HP Threat Research Blog HP Wolf Security Threat Insights Report: June 2026

June 11, 2026 Category: Threat Insights Reports By: HP Wolf Security Comments: 0

HP Wolf Security Threat Insights Report: June 2026

Welcome to the June 2026 edition of the HP Wolf Security Threat Insights Report. In the report, we review notable malware campaigns, trends and techniques identified from HP Wolf Security’s customer telemetry in calendar Q1 2026.

Key Findings

  • In Q1 2026, HP Threat Research found cybercriminal campaigns abusing LogMeIn and ScreenConnect, two legitimate remote access tools commonly used for IT support. The use of remote access tools is not new, but these campaigns stood out because of the specific tools attackers chose. The campaigns relied on tax year-end phishing emails and fake desktop app downloads to install the tools without the user’s knowledge, giving attackers full control of victim devices while helping them avoid suspicion.
  • Attackers behind ClickFix malware campaigns disguised malware as audio files to evade detection. Victims are guided through realistic CAPTCHA prompts on well-designed fake websites, triggering malicious commands that execute malware payloads in the background. The campaigns, which were stopped by HP Wolf Security, would have delivered Amatera Stealer. The malware steals credentials, browser cookies, and cryptocurrency wallet data. We also observed follow-on payloads, including adware and NetSupport, giving attackers remote control of infected endpoints.
  • This quarter saw attackers spread fake cryptocurrency wallet recovery tools that claimed to help users locate lost wallets but instead stole them. Shared via code-sharing platforms and media download sites, the emoji-filled infostealer scripts were likely vibe-coded. The scripts harvest credentials, wallet and system data, which are then packaged into archive files for exfiltration.
  • Attackers continued to weaponize common document workflows in Q1, with HP Wolf Security stopping a PDF-based GuLoader campaign that used CAPTCHAs to evade detection, Excel macro Loda RAT attacks aimed at Spanish-language speakers, and Global Group ransomware delivered via a Windows shortcut disguised as a Word document.

Read the Report

Download the report: HP Wolf Security Threat Insights Report: June 2026

Download (PDF)

You can download and read our previous Threat Insights Reports here.

About the Author

HP Wolf Security

Recent Posts

2026-06-11T08:35:59+01:00June 11th, 2026|Threat Insights Reports|