The HP Threat Insights report reveals how attackers are using legitimate software, cloaked malware, and increasingly convincing lures to gain access to users’ devices. The research highlights a growing challenge for both users and security teams, as malicious activity becomes harder to distinguish from legitimate behavior.
Malicious Campaigns
The report analyzes real cyberattacks to help organizations keep up with the latest techniques criminals are using to evade detection and compromise devices in a threat landscape that is constantly evolving. Drawing on the millions of devices protected by HP Wolf Security, researchers identified, among others, the following campaigns:
- Backdoors through legitimate remote-access tools: Cybercriminals are abusing applications such as LogMeIn and ScreenConnect to take control of victims’ devices without raising suspicion. Campaigns were launched via phishing emails related to the end of the fiscal year and fake downloads of desktop applications, including fraudulent dating sites, to persuade users to install legitimate remote-access tools. Once installed, these tools were controlled by the attackers, allowing them to blend into routine IT activity and gain full control over the devices.
- Attackers exploiting users attempting to recover lost cryptocurrency wallets: Attackers are distributing fake wallet-recovery tools that claim to help locate lost funds, but their real aim is to steal them. These malicious programs, commonly shared via code-exchange platforms and content download sites, contain information-stealing scripts packed with emojis that appear to have been developed using “vibe coding” techniques. They are capable of collecting credentials, wallet data, and system information before packaging them into compressed files for exfiltration.
- ClickFix campaigns hide malware in audio files: Operators behind recent ClickFix campaigns are camouflaging malware in audio files to avoid detection. Victims are directed to carefully crafted fake websites that display seemingly legitimate CAPTCHA messages. Interacting with them executes malicious commands that quietly trigger malicious payloads concealed in the background.
Patrick Schläpfer, senior threat researcher at HP Security Lab, notes: “What stands out most about these campaigns is how easily legitimate remote-access tools can become entry points for attackers. By pairing trusted software with carefully designed social engineering — tied to events like the fiscal year-end — it becomes increasingly difficult to distinguish what is reliable from what isn’t.”
By isolating threats that have evaded detection tools on personal computers — while at the same time allowing malware to run safely inside protected containers — HP Wolf Security gains insight into the latest techniques used by cybercriminals. To date, HP Wolf Security customers have clicked on more than 60 billion email attachments, websites, and downloaded files without any reported security breaches.
The report, based on data collected between January and March 2026, shows how cybercriminals continue to diversify their attack methods to evade security tools:
- At least 11% of email threats identified by HP Sure Click managed to evade one or more email gateway scanners.
- Executable files were the most popular method for distributing malware (39%), followed by compressed files (38%) and PDF documents (10%).
- Malware distributed via PDF documents rose by 2%, using a variety of lures, such as legal documents or bonus payment notices, to create a sense of urgency and prompt user interaction.
Alex Holland, principal threat researcher at HP Security Lab, comments: “These attacks don’t resemble a traditional intrusion; they look like ordinary business activity. They blend into normal IT operations and bypass many of the alert signals tied to malware. To safeguard the future of work and reduce risk, organizations should limit unnecessary privileges, control software installation, and isolate risky activities like downloads and unknown links. Detection alone is no longer enough when legitimate tools can become backdoors.”