Back Hp HP Research: Cybercriminals Leaning into Agentic AI Momentum to Steal Crypto Wallets
Latest HP Wolf Security research reveals attackers are leveraging Agentic AI momentum to trick users into compromising their browsers.
News highlights from HP’s latest Threat Insights Report: Attackers are drawing on interest in Agentic AI by creating fake AI trading agents to dupe crypto users into downloading malware that replaces trusted crypto browser extensions with malicious versions Trend in QR code phishing continues, as attackers lure users onto less defended mobile devices The appearance of Phantom Gate alongside Phantom Stealer suggests threat actors are developing increasingly specialized malware components to streamline and scale attacks PALO ALTO, Calif., 17 September 2026 – HP Inc. (NYSE: HPQ) today released its latest Threat Insights Report , providing analysis of real-world cyberattacks, helping organizations keep up with the latest techniques cybercriminals are using to evade detection and breach PCs in the fast-changing cybercrime landscape. Based on millions of endpoints running HP Wolf Security*, notable campaigns identified by HP Wolf Security threat researchers include: Fake AI Trading Agents Lure Crypto Users into Malware Trap: Cybercriminals are capitalizing on interest in Agentic AI by advertising fake AI trading agents to trick users into infecting themselves with malware. Once downloaded, victims’ browsers are scanned for crypto wallet extensions like Coinbase and MetaMask, replacing them with malicious lookalikes that harvest any credentials entered. Once harvested, attackers have easy access to steal crypto holdings. QR Phishing Remains a Common Credential Theft Route : Attackers are using QR codes to move victims from PCs to less-protected mobile devices. Victims receive PDFs with content supposedly “blurred for security”. They are then prompted to scan a QR code with their phone which redirects to phishing sites that may otherwise be blocked on their PCs, putting login credentials at risk. Phantom Stealer Ecosystem Expands: Researchers identified Phantom Gate, a new malware loader, that appears to extend the Phantom Stealer campaign. Combining Phantom Stealer malware, which is openly marketed as legitimate penetration-testing software, with the Phantom Gate loader mechanism, makes it easier for threat actors to build and scale attack campaigns. Patrick Schläpfer, Principal Threat Researcher, HP Security Lab, : “Attackers are tapping into Agentic AI tool adoption to invest in new lures that trick users into downloading malicious software that looks legitimate. This tactic makes malware delivery more polished and harder to detect. New attack tools such as Phantom Gate reflect the expanding threat landscape. They enable threat actors to easily compose dangerous infection chains, which greatly increases the risk of compromise for organizations.” By isolating threats that have evaded detection tools on PCs – but still allowing malware to detonate safely inside secure containers – HP Wolf Security has insight into the latest techniques used by cybercriminals. To date, HP Wolf Security customers have clicked on 60 billion email attachments, web pages and downloaded files with no reported breaches. The report, which examines data from April-June 2026, details how cybercriminals continue to diversify attack methods to bypass security tools, revealing that: At least 10% of email threats identified by HP Sure Click bypassed one or more email gateway scanners. Executable files were the most popular malware delivery type (40%), followed by archive files (38%) and PDF documents (7.5%). James Wright, HP’s Global Head of Security for Personal Systems : “Users move constantly between devices and applications, like browsers or new AI tools – and attackers are quick to follow. Security needs to work across all of those interactions, without getting in people’s way. That means organizations need a zero-trust approach built around isolation and containment, so untrusted clicks and downloads don’t become a risk.” Please visit the HP Threat Research blog to view the report. FAQs
News highlights from HP’s latest Threat Insights Report:
News highlights from HP’s latest Threat Insights Report:
Attackers are drawing on interest in Agentic AI by creating fake AI trading agents to dupe crypto users into downloading malware that replaces trusted crypto browser extensions with malicious versions
Trend in QR code phishing continues, as attackers lure users onto less defended mobile devices
The appearance of Phantom Gate alongside Phantom Stealer suggests threat actors are developing increasingly specialized malware components to streamline and scale attacks
Fake AI Trading Agents Lure Crypto Users into Malware Trap: Cybercriminals are capitalizing on interest in Agentic AI by advertising fake AI trading agents to trick users into infecting themselves with malware. Once downloaded, victims’ browsers are scanned for crypto wallet extensions like Coinbase and MetaMask, replacing them with malicious lookalikes that harvest any credentials entered. Once harvested, attackers have easy access to steal crypto holdings.
QR Phishing Remains a Common Credential Theft Route : Attackers are using QR codes to move victims from PCs to less-protected mobile devices. Victims receive PDFs with content supposedly “blurred for security”. They are then prompted to scan a QR code with their phone which redirects to phishing sites that may otherwise be blocked on their PCs, putting login credentials at risk.
Phantom Stealer Ecosystem Expands: Researchers identified Phantom Gate, a new malware loader, that appears to extend the Phantom Stealer campaign. Combining Phantom Stealer malware, which is openly marketed as legitimate penetration-testing software, with the Phantom Gate loader mechanism, makes it easier for threat actors to build and scale attack campaigns.
At least 10% of email threats identified by HP Sure Click bypassed one or more email gateway scanners.
Executable files were the most popular malware delivery type (40%), followed by archive files (38%) and PDF documents (7.5%).
The report shows attackers exploiting interest in Agentic AI tools to lure victims, using QR codes to shift credential theft onto less-protected mobile devices, and continuing to invest in specialized malware capability modules like the Phantom Gate loader to expand existing malware campaigns.
The report shows attackers exploiting interest in Agentic AI tools to lure victims, using QR codes to shift credential theft onto less-protected mobile devices, and continuing to invest in specialized malware capability modules like the Phantom Gate loader to expand existing malware campaigns.
In this report, we find that attackers are advertising fake AI trading agents to cryptocurrency users. When installed, the malware scans browsers for crypto wallet extensions such as Coinbase and MetaMask, replaces them with malicious lookalikes, and harvests credentials entered by victims.
In this report, we find that attackers are advertising fake AI trading agents to cryptocurrency users. When installed, the malware scans browsers for crypto wallet extensions such as Coinbase and MetaMask, replaces them with malicious lookalikes, and harvests credentials entered by victims.
QR phishing moves users from PCs to mobile devices that may have weaker protections. HP researchers observed malicious PDFs claiming content was “blurred for security” and prompting users to scan QR codes for authenticated access, redirecting them to phishing sites to steal login credentials.
QR phishing moves users from PCs to mobile devices that may have weaker protections. HP researchers observed malicious PDFs claiming content was “blurred for security” and prompting users to scan QR codes for authenticated access, redirecting them to phishing sites to steal login credentials.
Phantom Gate is a new malware loader that shows how threat actors are investing in specialized modular components to make attack campaigns, like Phantom Stealer, easier to build and scale. Phantom Stealer is sold to attackers as “legitimate” penetration-testing software, showing how cybercrime-as-a-service blurs the line between legitimate tools and malware.
Phantom Gate is a new malware loader that shows how threat actors are investing in specialized modular components to make attack campaigns, like Phantom Stealer, easier to build and scale. Phantom Stealer is sold to attackers as “legitimate” penetration-testing software, showing how cybercrime-as-a-service blurs the line between legitimate tools and malware.
The report shows how Agentic AI momentum expands opportunities for attackers to trick users into downloading malicious software. We also see continued threat actor investment in developing tools to scale phishing and malware deployment. This tells us that organizations should assume malicious links, files and downloads may evade traditional detection. It highlights the importance of integrating isolation and containment into a zero-trust approach to prevent untrusted clicks and downloads from becoming endpoint compromises.
The report shows how Agentic AI momentum expands opportunities for attackers to trick users into downloading malicious software. We also see continued threat actor investment in developing tools to scale phishing and malware deployment. This tells us that organizations should assume malicious links, files and downloads may evade traditional detection. It highlights the importance of integrating isolation and containment into a zero-trust approach to prevent untrusted clicks and downloads from becoming endpoint compromises.
the Data This data was gathered from consenting HP Wolf Security customers from April-June 2026, with investigations conducted by the HP Threat Research Team. HP Wolf Security* Built on more than 25 years of security research and innovation from the HP Security Lab, HP Wolf Security provides comprehensive endpoint protection and resilience across the stack, starting at the hardware level and extending across software and services. To date, HP Sure Start has protected more than 200 million endpoints 1 against compromised firmware. HP Sure Click has isolated more than 60 billion 2 risky user activities across documents and web pages, with zero reported breaches resulting from those isolated activities. With the most secure hardware at its core, future-ready security for continuous up time, and visibility, control, and resilience at scale, HP Security is built for the future of work.
HP Wolf Security*
© HP Development Company, L.P. The information contained herein is subject to change without notice. The only warranties for HP products and services are set forth in the express warranty statements accompanying such products and services. Nothing herein should be construed as constituting an additional warranty. HP shall not be liable for technical or editorial errors or omissions contained herein. *HP Wolf Security for Business requires Windows 10 or 11 Pro and higher, includes various HP security features and is available on HP Pro, Elite, RPOS, Thin Client and Workstation products. See product details for included security features. Based on HP’s internal analysis: Over 200 million PCs shipped with HP Sure Start and no reported malware breaches. Assumptions based on HP internal analysis of customer reported insights and installed base.
© HP Development Company, L.P. The information contained herein is subject to change without notice. The only warranties for HP products and services are set forth in the express warranty statements accompanying such products and services. Nothing herein should be construed as constituting an additional warranty. HP shall not be liable for technical or editorial errors or omissions contained herein.
*HP Wolf Security for Business requires Windows 10 or 11 Pro and higher, includes various HP security features and is available on HP Pro, Elite, RPOS, Thin Client and Workstation products. See product details for included security features.
Based on HP’s internal analysis: Over 200 million PCs shipped with HP Sure Start and no reported malware breaches.
Assumptions based on HP internal analysis of customer reported insights and installed base.
HP Inc. (NYSE:HPQ) is a global technology leader redefining the Future of Work. Operating in more than 180 countries, HP delivers innovative and AI-powered devices, software, services and subscriptions that drive business growth and professional fulfillment. For more information, please visit: HP.com . : [email protected]
المملكة العربية السعودية
Sustainability Progress
HP Printables
Public sector purchasing
Support & troubleshooting
Authorized service providers
HP Amplify Partner Program
Limited warranty statement
Terms & conditions of sales & service
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
