{"slug": "fake-ai-agents-as-bait-attackers-capitalize-on-the-hype", "title": "Fake AI agents as bait: attackers capitalize on the hype", "summary": "HP Wolf Security's latest Threat Insights Report, analyzing attacks from the second quarter of 2026, found cybercriminals capitalizing on AI agent hype with campaigns including a fake crypto trading bot that mimics a well-known AI assistant's name and a PDF invoice QR-code phishing scheme. The fake crypto bot delivers a ZIP archive whose Microsoft-signed executable passes SmartScreen before loading an infostealer that scans browser extensions against a list of seven crypto wallets, replaces matches with infected versions, and harvests credentials. \"Attackers are capitalizing on the growing popularity of agentic AI tools and using new ways to deceive users and trick them into downloading malicious software that appears trustworthy,\" said Patrick Schläpfer, Principal Threat Researcher at HP Security Lab, who noted malware distribution is becoming increasingly sophisticated and difficult to detect.", "body_md": "**Crypto-stealers, malicious QR codes, and ready-made malware: a new report from HP exposes the most acute risks for PC users.**\n\nCybercriminals are cleverly capitalizing on the popularity of AI agents. This is according to the latest Threat Insights Report from [HP Wolf Security](https://itdaily.be/blogs/beveiliging/wat-is-hp-wolf-security/), which analyzes attacks from the second quarter of 2026. The report is based on actual attack attempts blocked by HP’s security suite. HP thus has a front-row seat to how attackers operate and continue to refine their methods.\n\n## Fake crypto-agent\n\nA first campaign noted by HP targets crypto wallets. The attackers promote a ‘crypto trading bot’ that supposedly trades 24/7 in your name according to a self-chosen strategy. The name of the bot deliberately mimics that of a well-known, unnamed AI assistant to build trust. Traffic to the site comes via *search engine poisoning* and paid advertisements: anyone searching for an AI agent for their portfolio will naturally stumble upon it.\n\nWhat you actually download is a ZIP archive containing two files. The executable file is a tool signed by Microsoft. This is precisely why it passes the SmartScreen reputation check without warning. The real payload is an infostealer, which is loaded upon startup.\n\nThis malware does something more specific than the average password thief. It scans installed browser extensions and compares their IDs against a list of seven crypto wallets. If a match is found, the malware closes the browser, replaces the extension with an infected version, and restarts. The counterfeit login screens are meticulously designed and nearly indistinguishable from the real ones. Anyone who enters their password sends it directly to the attacker, who can then drain the wallet.\n\n“Attackers are capitalizing on the growing popularity of agentic AI tools and using new ways to deceive users and trick them into downloading malicious software that appears trustworthy,” says Patrick Schläpfer, Principal Threat Researcher at HP Security Lab. “As a result, the distribution of malware is becoming increasingly sophisticated and difficult to detect.”\n\nThe underlying problem is not technical but human: new AI tools and agents appear daily, making the distinction between legitimate software and malware with a convincing appearance increasingly difficult.\n\n## QR codes push the victim toward the smartphone\n\nA second campaign utilizes [a classic](https://itdaily.com/news/security/phishing-met-qr-codes-in-opmars/) with a clever twist. Victims receive a PDF invoice with blurred content, stating they must scan the QR code with their phone to view the document. Those who do so pass through several redirects, including a page posing as an email security scanner. Only then does a counterfeit Microsoft login page appear, which captures the credentials.\n\nThe attackers’ trick lies in making the victim switch devices. By sending the victim to the smartphone, attackers bypass the security layers that are active on the work PC, such as HP Wolf Security. A URL that the corporate browser blocks often opens without issue on a phone.\n\n## Malware as a construction kit\n\nHP’s third finding concerns the professionalization of malware. In addition to *Phantom Stealer,* an infostealer openly sold on the clear web as a “penetration testing tool” with performance benchmarks and 24/7 support, researchers discovered *Phantom Gate*. This loader extracts the malware from a seemingly innocent image and injects it into a legitimate Windows process. The name and methodology suggest both originate from the same creator.\n\nWith this, HP illustrates a broader shift. Attackers assemble campaigns from ready-made components that they mix and match, lowering the barrier to entry and increasing the scale.\n\n## One wrong click is enough\n\nThe figures behind the report emphasize that detection alone is not enough. At least ten percent of the email threats detected by HP Sure Click passed one or more email scanners. Executable files remained the most popular vehicle (40 percent), followed by archive files (38 percent) and PDFs (7.5 percent).\n\n“Cybercriminals do not need to defeat every security layer. Often, one wrong click or download is enough to create an initial entry point,” says Pelle Aardewerk, Security Specialist at HP. “Organizations should therefore not assume that every attack can be prevented. The most important question is what happens if someone does make the wrong choice.”", "url": "https://wpnews.pro/news/fake-ai-agents-as-bait-attackers-capitalize-on-the-hype", "canonical_source": "https://itdaily.com/blogs/security/hp-security-report/", "published_at": "2026-09-18 11:52:37+00:00", "updated_at": "2026-09-18 12:22:47.474294+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety"], "entities": ["HP Wolf Security", "HP", "HP Security Lab", "Patrick Schläpfer", "Phantom Stealer", "Phantom Gate", "HP Sure Click", "Microsoft"], "alternates": {"html": "https://wpnews.pro/news/fake-ai-agents-as-bait-attackers-capitalize-on-the-hype", "markdown": "https://wpnews.pro/news/fake-ai-agents-as-bait-attackers-capitalize-on-the-hype.md", "text": "https://wpnews.pro/news/fake-ai-agents-as-bait-attackers-capitalize-on-the-hype.txt", "jsonld": "https://wpnews.pro/news/fake-ai-agents-as-bait-attackers-capitalize-on-the-hype.jsonld"}}