The calm before the ransom: What you see is not all there is

2026-04-25T08:51:42Z9f935e0857a4efa68909a020e19493cac218db827720a482f221f1ac0c770e10
AI-assisted malwareAPTAndroid malwareDynoWiperEDR killersESETGenAIGopherWhisperNGatePromptSpySandwormSednitSilver Foxcloud securitynaming-and-shamingransomwarespywaresupply-chain risktrojanized NFC appvulnerable drivers

What happened

Collection of ESET WeLiveSecurity research and advisories (Jan–Apr 2026) highlighting multiple active threat trends: discovery of a new China-aligned APT dubbed “GopherWhisper” targeting Mongolian government entities; a new NGate malware variant hidden in a trojanized NFC payment app (possible AI-assisted development); PromptSpy — the first known Android malware to incorporate generative AI into its execution flow; analysis of EDR-killer tooling that abuses vulnerable drivers; technical coverage of DynoWiper (attributed to Sandworm) — a destructive data-wiping incident affecting Poland’s power

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
eset_welivesecurity
Record identifier
9f935e0857a4efa68909a020e19493cac218db827720a482f221f1ac0c770e10
Enrichment time
2026-04-25T08:51:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.