The calm before the ransom: What you see is not all there is
2026-04-25T08:51:42Z•9f935e0857a4efa68909a020e19493cac218db827720a482f221f1ac0c770e10
AI-assisted malwareAPTAndroid malwareDynoWiperEDR killersESETGenAIGopherWhisperNGatePromptSpySandwormSednitSilver Foxcloud securitynaming-and-shamingransomwarespywaresupply-chain risktrojanized NFC appvulnerable drivers
What happened
Collection of ESET WeLiveSecurity research and advisories (Jan–Apr 2026) highlighting multiple active threat trends: discovery of a new China-aligned APT dubbed “GopherWhisper” targeting Mongolian government entities; a new NGate malware variant hidden in a trojanized NFC payment app (possible AI-assisted development); PromptSpy — the first known Android malware to incorporate generative AI into its execution flow; analysis of EDR-killer tooling that abuses vulnerable drivers; technical coverage of DynoWiper (attributed to Sandworm) — a destructive data-wiping incident affecting Poland’s power
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- eset_welivesecurity
- Record identifier
- 9f935e0857a4efa68909a020e19493cac218db827720a482f221f1ac0c770e10
- Enrichment time
- 2026-04-25T08:51:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.