Recovery scammers hit you when you’re down: Here’s how to avoid a second strike

2026-04-11T08:51:40Z9cca3d8119e3a3566e2ed69ce0afbebd3506bb647d69edbaf8f33f974604a406
Android spywareDynoWiperEDR killersESETGenAI malwarePromptSpySandwormSednitSilver FoxThreat Researchaccount recoverycloud VM securitycloud workload securitycredential stuffingdeepfake voicefacial recognition spoofingmarketplace scamsmobile app permissionsransomware naming-and-shamingrecovery scamsscamstax scamsvulnerable drivers

What happened

ESET's WeLiveSecurity roundup highlights a broad set of active threats and defensive guidance: targeted espionage (Sednit, Sandworm/DynoWiper), commodity and opportunistic malware (PromptSpy — first-known Android malware abusing generative AI, EDR-killer toolchains abusing vulnerable drivers), sector- and region-focused campaigns (Silver Fox targeting Japanese firms, Android spyware in Pakistan), and prolific social-engineering scams (recovery scams, tax/marketplace scams, credential stuffing, brushing). Coverage also emphasizes emerging risks from AI-enabled deepfakes (voice and facial spoof‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
eset_welivesecurity
Record identifier
9cca3d8119e3a3566e2ed69ce0afbebd3506bb647d69edbaf8f33f974604a406
Enrichment time
2026-04-11T08:51:40Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Recovery scammers hit you when you’re down: Here’s how to avoid a second strike · Baitaphish