Inside the inbox: Why cybercriminals want to break into your email account
2026-06-30T08:51:41Z•ff43ff9f8fdeec2f9b098d3ad00fdff14c7d41b1d9b73ad09d9ecc0a09c89d8f
APTAmadeyAndroid RATBTMOBCallPhantom','supply chain','OT security','SMB cyber readiness'EDR evasionESETEvilTokensFishMongerFrostyNeighborGamaredonGentlemen RaaSGopherWhisperNGateOceanLotusOperation EndgameScarCruftSprySOCKSStealcWeLiveSecurityWebwormbotnetemail compromiseinfostealerphishing
What happened
ESET WeLiveSecurity feed (Mar–Jun 2026) compiling research, advisories and news on a wide spectrum of cyber threats and defensive guidance. Topics include email account compromise and advanced phishing (EvilTokens), botnet/infostealer activity and a global disruption operation (Amadey, Stealc, Operation Endgame), APT reporting and new tooling (Gamaredon, OceanLotus, Webworm, FrostyNeighbor, GopherWhisper, ScarCruft), new malware and capabilities (FishMonger’s SprySOCKS kernel-backed backdoor, NGate variant, BTMOB Android RAT, CallPhantom), EDR evasion frameworks (Gentlemen’s EDR killer / RaaS)
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- eset_welivesecurity
- Record identifier
- ff43ff9f8fdeec2f9b098d3ad00fdff14c7d41b1d9b73ad09d9ecc0a09c89d8f
- Enrichment time
- 2026-06-30T08:51:41Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.