
HP Wolf Security Threat Insights Report: September 2026
Welcome to the September 2026 edition of the HP Wolf Security Threat Insights Report. In the report, we review notable malware campaigns, trends and techniques identified from HP Wolf Security’s customer telemetry in calendar Q2 2026.
Key Findings
-
- Attackers built a website posing as an AI-powered crypto trading assistant, borrowing the name of a well-known AI tool to seem trustworthy, and used it to spread Needle Stealer. Victims looking for a bot to grow their portfolio instead downloaded malware that used a legitimate Microsoft-signed program to sneak in a malicious file (T1574.001), then quietly swapped their browser’s cryptocurrency wallet for a fake one. Once they typed in their wallet password, the attackers had everything they needed to empty it.
- HP Sure Click detected phishing campaigns that hid a QR code inside a PDF invoice, coaxing victims to scan it with their phone, a technique known as quishing (T1598.003). The clever part was the switch of device. By moving the victim onto a smartphone, this sidesteps the protections guarding a work PC, so a scam link already blocked on a computer can open freely on a phone. At the end of the trail was a convincing fake login page built to capture Microsoft passwords.
- HP Sure Click isolated campaigns spreading Phantom Stealer, malware marketed online as a “penetration testing tool,” complete with feature updates and 24/7 buyer support. It arrived by email, where a PowerShell script (T1059.001) pulled the malware out of an image and a helper component named Phantom Gate unpacked and launched it into a legitimate process (T1055). The shared naming and delivery method suggest Phantom Gate and Phantom Stealer may come from the same source, another sign of a growing underground market where attackers mix and match ready-made parts to build campaigns faster.
Read the Report
Download the report: HP Wolf Security Threat Insights Report: September 2026
You can download and read our previous Threat Insights Reports here.




