Webworm: New burrowing techniques
2026-05-21T08:51:38Z•d6269508962b51001a3f8ecaf7aaa909150ee85be943ded08caf33bc510e2a36
APTAndroid malwareCallPhantomEDR killersFrostyNeighborGenAI abuseGopherWhisperNFC payment trojanNGatePromptSpyScarCruftWebwormcyberespionagefraudransomwaresupply-chain attack
What happened
A collection of ESET WeLiveSecurity publications from Mar–May 2026 describing active offensive campaigns, new APT tooling and techniques, and high-impact malware. Notable research covers Webworm’s new burrowing techniques, updates to FrostyNeighbor’s compromise chain, the discovery of GopherWhisper (a China‑aligned APT targeting Mongolian institutions), a ScarCruft supply‑chain attack against gaming platforms, a trojanized NFC payment app delivering a new NGate variant, PromptSpy (first‑known Android malware abusing generative AI), large‑scale fraudulent Android apps (CallPhantom) removed from
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- eset_welivesecurity
- Record identifier
- d6269508962b51001a3f8ecaf7aaa909150ee85be943ded08caf33bc510e2a36
- Enrichment time
- 2026-05-21T08:51:38Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.