This month in security with Tony Anscombe – April 2026 edition
2026-05-01T08:51:43Z•17ce9e7ae0b08ced660beaaa4a73dfd65fd6bf0b61952e91dc4de0228692fad6
AI‑assisted malwareAPTAndroid malwareDynoWiperEDR killersGopherWhisperIran‑linked actorsNFCNGatePromptSpySandwormSednitSilver FoxVM securitycloud securitycritical infrastructuredata‑wiperdeepfake voicefacial recognition bypassgenerative AIphishingransomwarescamssupply‑chain risktrojanized app
What happened
ESET’s April 2026 coverage highlights a surge in high‑impact offensive activity and evolving malware techniques. Key findings include discovery of a new China‑aligned APT named GopherWhisper targeting Mongolian government institutions; a new NGate variant hidden in a trojanized NFC payment app (possibly developed with AI assistance); PromptSpy, the first known Android malware to incorporate generative AI in its execution flow; and DynoWiper, a destructive data‑wiper attributed to Sandworm that impacted Poland’s energy sector. Reports also describe a Sednit resurgence, attackers abusing EDR‑vul
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- eset_welivesecurity
- Record identifier
- 17ce9e7ae0b08ced660beaaa4a73dfd65fd6bf0b61952e91dc4de0228692fad6
- Enrichment time
- 2026-05-01T08:51:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.