ESET 's latest threat report – covering the period from December 2023 to May 2024 – offers a detailed picture of the dynamic and ever-changing cybersecurity landscape .

The report highlights significant trends and threats, such as the rise of information-stealing malware, mobile malware targeting financial data, and ongoing attacks by ransomware gangs and other cybercriminal entities.
Information-stealing malware and AI
Information -stealing malware is increasingly attacking Windows users, taking advantage of the growing interest in creative artificial intelligence tools .
Read more: Ransomware groups are using more infostealers
Specifically, the Vidar infostealer masquerades as a Windows desktop app for the AI image creator Midjourney, even though the Midjourney model is only accessible via Discord. Similarly, the Rilide Stealer exploits the names of popular AI assistants, such as OpenAI’s Sora and Google’s Gemini , to trick victims. This trend, seen since 2023, is expected to continue as cybercriminals take advantage of the boom in AI.
GoldPickaxe and mobile malware
Mobile malware has also seen significant developments. The new GoldPickaxe malware is capable of stealing facial recognition data to create deepfake videos, which are then used to authenticate fake financial transactions. This malware, with versions for both Android and iOS, has primarily targeted Southeast Asia through local malicious apps. An older variant, GoldDiggerPlus, has expanded its reach to Latin America and South Africa, indicating a broadening threat landscape.
Games and hacking tools as carriers of malware
See more: ANY.RUN Sandbox: Allows SOC and DFIR teams to analyze advanced Linux malware
Gamers involved in unofficial gaming ecosystems are at risk, as some cracked video games and multiplayer game hacking tools have been found to contain information-stealing malware, such as Lumma Stealer and RedLine Stealer. RedLine Stealer, in particular, saw several spikes in detections in the first half of 2024, with notable campaigns in Spain, Japan, and Germany. These recent surges have seen a one-third increase in detections compared to the second half of 2023.
Exploit and Ransomware
ESET's report also highlights the ongoing threat from groups like the Balada Injector gang, which exploited vulnerabilities in WordPress plugins to compromise over 20,000 websites in the first half of 2024. Their campaign resulted in over 400,000 detections in ESET's telemetry.
In the ransomware space, the once dominant LockBit group suffered a significant blow from Operation Chronos, a global law enforcement initiative conducted in February 2024. Although ESET telemetry recorded two significant LockBit in the first half of 2024, it was found that these were caused by gangs not affiliated with LockBit, but using its creation program.

Ebury Group and Server-Side Malware
ESET’s extensive report on the Ebury group has uncovered one of the most sophisticated server-side malware campaigns to date. The group used its malware and botnet to compromise nearly 400,000 Linux, FreeBSD, and OpenBSD servers, with over 100,000 remaining compromised by the end of 2023.
Read more: Hackers distribute USB malware via websites
The backdoor continues to pose a serious threat, highlighting the imperative need for strong server security.
Source: helpnetsecurity
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
