “Users move constantly between devices and applications, like browsers or new AI tools – and attackers are quick to follow. Security needs to work across all of those interactions, without getting in people’s way. That means organizations need a zero-trust approach built around isolation and containment, so untrusted clicks and downloads don’t become a risk.”

    حمّل تطبيق Alamrakamy| عالم رقمي الآن