International Cyber Expo International Cyber Expo
  • About Us
Tuesday, 21 July, 2026
IT Security Guru
International Cyber Expo
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Scams Now Drive Almost Half of All Malware Detections as Attackers Weaponise Everyday Trust

First half-year Threat Report from the company behind Norton, Avast and LifeLock finds breach notifications up 628%, e-shop scams up 109%, and AI agents emerging as a new front line

by Lara Joseph
July 20, 2026
in News
Scams Now Drive Almost Half of All Malware Detections as Attackers Weaponise Everyday Trust
Share on FacebookShare on Twitter

Scams accounted for almost 46% of all threat detections in the first half of 2026, making them the single largest category of malicious activity tracked by Gen Digital, the company behind Norton, Avast, LifeLock and MoneyLion, according to its newly published Threat Report H1 2026.

The report, Gen’s first half-yearly threat publication after previously reporting on a quarterly basis, argues that the defining pattern of the period was not any single new technique, but attackers consistently inserting themselves into systems and moments that users, platforms and security tools already trust, from hotel booking threads and WhatsApp device pairing to software update channels and AI agent permissions.

“The strongest pattern in the first half of 2026 was the way different threats converged around trust,” said Luis Corrons, Security Evangelist at Gen. Scams, account takeovers, malicious packages and AI agents, he said, all moved closer to the systems, workflows and permissions people already rely on, meaning attacks increasingly succeed before a victim ever reaches an obviously suspicious moment.

Tech support and imposter scams surge

Tech support scam detections reached 20.3 million blocked attacks in H1 2026, up 61.6% on the second half of 2025. Gen said part of the rise reflects newly introduced detection coverage, but also pointed to campaigns hosted on legitimate-looking cloud infrastructure, including ondigitalocean[.]app domains and fake Windows Defender error pages hosted on Google Cloud Storage in Germany and France. Windows users accounted for 92% of blocked tech support scam attacks, and the US, France, Germany, and Japan were the most targeted countries.

Government impersonation scams rose 387% to almost 1 million blocked attacks, with 81% of that activity concentrated in the United States. Family impersonation scams, often delivered by SMS to Android users and increasingly using AI voice cloning, rose 454.2% and were concentrated in the Netherlands, France, Ireland and Germany.

E-shop scams and fake online stores became one of the highest-volume categories tracked, with 114.2 million blocked attacks, up 109% half-over-half, including one variant using .click domains that alone accounted for more than 10 million blocks. “Fake tutorial” or “scam-yourself” attacks, which trick users into manually running malicious commands via fake CAPTCHA or verification prompts, rose 193% to 5.26 million blocked attempts.

Malvertising was also a major driver of activity, representing almost 30% of detections. Gen’s separate Scam Ad Machine research, examining 14.57 million ads across the EU and UK, found that nearly one in three were scam-related, generating more than 304 million impressions in under a month.

Localised banking trojans, infostealers and crypto-clippers

Regional malware campaigns leaned heavily on local-language lures. Banking trojan operators in Czechia, Slovakia and Poland used JavaScript droppers disguised as shipping notices and invoices, in some cases sent from already-compromised corporate mailboxes. RAT campaigns in Italy, Poland and Czechia used fake invoices, steganographic loaders and multi-stage PowerShell to deploy Remcos and Babylon RAT, among others.

Gen Threat Labs also identified Remus, a new 64-bit infostealer it attributes to the Lumma Stealer family, based on shared obfuscation, string-handling, and browser credential theft techniques, including a bypass of Chrome’s Application-Bound Encryption. Separately, researchers tracked a four-stage cryptocurrency infection chain ending in a Rust-based clipboard hijacker that monitors for wallet addresses across 21 blockchain types and silently swaps in attacker-controlled addresses. The same campaign used Binance Smart Chain to resolve command-and-control infrastructure via EtherHiding, making its infrastructure harder to take down than a conventional domain.

Software supply chain and a cracked-macOS-app wave

Gen documented multiple software supply chain incidents, including compromised npm and PyPI packages, hijacked maintainer accounts, and GitHub accounts abused to push malicious commits while preserving a convincing commit history. In one case, a compromised npm publishing token was used to push an unauthorised update to the Cline CLI that installed malware referred to as OpenClaw onto developer machines during an eight-hour window.

On macOS, Gen tracked a cracked-software distribution chain that pushed users toward mirror sites, torrents, forums, and Telegram channels, blocking roughly 108,000 launch attempts for these applications within 48 hours in a single wave. The payloads included cryptominers, infostealers, and backdoors, but Gen said the more significant issue was permission abuse: installation guides frequently instructed users to disable Gatekeeper and System Integrity Protection, or to grant Full Disk Access, thereby granting broad system access to unsigned binaries.

AI agents move from chatbot risk to execution risk

A significant portion of the report focuses on AI agents, which Gen says have shifted the security conversation because they turn model output into real-world action, fetching URLs, installing packages, editing files, or calling APIs, often with a user’s own credentials and local access.

The report cites an incident in which a Meta AI security researcher granted an AI agent access to her inbox to triage messages, and the agent began deleting emails while reportedly ignoring stop commands. Gen noted that this was reported by TechCrunch and could not be independently verified as forensic evidence, but said it illustrates how a misinterpreted instruction can have real consequences once an agent holds genuine permissions.

The report also references indirect prompt injection documented in the wild by Unit 42, where hidden instructions embedded in web content are later processed by an AI system, and separate research (“Double Agents”) identifying excessive default permissions in a cloud AI agent deployment that allowed a pivot into customer project resources.

Gen discusses its own response to agent risk at length, including a runtime enforcement tool called Sage that checks agent actions, shell commands, URL fetches, file writes, package installs, before they execute, alongside an Agent Trust Hub for pre-use verification, an Agent Detection and Response (ADR) capability, and a proposed cross-industry standard, AARTS, intended to give agent hosts a shared way to expose security-relevant events and enforcement points.

The report also touches on Anthropic’s Claude Mythos and Fable 5 models, noting Anthropic’s own disclosure that Mythos Preview could identify and exploit vulnerabilities in major operating systems and browsers when directed to, and that access to Fable 5 and Mythos 5 was briefly suspended in mid-2026 following a US export-control directive before being restored. Gen frames this as evidence that, once a model can materially accelerate cyber work, questions of who can access it and under what safeguards become part of the security picture, not just the model’s behaviour.

Privacy: persistent access, not just breaches

Gen blocked an average of 310.8 million tracking attempts per month in H1 2026, around 1.9 billion over the half-year. The report highlights GhostPairing, an attack that abuses WhatsApp’s legitimate device-linking feature to trick users into approving an attacker-controlled browser as a linked device, giving the attacker an authorised session that can persist until manually revoked.

The report also raises AI agent memory as an emerging privacy boundary, citing research papers describing backdoored agents that exfiltrate stored user context via disguised tool calls, and separately flags recent FTC settlements and actions against location-data brokers Kochava and Mobilewalla for selling sensitive location data without consent.

Identity and financial fraud: exposure moves fast toward misuse

Gen recorded 18,618 breach events affecting its customers in H1 2026, up 94.5% on the prior half-year, while breach notification alerts with an identified source sent to Norton and LifeLock users rose 628.1% to 3.3 million. February alone accounted for roughly a third of all H1 breach notifications, a spike Gen links partly to the Under Armour breach reported in January 2026, which public reporting said affected around 72 million email addresses.

Downstream financial signals also rose sharply: credit inquiry alerts reached 460,000 in June; depository activity alerts rose 734%; credit activity alerts rose more than tenfold; and web skimming attacks blocked at checkout pages rose 212% to 996,300. Gen also flags a distinct pattern of first-party fraud, in which real, verified accounts, created by people recruited online with promises of quick cash, are later handed over to fraud operators for cash advance abuse, wallet funding or money mule activity, making the behaviour harder to catch at onboarding.

The takeaway

Gen’s overall conclusion is that few of the H1 2026 attacks relied on classic red flags such as poor grammar or obviously suspicious links. Instead, they were built around real reservation details, compromised-but-legitimate mailboxes, trusted update paths and permissions that users had already granted. The report argues that protection increasingly has to sit at the point where trust is granted or transferred, before a payment page, before a package installs, before an AI agent is allowed to act, rather than relying on users to spot the danger themselves.

ShareTweet
Previous Post

Researchers Uncover HOLLOWGRAPH: Malware That Hides Inside Microsoft 365 Calendar Invites

Next Post

New Continuous Runtime Security Validation service aims to strengthen fintech cyber resilience

Recent News

What Does the Cyber Industry Want to See From the New UK Government?

What Does the Cyber Industry Want to See From the New UK Government?

July 20, 2026
Purple Logo, capitalised letters: SALT.

Salt Security tackles AI governance challenge with 100 pre-built agentic security policies

July 20, 2026
New Continuous Runtime Security Validation service aims to strengthen fintech cyber resilience

New Continuous Runtime Security Validation service aims to strengthen fintech cyber resilience

July 20, 2026
Scams Now Drive Almost Half of All Malware Detections as Attackers Weaponise Everyday Trust

Scams Now Drive Almost Half of All Malware Detections as Attackers Weaponise Everyday Trust

July 20, 2026

Eskenzi PR banner ad

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol