ESET APT Activity Report Q4 2025–Q1 2026

2026-05-29T08:51:37Z771655a29b308991727a6f0a1bc2adfcd67d393f736c35d7a54b714ec5b11656
androidaptcampaign-trackingcloud-securitycredential-theftedr-killersespionagegenaiiotmalwaremobile-fraudnfcphishingprivacyransomwarescamssupply-chainthreat-researchweblive-security

What happened

A roundup of ESET WeLiveSecurity content (Q4 2025–Q1 2026) covering active APT campaigns, mobile and supply‑chain threats, scams and privacy risks, and emerging AI-assisted malware. Notable items include new and resurgent APT activity (Webworm, FrostyNeighbor, GopherWhisper, ScarCruft, Sednit, Silver Fox), Android threats and fraud (BTMOB RAT, PromptSpy — the first observed Android malware abusing generative AI — CallPhantom with millions of downloads, and a trojanized NFC payment app hiding an NGate variant), research on EDR killers and new burrowing techniques, plus consumer/business advice—

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
eset_welivesecurity
Record identifier
771655a29b308991727a6f0a1bc2adfcd67d393f736c35d7a54b714ec5b11656
Enrichment time
2026-05-29T08:51:37Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.