Cyber readiness for SMBs: Getting the basics right
2026-07-04T08:51:37Z•12140e30a80c8f82316058fd7deb487f60a913bc5303e87d249cc04275095f3f
AI-enabled attacksAmadeyAndroid RATBTMOBCallPhantomEDR bypassESETEvilTokensFishMongerFrostyNeighborGamaredonGentlemen (RaaS)GopherWhisperNGateOperation EndgameSMB cyber readinessScarCruft supply‑chain attack analysis','OceanLotus','infosteal/SprySOCKSStealcWebwormkernel driver backdoorphishingtoken‑based phishingtrojanized NFC appweLiveSecurity
What happened
ESET’s WeLiveSecurity collection (Mar–Jul 2026) covers a broad set of active threats, research and defensive guidance: emphasis on improving SMB cyber‑readiness and supply‑chain/OT hygiene; analysis of AI‑accelerated attacker TTPs; multiple APT and crimeware investigations (Gamaredon, OceanLotus, GopherWhisper, Webworm, FrostyNeighbor, ScarCruft); new malware discoveries and evolutions (FishMonger’s SprySOCKS kernel‑driver backdoor, BTMOB Android RAT, NGate variant hidden in trojanized NFC payment app, CallPhantom fraudulent Play Store apps); a sophisticated phishing kit (EvilTokens) that sub‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- eset_welivesecurity
- Record identifier
- 12140e30a80c8f82316058fd7deb487f60a913bc5303e87d249cc04275095f3f
- Enrichment time
- 2026-07-04T08:51:37Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.