ESET APT Activity Report Q4 2025–Q1 2026
2026-05-29T08:51:37Z•771655a29b308991727a6f0a1bc2adfcd67d393f736c35d7a54b714ec5b11656
androidaptcampaign-trackingcloud-securitycredential-theftedr-killersespionagegenaiiotmalwaremobile-fraudnfcphishingprivacyransomwarescamssupply-chainthreat-researchweblive-security
What happened
A roundup of ESET WeLiveSecurity content (Q4 2025–Q1 2026) covering active APT campaigns, mobile and supply‑chain threats, scams and privacy risks, and emerging AI-assisted malware. Notable items include new and resurgent APT activity (Webworm, FrostyNeighbor, GopherWhisper, ScarCruft, Sednit, Silver Fox), Android threats and fraud (BTMOB RAT, PromptSpy — the first observed Android malware abusing generative AI — CallPhantom with millions of downloads, and a trojanized NFC payment app hiding an NGate variant), research on EDR killers and new burrowing techniques, plus consumer/business advice—
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- eset_welivesecurity
- Record identifier
- 771655a29b308991727a6f0a1bc2adfcd67d393f736c35d7a54b714ec5b11656
- Enrichment time
- 2026-05-29T08:51:37Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.