HP Threat Report: Cybercriminals Target Crypto Wallets with Agentic AI

0
HP Inc. has published its latest Threat Insights Report, offering an analysis of real-world cyberattacks and the evolving tactics cybercriminals use to bypass detection and compromise PCs. Drawing on data from millions of endpoints protected by HP Wolf Security, the report highlights several notable campaigns identified by HP’s threat research team, including:
  • Fake AI Trading Agents Lure Crypto Users into Malware Trap: Cybercriminals are capitalizing on interest in Agentic AI by advertising fake AI trading agents to trick users into infecting themselves with malware. Once downloaded, victims’ browsers are scanned for crypto wallet extensions like Coinbase and MetaMask, replacing them with malicious lookalikes that harvest any credentials entered.  Once harvested, attackers have easy access to steal crypto holdings.
  • QR Phishing Remains a Common Credential Theft Route: Attackers are using QR codes to move victims from PCs to less-protected mobile devices. Victims receive PDFs with content supposedly “blurred for security”. They are then prompted to scan a QR code with their phone, which redirects to phishing sites that may otherwise be blocked on their PCs, putting login credentials at risk.
  • Phantom Stealer Ecosystem Expands: Researchers identified Phantom Gate, a new malware loader, that appears to extend the Phantom Stealer campaign. Combining Phantom Stealer malware, which is openly marketed as legitimate penetration-testing software, with the Phantom Gate loader mechanism makes it easier for threat actors to build and scale attack campaigns.

Patrick Schläpfer, Principal Threat Researcher, HP Security Lab, comments: “Attackers are tapping into Agentic AI tool adoption to invest in new lures that trick users into downloading malicious software that looks legitimate. This tactic makes malware delivery more polished and harder to detect. New attack tools such as Phantom Gate reflect the expanding threat landscape. They enable threat actors to easily compose dangerous infection chains, which greatly increases the risk of compromise for organizations.”

By isolating threats that have evaded detection tools on PCs – but still allowing malware to detonate safely inside secure containers – HP Wolf Security has insight into the latest techniques used by cybercriminals. To date, HP Wolf Security customers have clicked on 60 billion email attachments, web pages and downloaded files with not reported breaches.

The report, which examines data from April-June 2026, details how cybercriminals continue to diversify attack methods to bypass security tools, revealing that:

  • At least 10% of email threats identified by HP Sure Click bypassed one or more email gateway scanners.
  • Executable files were the most popular malware delivery type (40%), followed by archive files (38%) and PDF documents (7.5%).

James Wright, HP’s Global Head of Security for Personal Systems comments: “Users move constantly between devices and applications, like browsers or new AI tools – and attackers are quick to follow. Security needs to work across all of those interactions, without getting in people’s way. That means organizations need a zero-trust approach built around isolation and containment, so untrusted clicks and downloads don’t become a risk.”

Please visit the HP Threat Research blog to view the report.

Related News:

10ZiG and Leostream Partner to Simplify HP Anyware Migration

HP Research: Legitimate Remote Access Tools Used as Backdoors

Frequently Asked Questions
  1. What are the main findings from HP’s latest Threat Insights Report? The report shows attackers exploiting interest in Agentic AI tools to lure victims, using QR codes to shift credential theft onto less-protected mobile devices, and continuing to invest in specialized malware capability modules like the Phantom Gate loader to expand existing malware campaigns.
  2. How are attackers using interest in Agentic AI? In this report, we find that attackers are advertising fake AI trading agents to cryptocurrency users. When installed, the malware scans browsers for crypto wallet extensions such as Coinbase and MetaMask, replaces them with malicious lookalikes, and harvests credentials entered by victims.
  3. Why does QR phishing remain a concern? QR phishing moves users from PCs to mobile devices that may have weaker protections. HP researchers observed malicious PDFs claiming content was “blurred for security” and prompting users to scan QR codes for authenticated access, redirecting them to phishing sites to steal login credentials.
  4. What does Phantom Gate reveal about the cybercrime ecosystem? Phantom Gate is a new malware loader that shows how threat actors are investing in specialized modular components to make attack campaigns, like Phantom Stealer, easier to build and scale. Phantom Stealer is sold to attackers as “legitimate” penetration-testing software, showing how cybercrime-as-a-service blurs the line between legitimate tools and malware.
  5. What should organizations take from the report? The report shows how Agentic AI momentum expands opportunities for attackers to trick users into downloading malicious software. We also see continued threat actor investment in developing tools to scale phishing and malware deployment. This tells us that organizations should assume malicious links, files and downloads may evade traditional detection. It highlights the importance of integrating isolation and containment into a zero-trust approach to prevent untrusted clicks and downloads from becoming endpoint compromises.

About the Data

This data was gathered from consenting HP Wolf Security customers from April-June 2026, with investigations conducted by the HP Threat Research Team.

Share.

About Author

Leigh Porter's first love is to love people. Beginning her career as a neonatal RN was an obvious choice until life threw the curve ball to embark on a new IT endeavor. Pursuing this fresh career was a piece of cake with her resilient and steadfast character. Outside of the office, Leigh also diligently gives much of her time faithfully as a nationally awarded volunteer leader to a very dear to her heart organization.