ESET Threat Report H2 2025: AI Ransomware and Evolving Cyber Threats
ESET's H2 2025 Threat Report highlights a rapidly evolving cybersecurity landscape marked by the emergence of AI-powered malware. A significant milestone was the discovery of PromptLock, the first known AI-driven ransomware capable of generating malicious scripts dynamically, signaling a new era in cyber threats. While Lumma Stealer detections plummeted by 86%, CloudEyE (GuLoader) surged thirtyfold, serving as a primary downloader for infostealers like Rescoms and Agent Tesla. The ransomware sector saw victim numbers exceed 2024 totals, with Akira and Qilin dominating the market and HybridPetya emerging as a UEFI-compromising derivative of NotPetya. On mobile platforms, NFC-based threats on Android increased by 87%, featuring upgraded tools like NGate and new malware such as RatOn. Additionally, investment fraud schemes like Nomani utilized advanced deepfakes and AI-generated phishing sites, though detection rates slightly declined in the second half. The report underscores attackers' increasing adaptation speed, particularly in leveraging AI for evasion and content creation, while emphasizing the continued importance of endpoint detection and response tools against proliferating EDR killers.
Wire timeline
ESET Threat Report H2 2025: AI Ransomware and Evolving Cyber Threats
ESET's H2 2025 Threat Report highlights a rapidly evolving cybersecurity landscape marked by the emergence of AI-powered malware. A significant milestone was the discovery of PromptLock, the first known AI-driven ransomware capable of generating malicious scripts dynamically, signaling a new era in cyber threats. While Lumma Stealer detections plummeted by 86%, CloudEyE (GuLoader) surged thirtyfold, serving as a primary downloader for infostealers like Rescoms and Agent Tesla. The ransomware sector saw victim numbers exceed 2024 totals, with Akira and Qilin dominating the market and HybridPetya emerging as a UEFI-compromising derivative of NotPetya. On mobile platforms, NFC-based threats on Android increased by 87%, featuring upgraded tools like NGate and new malware such as RatOn. Additionally, investment fraud schemes like Nomani utilized advanced deepfakes and AI-generated phishing sites, though detection rates slightly declined in the second half. The report underscores attackers' increasing adaptation speed, particularly in leveraging AI for evasion and content creation, while emphasizing the continued importance of endpoint detection and response tools against proliferating EDR killers.
WeLiveSecurity