ESET Threat Report H2 2025

Η ESET published the news Threat Report for the second half of 2025, which presents key trends in the global cyber threat landscape. The report is based on the company's telemetry data, as well as the analysis and observations of its experts. ESET, and covers the period from June to November 2025.

According to the new report, in the second half of 2025 , ESET detected PromptLock , the first known ransomware based on artificial intelligence and capable of creating malicious scripts in real time.

See more articles from iGuRu.gr when you search for news on Google.

Why this matters: Because until now, AI has been used primarily to create more convincing phishing and online fraud attacks. However, PromptLock, along with a few other AI-powered threats that have already been identified, marks the beginning of a new era in cyberthreats, where cyberattacks can become faster, smarter, and harder to stop.

“Scammers running investment scams like Nomani have significantly improved their techniques. We have seen higher quality deepfakes , AI-generated phishing website signals , and increasingly short-lived advertising campaigns aimed at avoiding detection,” said Jiří Kropáč , Director of ESET Threat Prevention Labs.

According to ESET telemetry , Nomani scam incidents increased by 62% year-on-year, although a slight decline was observed in the second half of 2025. These scams have recently expanded beyond the Meta ecosystem , reaching other platforms, such as YouTube.

As for ransomware , the number of victims surpassed the total of 2024 well before the end of the year. ESET Research Center forecasts a 40% year-on-year increase. The Akira and Qilin groups now dominate the ransomware-as-a-service market, while new entrant Warlock, although low-profile, introduced innovative detection evasion techniques. At the same time, so-called EDR killers continued to proliferate, highlighting that endpoint detection and response (EDR) tools remain a key obstacle for ransomware operators.

On mobile phones, risks from the use of technology that enables wireless payments and data exchange near-field communication ( NFC ) continued to grow in both scale and complexity. ESET telemetry recorded an 87% increase, with several significant upgrades and new campaigns emerging in the second half of 2025.

NGate – one of the first NFC threats detected by ESET – has been upgraded to include contact-stealing capabilities, potentially laying the groundwork for future, more targeted attacks. Meanwhile, RatOn, a completely new malware in the NFC fraud space, demonstrated a rare fusion of remote access trojan (RAT) capabilities and NFC relay attacks, highlighting cybercriminals’ determination to seek new attack methods.

RatOn was distributed through fake Google Play pages and ads that mimicked an adult version of TikTok, as well as a digital banking ID service.

Additionally, PhantomCard, a new NGate-based malware tailored for the Brazilian market, was detected in multiple campaigns in the country during the second half of 2025.

After its global outage in May, the Lumma Stealer ransomware managed to temporarily resurface – twice – but its heyday appears to be over. Detections fell by 86% in the second half of 2025 compared to the first, while a key distribution vector, the HTML/FakeCaptcha trojan used in ClickFix attacks, has all but disappeared from ESET telemetry.

In contrast, CloudEyE, also known as GuLoader, saw an impressive rise, with a nearly thirtyfold increase according to ESET data. The malware-as-a-service downloader and cryptor is distributed via malicious email campaigns and is used to deploy additional malware, including ransomware and well-known infostealers such as Rescoms, Formbook, and Agent Tesla. Poland was most affected by this threat, as 32% of CloudEyE attack attempts recorded in the second half of 2025 were detected in the country.

For more information, you can read the ESET Threat Report for the second half of 2025 on WeLiveSecurity.com


Google preferences

Leave a Comment

Your email address will not be published. Required fields are marked *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).