ESET Threat Report H1 2026

2026-07-09T08:51:40Z9d3878161f640a7ae9bf40f5031b67da7565ef1f5d5a2ff672d7debc23cb3c68
amadeyandroid-rat','btmob','callphantom','smB-readiness','ot-security'aptbackdoorbotnetedr-killereset-threat-reporteviltokensfishmongergamaredongentlemengopherwhisperh1-2026infostealerkernel-drivermalwarengateoceanlotusphishing-kitraasscarcruftsprysocksstealcsupply-chainwebworm

What happened

ESET’s H1 2026 collection highlights a high-activity, evolving threat landscape: new APT discoveries and shifts (GopherWhisper, Gamaredon, Webworm, OceanLotus, FrostyNeighbor, ScarCruft), widespread commodity and targeted malware (BTMOB Android RAT, NGate variant, FishMonger’s SprySOCKS kernel backdoor), large-scale botnet/infostealer disruption (Amadey, Stealc), and novel phishing techniques (EvilTokens subverting Microsoft auth). Reported trends include increased abuse of legitimate online services and tunneling for C2/exfiltration, supply-chain compromise, growing RaaS tooling (Gentlemen E2

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
eset_welivesecurity
Record identifier
9d3878161f640a7ae9bf40f5031b67da7565ef1f5d5a2ff672d7debc23cb3c68
Enrichment time
2026-07-09T08:51:40Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · ESET Threat Report H1 2026 · Baitaphish