HP warns of AI lures & QR phishing targeting crypto
Wed, 30th Sep 2026 (Today)
HP has published new threat research on cybercriminal tactics targeting AI users, mobile devices and cryptocurrency holders, based on campaigns observed by HP Wolf Security.
One campaign involved attackers advertising fake AI trading agents to cryptocurrency users and delivering malware instead of the promised software.
According to HP, the malicious program scanned victims' browsers for crypto wallet extensions, including Coinbase and MetaMask, then replaced them with fraudulent versions designed to capture credentials. Once users entered their details into the lookalike extensions, attackers could access their crypto holdings.
The campaign reflects a broader shift in how attackers are adapting popular technology themes into more convincing lures. In this case, interest in agentic AI was used to persuade users to install software that appeared legitimate.
Another campaign highlighted in the report involved QR code phishing designed to move victims from desktop or laptop computers to smartphones. Researchers said victims received PDF files stating that content was "blurred for security" and were then prompted to scan a QR code with their phones.
That process redirected users to phishing websites, potentially bypassing protections on their PCs and putting login details at risk. The tactic highlights a long-running challenge for security teams as attackers shift activity across devices to find weaker points of defence.
Specialised tools
HP also identified Phantom Gate, a malware loader that appears linked to the Phantom Stealer campaign. Together, they suggest attackers are using increasingly specialised components to make attack chains easier to assemble and scale.
Phantom Stealer is marketed openly as legitimate penetration-testing software, according to the findings. The apparent addition of Phantom Gate points to a wider cybercrime market in which distinct tools and services are combined for different stages of an attack.
The report draws on data gathered from consenting customers between April and June and examines attacks that reached endpoints monitored by HP Wolf Security. The research is based on millions of endpoints.
HP said at least 10% of email threats identified by HP Sure Click had bypassed one or more email gateway scanners. It also said executable files were the most common malware delivery format at 40%, followed by archive files at 38% and PDF documents at 7.5%.
Those figures suggest attackers still rely on familiar file types while adapting the social engineering around them. The use of PDFs in QR phishing, for example, shows how routine-looking documents can still serve as the first step in credential theft.
Patrick Schläpfer, Principal Threat Researcher, HP Security Lab, said HP's researchers were seeing attackers rework established methods around current technology trends.
"Attackers are tapping into Agentic AI tool adoption to invest in new lures that trick users into downloading malicious software that looks legitimate. This tactic makes malware delivery more polished and harder to detect. New attack tools such as Phantom Gate reflect the expanding threat landscape. They enable threat actors to easily compose dangerous infection chains, which greatly increases the risk of compromise for organizations," said Schläpfer.
Cross-device risk
The findings also point to a challenge created by the way people move between browsers, phones and desktop applications during everyday work. Attackers can exploit that movement to push targets towards devices or software environments with fewer protections in place.
HP said QR phishing remained a common route for stealing credentials because it shifted users on to less-defended mobile devices. That approach may also reduce the chances that security controls on corporate PCs will block the malicious destination before credentials are entered.
James Wright, Global Head of Security for Personal Systems, HP, said organisations needed to adapt to that pattern of user behaviour and attack design.
"Users move constantly between devices and applications, like browsers or new AI tools - and attackers are quick to follow. Security needs to work across all of those interactions, without getting in people's way. That means organizations need a zero-trust approach built around isolation and containment, so untrusted clicks and downloads don't become a risk," said Wright.
HP also said customers using HP Sure Click had clicked on 60 billion email attachments, web pages and downloaded files with no reported breaches from those isolated activities.