Webworm: New burrowing techniques

2026-05-21T08:51:38Zd6269508962b51001a3f8ecaf7aaa909150ee85be943ded08caf33bc510e2a36
APTAndroid malwareCallPhantomEDR killersFrostyNeighborGenAI abuseGopherWhisperNFC payment trojanNGatePromptSpyScarCruftWebwormcyberespionagefraudransomwaresupply-chain attack

What happened

A collection of ESET WeLiveSecurity publications from Mar–May 2026 describing active offensive campaigns, new APT tooling and techniques, and high-impact malware. Notable research covers Webworm’s new burrowing techniques, updates to FrostyNeighbor’s compromise chain, the discovery of GopherWhisper (a China‑aligned APT targeting Mongolian institutions), a ScarCruft supply‑chain attack against gaming platforms, a trojanized NFC payment app delivering a new NGate variant, PromptSpy (first‑known Android malware abusing generative AI), large‑scale fraudulent Android apps (CallPhantom) removed from

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
eset_welivesecurity
Record identifier
d6269508962b51001a3f8ecaf7aaa909150ee85be943ded08caf33bc510e2a36
Enrichment time
2026-05-21T08:51:38Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Webworm: New burrowing techniques · Baitaphish