Infostealer and Android threats on the rise, ESET helps dismantle two malware-as-a-service. Ransomware is less profitable, due to internal instabilities and a decline in credibility. Strong growth in NFC fraud, driven by new tools for digital theft
ESET, the global European leader in the cybersecurity market, has published the new Threat Report, which summarizes the main trends that emerged from ESET telemetry data and analyzes conducted by the company's researchers, in the period between December 2024 and May 2025. Among the most significant developments of the semester is ClickFix, a new and deceptive attack vector which recorded a surge of more than 500% compared to the second half of 2024. ClickFix is now the second vector most detected attack after phishing, and is responsible for nearly 8% of all blocked attacks in the first half of 2025.
ClickFix attacks use a fake error message that tricks the victim into copying, pasting, and executing malicious commands on their device. This type of attack affects all major operating systems, including Windows, Linux, and macOS.
“The list of threats associated with ClickFix grows every day: infostealers, ransomware, remote access Trojans, cryptominers, post-exploitation tools and even custom malware developed by groups linked to nation-states,” says Jiří Kropáč, Director of Threat Prevention Labs at ESET.
The infostealer sector has also undergone significant changes. With the progressive decline of Agent Tesla, SnakeStealer (also known as Snake Keylogger) has taken hold and has become the most frequently detected information theft malware by ESET. SnakeStealer can record keystrokes, steal saved credentials, capture screenshots, and scrape data copied to the clipboard.
In parallel, ESET participated in major international law enforcement operations against two extremely active malware-as-a-service threats: Lumma Stealer and Danabot. Before the dismantling, Lumma Stealer's business had grown by 21% compared to the previous six months, while Danabot had recorded an even more marked increase of 52%. Data that confirms the urgency and effectiveness of counteractions.
The ransomware landscape has seen increasing instability, with internal conflicts between rival groups affecting several operators, including the leading ransomware-as-a-service, RansomHub. According to 2024 data, while the overall number of attacks and active groups has increased, ransom payments are declining. A signal that could reflect on the one hand the success of the dismantling operations, on the other the negative impact of internal scams (exit scams) and the consequent loss of confidence in the possibility of obtaining data restoration by the victims.
On the Android front, adware detections increased by 160%, largely due to Kaleidoscope, a sophisticated new malware that adopts an evil twin strategy to spread malicious apps. Once installed, these apps flood devices with intrusive advertisements, compromising performance.
Over the same period, NFC-based fraud has grown more than 35-fold, driven by phishing campaigns and increasingly ingenious relay attack techniques. While absolute volumes are still small, the exponential growth highlights how rapidly NFC-based attack modes are evolving.
ESET's analysis of the GhostTap malware reveals how this tool is used to steal payment card data, which is then uploaded to digital wallets controlled by attackers, enabling fraudulent contactless payments around the world. In some cases, real "fraud factories" manage numerous phones in parallel to scale the attack.
SuperCard
“From new social engineering techniques to increasingly complex mobile threats, through operations to combat the main infostealers, the first half of 2025 has demonstrated how the threat landscape is constantly evolving,” concludes Kropáč regarding the contents of the latest ESET Threat Report.
For more information, you can consult l’ESET Threat Report H1 2025 on WeLiveSecurity.com. To stay updated on the latest news you can follow ESET Research on X (formerly known as Twitter), BlueSky e Mastodon.






