Formbook is the most widespread infostealer; Lumma Stealer sees an increase of 400%. Social media scams increase by 335%. RansomHub establishes itself as a major RaaS player, while cryptocurrency wallets, particularly on macOS, are among the main targets
ESET, the global European leader in the cybersecurity market, has published its latest Threat Report, which summarizes the trends observed by its detection systems from June to November 2024.
A significant shift has occurred in the infostealer category, with Formbook displacing Agent Tesla from the top spot. Formbook is a well-established threat, designed to steal a wide range of sensitive data. Lumma Stealer, which has seen a 369% increase in ESET telemetry detections, is gaining traction among cybercriminals, with a growing presence in major malicious campaigns in the second half of 2024. Social media has been flooded with a new wave of scams using deepfake videos and spoofed company posts to lure victims into fraudulent investment schemes. These scams, identified by ESET as HTML/Nomani, have seen a 335% increase compared to the previous period. The countries with the highest number of detections were Japan, Slovakia, Canada, Spain and the Czech Republic.
“The second half of 2024 has seen cybercriminals exploit security vulnerabilities and devise new ways to expand their reach in the usual cat-and-mouse game with security systems,” said Jiří Kropáč, Director of Threat Detection at ESET. “We have observed new attack vectors, social engineering methods, emerging threats in our telemetry and enforcement operations that have destabilized previous balances.”
Among infostealers, the well-known “infostealer-as-a-service” Redline Stealer was dismantled by international authorities in October 2024, but its removal will likely lead to an expansion of similar threats. In the ransomware landscape, the removal of leader LockBit created a void that was quickly filled by other players. RansomHub, a ransomware-as-a-service (RaaS), has amassed hundreds of victims before the end of 2024, establishing itself as the new industry leader. APT groups linked to China, North Korea and Iran are increasingly involved in ransomware attacks.
Cryptocurrencies have reached record values in the second half of 2024, and crypto wallet data has been among the main targets of malicious actors. ESET has observed a significant increase in cryptostealer detections across multiple platforms, with a particularly sharp increase on macOS, where malware known as Password-Stealing Ware, designed to target cryptocurrency wallet credentials, has more than doubled compared to the first half of the year. AMOS (also known as Atomic Stealer), malware designed to collect and export sensitive data from Mac devices, contributed significantly to this increase. Financial threats on Android, targeting both banking apps and cryptocurrency wallets, saw a 20% increase.






