
HP Wolf Security Threat Insights Report: March 2025
Welcome to the March 2025 edition of the HP Wolf Security Threat Insights Report. In the report, we review notable malware campaigns, trends and techniques identified from HP Wolf Security’s customer telemetry in calendar Q4 2024.
Key Findings
- In Q4 2024, the HP Threat Research team has been seeing a growth in social engineering campaigns that rely on fake CAPTCHA challenges to infect users with malware. Potential victims are directed to websites controlled by attackers and prompted to complete a series of verification steps. If followed, these steps involve the user running malicious PowerShell commands on their PC using the Windows Run prompt, ultimately infecting their computer with malware, such as Lumma Stealer.
- In another notable campaign, HP Sure Click caught attackers delivering malicious code inside Scalable Vector Graphic (SVG) images to evade detection (T1027.009). These images, which are opened by default in web browsers, ultimately deployed seven remote access trojans (RATs) and information stealers, offering redundancy and monetization opportunities for threat actors. Interestingly, part of the infection chain relied on obfuscated Python scripts to deliver the malware (T1059.006). Python’s popularity – which is being further boosted by rising interest in AI and data science – means it is an increasingly attractive language for attackers to write malware, as its interpreter is widely installed.
- Malicious PDF documents were the third most popular threat file type encountered by HP Sure Click in Q4 2024. HP Sure Click identified a malware campaign delivering VIP Keylogger targeting engineering companies in the Asia Pacific region. The attackers emailed malicious PDF files posing as quotation requests and tailored their messages to potential victims based on the products they sold, such as automobile and industrial parts.
Read the Report
Download the report: HP Wolf Security Threat Insights Report: March 2025
You can download and read our previous Threat Insights Reports here.




