Each quarter HP’s security experts highlight notable malware campaigns, trends and techniques. By isolating threats that have evaded detection and made it to endpoints, HP Wolf Security shines the light on what tactics cybercriminals are using – in turn providing security teams with information to battle the latest tactics. Here are a few examples:
In one instance, the HP Threat Research team identified attackers refining their use of living-off-the-land (LOTL) tools to evade detection. In one campaign that targeted businesses, threat actors chained together multiple LOTL tools, including lesser-known ones, to deliver XWorm malware which enable remote access and data theft.
In a second example, HP Sure Click detected attackers targeting German-speaking regions with highly realistic SVG-based (T1027.017) invoice lures to deliver malware. These emails bypassed scanners and mimicked Adobe Acrobat to trick users into downloading malicious ZIP files.
Lumma Stealer was one of the most active malware families observed in Q2. HP Wolf Security found the malware being actively distributed via phishing emails containing malicious IMG archives. Despite a law enforcement takedown in May 2025, campaigns continued in June, and its operators have been rebuilding their infrastructure.
Download the report here.
/
