
A view of the H1 2025 menace panorama as seen by ESET telemetry and from the attitude of ESET menace detection and analysis consultants
26 Jun 2025
•
,
2 min. learn

From novel social engineering strategies to classy cell threats and main infostealer disruptions, the menace panorama within the first half of 2025 was something however boring.
Probably the most putting developments this era was the emergence of ClickFix, a brand new, misleading assault vector that skyrocketed by over 500% in comparison with H2 2024 in ESET telemetry. Now the second most typical assault vector after phishing, ClickFix manipulates web customers into executing malicious instructions underneath the guise of fixing a faux error. The payloads on the finish of ClickFix assaults differ extensively – from infostealers to ransomware and even to nation-state malware – making this a flexible and formidable menace throughout Home windows, Linux, and macOS.
The infostealer panorama additionally noticed vital shifts. With Agent Tesla fading into obsolescence, SnakeStealer (also called Snake Keylogger) surged forward, changing into probably the most detected infostealer in our telemetry. In the meantime, ESET contributed to main disruption operations focusing on Lumma Stealer and Danabot, two prolific malware-as-a-service threats.
On the Android entrance, adware detections soared by 160%, pushed largely by a classy new menace dubbed Kaleidoscope. This malware makes use of a misleading “evil twin” technique to distribute malicious apps that bombard customers with intrusive adverts, degrading system efficiency. On the identical time, NFC-based fraud shot up greater than thirty-five-fold, fueled by phishing campaigns and creative relay strategies. Whereas the general numbers stay modest, this leap highlights the fast evolution of the criminals’ strategies and their continued concentrate on exploiting NFC know-how. Every new iteration of NFC threats – from NGate to GhostTap, and most just lately SuperCard – demonstrates how attackers adapt to new safety measures.
The ransomware scene descended (even additional) into chaos, with fights between rival ransomware gangs impacting a number of gamers together with the highest ransomware as a service – RansomHub. Yearly information from 2024 exhibits that whereas ransomware assaults and the variety of lively gangs have grown, ransom funds noticed a big drop. This discrepancy could also be the results of takedowns and exit scams that reshuffled the ransomware scene in 2024, but in addition partially attributable to diminished confidence within the gangs’ skill to maintain their facet of the discount.
Comply with ESET analysis on X, Bluesky and Mastodon for normal updates on key traits and high threats.
To study extra about how menace intelligence can improve the cybersecurity posture of your group, go to the ESET Menace Intelligence web page.