{"id":9891,"date":"2025-12-19T00:03:49","date_gmt":"2025-12-19T00:03:49","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=9891"},"modified":"2025-12-19T00:03:49","modified_gmt":"2025-12-19T00:03:49","slug":"eset-menace-report-h2-2025","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=9891","title":{"rendered":"ESET Menace Report H2 2025"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p class=\"sub-title\">A view of the H2 2025 menace panorama as seen by ESET telemetry and from the attitude of ESET menace detection and analysis consultants<\/p>\n<div class=\"article-authors d-flex flex-wrap\">\n<div class=\"article-author d-flex\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/en\/our-experts\/jiri-kropac\/\" title=\"Ji\u0159\u00ed Krop\u00e1\u010d\"><picture><source srcset=\"https:\/\/web-assets.esetstatic.com\/tn\/-x45\/wls\/jiri-kropac.jpeg\" media=\"(max-width: 768px)\"\/><img decoding=\"async\" class=\"author-image me-3\" src=\"https:\/\/web-assets.esetstatic.com\/tn\/-x45\/wls\/jiri-kropac.jpeg\" alt=\"Ji\u0159\u00ed Krop\u00e1\u010d\"\/><\/picture><\/a><\/div>\n<\/div>\n<p class=\"article-info mb-5\">\n        <span>16 Dec 2025<\/span><br \/>\n        <span class=\"d-none d-lg-inline\">\u00a0\u2022\u00a0<\/span><br \/>\n        <span class=\"d-inline d-lg-none\">, <\/span><br \/>\n        <span>2 min. learn<\/span>\n    <\/p>\n<div class=\"hero-image-container\">\n        <picture><source srcset=\"https:\/\/web-assets.esetstatic.com\/tn\/-x266\/wls\/2025\/12-25\/eset-threat-report-h2-2025.jpg\" media=\"(max-width: 768px)\"\/><source srcset=\"https:\/\/web-assets.esetstatic.com\/tn\/-x425\/wls\/2025\/12-25\/eset-threat-report-h2-2025.jpg\" media=\"(max-width: 1120px)\"\/><img decoding=\"async\" class=\"hero-image\" src=\"https:\/\/web-assets.esetstatic.com\/tn\/-x700\/wls\/2025\/12-25\/eset-threat-report-h2-2025.jpg\" alt=\"ESET Threat Report H2 2025\"\/><\/picture>    <\/div>\n<\/div>\n<div>\n<p>The second half of the yr underscored simply how shortly attackers adapt and innovate, with fast modifications sweeping throughout the menace panorama.<\/p>\n<p>AI-powered malware moved from concept to actuality in H2 2025, as ESET found PromptLock, the primary recognized AI-driven ransomware, able to producing malicious scripts on the fly. Whereas AI remains to be primarily used for crafting convincing phishing and rip-off content material, PromptLock \u2013 and the handful of different AI-driven threats recognized to at the present time \u2013 sign a brand new period of threats.<\/p>\n<p>After its world disruption in Might, Lumma Stealer managed to briefly resurface \u2013 twice \u2013 however its glory days are more than likely over. Detections plummeted by 86% in H2 2025 in comparison with the primary half of the yr, and a big distribution vector of Lumma Stealer \u2013 HTML\/FakeCaptcha trojan, utilized in ClickFix assaults \u2013 almost vanished from our telemetry.<\/p>\n<p>In the meantime, CloudEyE, also referred to as GuLoader, surged into prominence, skyrocketing nearly thirtyfold in ESET telemetry. Distributed through malicious e mail campaigns, this malware-as-a-service downloader and cryptor is used to deploy different malware, together with ransomware, in addition to infostealer juggernauts corresponding to Rescoms, Formbook, and Agent Tesla.<\/p>\n<p>On the ransomware scene, sufferer numbers surpassed 2024 totals nicely earlier than yr\u2019s finish, with ESET Analysis projections pointing to a 40% year-over-year improve. Akira and Qilin now dominate the ransomware-as-a-service market, whereas low-profile newcomer Warlock launched revolutionary evasion strategies. EDR killers continued to proliferate, highlighting that endpoint detection and response instruments stay a big impediment for ransomware operators. H2 2025 additionally introduced an disagreeable flashback to the Petya\/NotPetya ransomware, when ESET researchers uncovered HybridPetya \u2013 a brand new derivate of the notorious malware able to compromising trendy UEFI-based programs.<\/p>\n<p>On the Android platform, NFC threats continued to develop in scale and class, with an 87% improve in ESET telemetry and several other notable upgrades and campaigns noticed in H2 2025. NGate \u2013 a pioneer amongst NFC threats, first described by ESET in 2024 \u2013 obtained an improve within the type of contact stealing, doubtless laying the groundwork for future assaults. RatOn, completely new malware on the NFC fraud scene, introduced a uncommon fusion of RAT capabilities and NFC relay assaults, displaying cybercriminals\u2019 dedication to pursuing new assault avenues.<\/p>\n<p>Fraudsters behind the Nomani funding scams have additionally refined their strategies \u2013 we now have noticed higher-quality deepfakes, indicators of AI-generated phishing websites, and more and more short-lived advert campaigns to keep away from detection. In ESET telemetry, detections of Nomani scams grew 62% year-over-year, with the pattern declining barely in H2 2025.<\/p>\n<blockquote>\n<div><em>Comply with ESET analysis on\u00a0<\/em><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/twitter.com\/ESETresearch\" target=\"_blank\" rel=\"noopener\">X<\/a><em>,\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/bsky.app\/profile\/esetresearch.bsky.social\" target=\"_blank\" rel=\"noopener\">Bluesky\u00a0<\/a>and\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/infosec.exchange\/@ESETresearch\" target=\"_blank\" rel=\"noopener\">Mastodon\u00a0<\/a>for normal updates on key traits and high threats.<\/em><\/p>\n<p><em>To study extra about how menace intelligence can improve the cybersecurity posture of your group, go to the\u00a0<\/em><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.eset.com\/int\/business\/services\/threat-intelligence\/?utm_source=welivesecurity.com&amp;utm_medium=referral&amp;utm_campaign=wls-research&amp;utm_content=eset-threat-report-h2-2024\" target=\"_blank\" rel=\"noopener\">ESET\u00a0Menace Intelligence<\/a><em>\u00a0web page.<\/em><\/p>\n<\/div>\n<\/blockquote>\n<\/div>\n<p><template id="VDiZv8Xz5ZrO7shZYbXY"></template><\/script><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A view of the H2 2025 menace panorama as seen by ESET telemetry and from the attitude of ESET menace detection and analysis consultants 16 Dec 2025 \u00a0\u2022\u00a0 , 2 min. learn The second half of the yr underscored simply how shortly attackers adapt and innovate, with fast modifications sweeping throughout the menace panorama. AI-powered [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":9893,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[679,770,461],"class_list":["post-9891","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-eset","tag-report","tag-threat"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/9891","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9891"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/9891\/revisions"}],"predecessor-version":[{"id":9892,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/9891\/revisions\/9892"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/9893"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9891"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9891"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9891"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-17 08:04:28 UTC -->