Inside the inbox: Why cybercriminals want to break into your email account

2026-06-30T08:51:41Zff43ff9f8fdeec2f9b098d3ad00fdff14c7d41b1d9b73ad09d9ecc0a09c89d8f
APTAmadeyAndroid RATBTMOBCallPhantom','supply chain','OT security','SMB cyber readiness'EDR evasionESETEvilTokensFishMongerFrostyNeighborGamaredonGentlemen RaaSGopherWhisperNGateOceanLotusOperation EndgameScarCruftSprySOCKSStealcWeLiveSecurityWebwormbotnetemail compromiseinfostealerphishing

What happened

ESET WeLiveSecurity feed (Mar–Jun 2026) compiling research, advisories and news on a wide spectrum of cyber threats and defensive guidance. Topics include email account compromise and advanced phishing (EvilTokens), botnet/infostealer activity and a global disruption operation (Amadey, Stealc, Operation Endgame), APT reporting and new tooling (Gamaredon, OceanLotus, Webworm, FrostyNeighbor, GopherWhisper, ScarCruft), new malware and capabilities (FishMonger’s SprySOCKS kernel-backed backdoor, NGate variant, BTMOB Android RAT, CallPhantom), EDR evasion frameworks (Gentlemen’s EDR killer / RaaS)

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
eset_welivesecurity
Record identifier
ff43ff9f8fdeec2f9b098d3ad00fdff14c7d41b1d9b73ad09d9ecc0a09c89d8f
Enrichment time
2026-06-30T08:51:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.