Crypto-stealers, malicious QR codes, and ready-made malware: a new report from HP exposes the most acute risks for PC users.
Cybercriminals are cleverly capitalizing on the popularity of AI agents. This is according to the latest Threat Insights Report from HP Wolf Security, which analyzes attacks from the second quarter of 2026. The report is based on actual attack attempts blocked by HP’s security suite. HP thus has a front-row seat to how attackers operate and continue to refine their methods.
Fake crypto-agent #
A first campaign noted by HP targets crypto wallets. The attackers promote a ‘crypto trading bot’ that supposedly trades 24/7 in your name according to a self-chosen strategy. The name of the bot deliberately mimics that of a well-known, unnamed AI assistant to build trust. Traffic to the site comes via search engine poisoning and paid advertisements: anyone searching for an AI agent for their portfolio will naturally stumble upon it.
What you actually download is a ZIP archive containing two files. The executable file is a tool signed by Microsoft. This is precisely why it passes the SmartScreen reputation check without warning. The real payload is an infostealer, which is loaded upon startup.
This malware does something more specific than the average password thief. It scans installed browser extensions and compares their IDs against a list of seven crypto wallets. If a match is found, the malware closes the browser, replaces the extension with an infected version, and restarts. The counterfeit login screens are meticulously designed and nearly indistinguishable from the real ones. Anyone who enters their password sends it directly to the attacker, who can then drain the wallet.
“Attackers are capitalizing on the growing popularity of agentic AI tools and using new ways to deceive users and trick them into down malicious software that appears trustworthy,” says Patrick Schläpfer, Principal Threat Researcher at HP Security Lab. “As a result, the distribution of malware is becoming increasingly sophisticated and difficult to detect.”
The underlying problem is not technical but human: new AI tools and agents appear daily, making the distinction between legitimate software and malware with a convincing appearance increasingly difficult.
QR codes push the victim toward the smartphone #
A second campaign utilizes a classic with a clever twist. Victims receive a PDF invoice with blurred content, stating they must scan the QR code with their phone to view the document. Those who do so pass through several redirects, including a page posing as an email security scanner. Only then does a counterfeit Microsoft login page appear, which captures the credentials.
The attackers’ trick lies in making the victim switch devices. By sending the victim to the smartphone, attackers bypass the security layers that are active on the work PC, such as HP Wolf Security. A URL that the corporate browser blocks often opens without issue on a phone.
Malware as a construction kit #
HP’s third finding concerns the professionalization of malware. In addition to Phantom Stealer, an infostealer openly sold on the clear web as a “penetration testing tool” with performance benchmarks and 24/7 support, researchers discovered Phantom Gate. This extracts the malware from a seemingly innocent image and injects it into a legitimate Windows process. The name and methodology suggest both originate from the same creator.
With this, HP illustrates a broader shift. Attackers assemble campaigns from ready-made components that they mix and match, lowering the barrier to entry and increasing the scale.
One wrong click is enough #
The figures behind the report emphasize that detection alone is not enough. At least ten percent of the email threats detected by HP Sure Click passed one or more email scanners. Executable files remained the most popular vehicle (40 percent), followed by archive files (38 percent) and PDFs (7.5 percent).
“Cybercriminals do not need to defeat every security layer. Often, one wrong click or download is enough to create an initial entry point,” says Pelle Aardewerk, Security Specialist at HP. “Organizations should therefore not assume that every attack can be prevented. The most important question is what happens if someone does make the wrong choice.”