HP Threat Report Exposed New AI-Themed Malware Tactics
Researchers have identified new delivery methods using fraudulent AI trading agents to compromise crypto wallets.
Updated on Sept. 22, 2026 in Cybersecurity

Live Poll
Do you trust the security of new AI tools and apps you use on your devices?
HP Inc. released a Threat Insights Report documenting how cybercriminals are exploiting interest in Agentic AI to distribute new malware. This research, covering the second quarter of 2026, highlights the emergence of the Phantom Gate malware loader.
Why it matters
Attackers are successfully leveraging the popularity of AI trading agents to create credible lures that bypass traditional defenses. By redirecting users to mobile devices via QR codes, these threats exploit the weaker security postures often found on personal handsets.
Malware delivery relied on executable files (40%) and archives (38%) to bypass email gateways at a rate of 10%. Attackers utilized PDFs with blurred content to trigger QR code scans, shifting the attack surface from PCs to mobile devices.
The players
HP Inc.
A global technology company providing hardware, software, and services, including security-focused endpoint monitoring.
The details
The report highlights the Phantom Gate malware loader, which enables threat actors to deploy additional malicious payloads. Once on a device, the malware scans browsers to replace legitimate crypto wallet extensions like Coinbase and MetaMask with malicious lookalikes designed to harvest user credentials. Attackers also utilize Phantom Stealer, which is marketed to users as legitimate penetration-testing software.
Timeline
April through June 2026: Reporting period for the HP Threat Insights Report.
The Tech Race
This development highlights the ongoing struggle between enterprise security vendors and malware authors who increasingly disguise payloads as legitimate AI productivity tools. It follows the pattern of sophisticated credential-harvesting campaigns that target browser-based crypto assets.
Users should exercise caution when downloading software promising AI trading capabilities, as these remain primary vectors for credential theft. Regularly auditing browser extensions for unexpected changes in permissions or functionality is critical for protecting crypto assets.
The takeaway
The rise of AI-themed lures confirms that attackers are successfully exploiting the psychological pivot toward agentic software. Watch for future security updates from endpoint vendors that aim to close the 10% detection gap in email gateway scanners.
Further reading
For broader trends in enterprise defense, explore our latest Cybersecurity analysis.
Live Poll
Do you trust the security of new AI tools and apps you use on your devices?






