A view of the H2 2025 risk panorama as seen by ESET telemetry and from the angle of ESET risk detection and analysis specialists
16 Dec 2025
•
,
2 min. learn

The second half of the yr underscored simply how rapidly attackers adapt and innovate, with fast adjustments sweeping throughout the risk panorama.
AI-powered malware moved from principle to actuality in H2 2025, as ESET found PromptLock, the primary identified AI-driven ransomware, able to producing malicious scripts on the fly. Whereas AI remains to be primarily used for crafting convincing phishing and rip-off content material, PromptLock – and the handful of different AI-driven threats recognized to this present day – sign a brand new period of threats.
After its world disruption in Might, Lumma Stealer managed to briefly resurface – twice – however its glory days are most certainly over. Detections plummeted by 86% in H2 2025 in comparison with the primary half of the yr, and a big distribution vector of Lumma Stealer – HTML/FakeCaptcha trojan, utilized in ClickFix assaults – almost vanished from our telemetry.
In the meantime, CloudEyE, often known as GuLoader, surged into prominence, skyrocketing nearly thirtyfold in ESET telemetry. Distributed through malicious electronic mail campaigns, this malware-as-a-service downloader and cryptor is used to deploy different malware, together with ransomware, in addition to infostealer juggernauts similar to Rescoms, Formbook, and Agent Tesla.
On the ransomware scene, sufferer numbers surpassed 2024 totals properly earlier than yr’s finish, with ESET Analysis projections pointing to a 40% year-over-year enhance. Akira and Qilin now dominate the ransomware-as-a-service market, whereas low-profile newcomer Warlock launched progressive evasion methods. EDR killers continued to proliferate, highlighting that endpoint detection and response instruments stay a big impediment for ransomware operators. H2 2025 additionally introduced an disagreeable flashback to the Petya/NotPetya ransomware, when ESET researchers uncovered HybridPetya – a brand new derivate of the notorious malware able to compromising fashionable UEFI-based techniques.
On the Android platform, NFC threats continued to develop in scale and class, with an 87% enhance in ESET telemetry and several other notable upgrades and campaigns noticed in H2 2025. NGate – a pioneer amongst NFC threats, first described by ESET in 2024 – acquired an improve within the type of contact stealing, doubtless laying the groundwork for future assaults. RatOn, totally new malware on the NFC fraud scene, introduced a uncommon fusion of RAT capabilities and NFC relay assaults, exhibiting cybercriminals’ dedication to pursuing new assault avenues.
Fraudsters behind the Nomani funding scams have additionally refined their methods – we have now noticed higher-quality deepfakes, indicators of AI-generated phishing websites, and more and more short-lived advert campaigns to keep away from detection. In ESET telemetry, detections of Nomani scams grew 62% year-over-year, with the development declining barely in H2 2025.
Observe ESET analysis on X, Bluesky and Mastodon for normal updates on key tendencies and prime threats.To study extra about how risk intelligence can improve the cybersecurity posture of your group, go to the ESET Menace Intelligence web page.
