×
ItalianoEnglish
Set as default language

Grandangolo Communications

  • Home
  • Company
  • Services
    • Public Relation
    • Digital PR
    • Marketing
    • Lead Generation
    • Events
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages
  • Home
  • Customer Press Room
  • Eset
  • ESET Threat Report: AI-driven attacks on the rise; NFC threats are growing and evolving in sophistication

Customer Press Room

ESET Threat Report: AI-driven attacks on the rise; NFC threats are growing and evolving in sophistication

by Grandangolo Communications / Thursday, 08 January 2026 / Published in Eset

The Report is based on data collected between June and November 2025 and signals an evolution in the techniques used in scams, with a growing use of deepfakes and AI-generated content. However, some known threats saw a sharp decline in detections in the second half of the year

ESET, a global leader in the cybersecurity market, has published the latest edition of the Threat Report, which summarizes the threat trends observed in ESET telemetry and analyzed by threat detection and research experts in the period between June and November 2025. In the second half of the year, AI-based malware moved from theory to reality: ESET discovered PromptLock, the first known AI-driven ransomware, capable of dynamically generating malicious scripts. While AI is still primarily used to create more convincing phishing and scam content, PromptLock – along with a few other AI-driven threats identified so far – signals the beginning of a new era of threats.

“Nomani investment scams have shown a significant evolution in the techniques used: higher quality deepfakes, AI-generated phishing site signals, and increasingly shorter advertising campaigns designed to reduce the chances of detection were observed,” says Jiří Kropáč, Director of ESET Threat Prevention Labs. In ESET telemetry, Nomani scam detections grew 62% year-on-year, with the trend declining slightly in the second half of 2025. Nomani scams are also expanding from Meta to other platforms, including YouTube.

As for ransomware, the number of victims exceeded 2024 levels well before the end of the year, with projections from ESET Research indicating a 40% increase year-on-year. Akira and Qilin now dominate the ransomware-as-a-service market, while newcomer Warlock, while low-profile, has introduced innovative evasion techniques. The spread of EDR killers has continued, demonstrating that endpoint detection and response tools continue to represent a significant obstacle for ransomware operators.

On the mobile platform, threats based on Near Field Communication (NFC) technology have continued to grow in scale and sophistication, with an 87% increase in ESET telemetry and several relevant updates and campaigns observed in the second half of 2025. NGate, a pioneer among NFC threats and first discovered by ESET, has received an update in the form of contact theft, likely setting the stage for future attacks. RatOn, a completely new malware in the NFC fraud landscape, introduced a rare combination of capabilities from remote access trojan (RAT) and NFC relay attacks, demonstrating the determination of cybercriminals to explore new attack vectors. RatOn was distributed via fake Google Play pages and ads that mimicked an adult version of TikTok and a banking digital identity service. PhantomCard, a new malware based on NGate and adapted to the Brazilian market, was observed in multiple campaigns in Brazil in the second half of 2025.

Additionally, after the global outage in May, infostealer Lumma Stealer managed to briefly resurface – twice – but its heyday appears to be over. Detections plummeted 86% in the second half of 2025 compared to the first half of the year, and a major distribution vector for Lumma Stealer – the HTML/FakeCaptcha Trojan used in the ClickFix attacks – has all but disappeared from ESET telemetry.

Meanwhile, CloudEyE, also known as GuLoader, has quickly risen to prominence, with a nearly thirty-fold increase according to ESET telemetry. Distributed via malicious email campaigns, this malware-as-a-service downloader and cryptor is used to distribute other malware, including ransomware and infostealers such as Rescoms, Formbook, and Agent Tesla. Poland was the most affected country, with 32% of CloudEyE attack attempts detected in the second half of 2025.

Tagged under: Eset

About Grandangolo Communications

What you can read next

ESET discovers NGate: Android malware that uses the NFC module to clone victims' credit and debit cards
ESET included among the Top Players in the Radicati 2020 Market Quadrant for the APT market segment
ESET participates in a global operation to dismantle Lumma Stealer, one of the most widespread infostealers

Customer Press Room

  • ESET releases SMB IT Readiness Index 2026, highlighting growing confidence but also concerns about AI technologies

    The majority of SMEs declare themselves optimistic...
  • ESET discovers the new arsenal of Webworm, a pro-Chinese APT active against European governments

    ESET Research analyzed recent activity…
  • Arrow Electronics expands distribution agreement with Veeam in EMEA

    Arrow Electronics, a global supplier of technology...
  • ESET Research APT Report: China-aligned groups spy on Venezuela and Gulf, targeting AI robotics in South Korea

    L’ultimo APT Activity Report di ESET Research t...
  • ESET accelerates AI innovation with investments aimed at managing a rapidly expanding attack surface

    ESET announces a 40 million investment ...

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018

Categories

  • A10
  • abstract
  • Abstract
  • Acronis
  • Ally Consulting
  • Arrow
  • Arrow Electronics
  • Axiante
  • Babel
  • Computer Center
  • Cohesity
  • Italy Cloud Consortium
  • Consys
  • D-Link
  • Eset
  • G.B. Service
  • Habble
  • HiSolution
  • HYCU
  • Icos
  • Information Tecnology
  • Innovaway
  • Ivanti
  • Link11
  • MobileIron
  • Netalia
  • Nethive
  • Nexthink
  • Nuvis
  • Praim
  • QAD
  • Qualys
  • Red Hot Cyber
  • Riverbed
  • Saviynt
  • Sensormatic
  • SentinelOne
  • Talent Software
  • Vectra
  • Vectra AI
  • Vertiv

Office printing, digital PR, marketing, lead generation: all projects are born from our passion and expertise, with an inevitable touch of creativity and innovation.

COMPANY

Grandangolo Communications Srl
Via Sardegna 19
20146 Milano
Telephone +39 335 8283393
info@grandangolo.it

I SERVIZI

  • Home
  • Company
  • Services
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages

CONTACTS

  • Contacts
  • Cookie policy
  • Privacy policy

© 2019 GRANDANGOLO COMMUNICATIONS SRL | P.IVA IT 06394850967 | All rights reserveD.

Powered by Webpowerplus

TOP