Work smarter than ever with Intel vPro and AI PC experiences for business
HP for BusinessLaptops & DesktopsWorkstations Video ConferencingServices

Threat Insights Report

HP Wolf Security

Shortcuts

Anchor: Threat-Landscape

Threat Landscape

Download PDF

Welcome to the January 2025 edition of the HP Wolf Security Threat Insights Report
Each quarter our security experts highlight notabl...

Anchor: Executive-Summary

Executive Summary

Download PDF

Email threats that evaded gateway security

11%

Heading 1

Subtitle 1

Heading 2

Subtitle 2

Heading 3

Subtitle 3

Threats delivered in archives in Q3

34%

Heading 1

Subtitle 1

Heading 2

Subtitle 2

Heading 3

Subtitle 3

• In Q3, HP Sure Click caught campaigns spreading VIP Keylogger and 0bj3ctivityStealer malware that relied on the same techniques and loaders...

Anchor: threats

Notable Threats

Download PDF

Malware lurking in images hosted on legitimate websites spread VIP Keylogger

Download PDF

In Q3, the HP Threat Research team uncovered large malware campaigns spreading VIP Keylogger, caught by HP Sure Click. The threat actors behind this campaign sent emails posing as invoices and...

Much of the code in the script belongs to a legitimate XML parsing library. This code obfuscates the malware and does not execute. The malicious code decodes and runs a PowerShell script (T105...

0bj3ctivityStealer campaign highlights how malware kits are boosting attack efficiency

Download PDF

Q3 saw another campaign, caught by HP Sure Click, that shared many similarities with the VIP Keylogger activity. Threat actors began by sending malicious archive files to targets by email, pos...

Though both campaigns distribute different malware families, they share many similarities, including:
•   Hiding malicious code within legitimate script...

HTML smuggling threat delivering XWorm bears hallmarks of GenAI

Download PDF

One of the techniques we see threat actors using to infect PCs is HTML smuggling (T1027.006).⁶ The aim is to deliver malicious content hidden within HTML files, tricking victims into infe...

In addition to the HTML smuggling campaign that leads to XWorm, in Q3 we observed another campaign that makes use of the same malware dropper. In this case, however, the infection started with...

The campaign not only combines multiple different attack techniques to stay undetected during delivery and execution, but also shows a rise of AI-assisted malware development. Currently, we ar...

Threat actors target video game modification and cheat code repositories with Lumma Stealer

Download PDF

All the campaigns we’ve highlighted so far this quarter make use of email as their delivery method. The following campaign was an exception. In Q3, we spotted threat actors setting up a series...

Anchor: malware-file-extensions

Top Malware File Extensions

Download PDF

Threat file type trends

In Q3, executables and scripts regained first place as the most popular malware delivery type (40% of threats caught by HP Sure Click), seeing a 5%-point rise over Q2. In Q3, the top five archive file formats abused by threat actors were ZIP, RAR, LZH, 7Z and GZ. Archives were the second most popular malware delivery file type (34% of threats). 
8% of threats relied on documents such as Microsoft Word formats (e.g. DOC, DOCX), while malicious spreadsheets (e.g. XLS, XLSX) totaled 7% of threats. 9% of threats were PDF files, seeing a 2%-point rise over Q2. The remaining 2% of threats used other application types.

Heading 1

Subtitle 1

Heading 2

Subtitle 2

Heading 3

Subtitle 3
Anchor: top-threat-vectors

Top Threat Vectors

Download PDF

52%

Email

28%

Web browser downloads

20%

Other

Threat vector trends

Download PDF

Email remained the top vector for delivering malware to endpoints (52% of threats), falling 9% points compared to Q2. Malicious web browser downloads grew by 10% points to 28% in Q3. Threats d...

Anchor: current

Stay Current

Download PDF

The HP Wolf Security Threat Insights Report is made possible by most of our customers who opt to share threat telemetry with HP. Our security experts analyze threat trends and significant malw...

Anchor: about

About the HP Wolf Security Threat Insights Report

Download PDF

Enterprises are most vulnerable from users opening email attachments, clicking on hyperlinks in emails, and downloading files from the web. HP Wolf Security protects the enterprise by isolatin...

Anchor: About-HP-Wolf-Security

About HP Wolf Security

Download PDF

HP Wolf Security is a new breedᶜ of endpoint security. HP’s portfolio of hardware-enforced security and endpointfocused security services are designed to help organizations safeguard PCs,...


References
[1] https://hp.com/wolf [2] https://malpedia.caad.fkie.fraunhofer.de/details/win.404keylogger [3] https://malpedia.caad.fkie.fraunhofer.de/details/win.0bj3ctivity_stealer [4] https://attack.mitre.org/techniques/T1027/009/ [5] https://attack.mitre.org/techniques/T1102/ [6] https://attack.mitre.org/techniques/T1027/006/ [7] https://malpedia.caad.fkie.fraunhofer.de/details/win.xworm [8] https://threatresearch.ext.hp.com/hp-wolf-security-threat-insights-report-september-2024/ [9] https://malpedia.caad.fkie.fraunhofer.de/details/win.lumma [10] https://nvd.nist.gov/vuln/detail/cve-2017-11882 [11] https://attack.mitre.org/techniques/T1203/ [12] https://attack.mitre.org/techniques/T1059/005/ [13] https://attack.mitre.org/techniques/T1059/001/ [14] https://attack.mitre.org/techniques/T1547/001/ [15] https://threatresearch.ext.hp.com/the-many-skins-of-snake-keylogger/ [16] https://github.com/tpn/windows-rktools-2003/blob/master/portmgr.vbs [17] https://attack.mitre.org/techniques/T1059/007/ [18] https://attack.mitre.org/techniques/T1059/010/ [19] https://attack.mitre.org/techniques/T1027/013/ [20] https://attack.mitre.org/techniques/T1055/012/ [21] https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook [22] https://enterprisesecurity.hp.com/s/article/Threat-Forwarding [23] https://enterprisesecurity.hp.com/s/article/HP-Threat-Intelligence [24] https://enterprisesecurity.hp.com/s/ [25] https://github.com/hpthreatresearch/ [26] https://threatresearch.ext.hp.com/blog
Anchor: Take-the-Next-Step

See HP Wolf Pro Security in Action

Schedule your FREE 30-minute live demo to see how HP Wolf Pro Security’s threat containment stops malware in its tracks.

Why HP Wolf Pro Security?
  • Advanced Threat Containment: Isolates commonly used files in micro-virtual machines, stopping malware before it spreads.
  • Secure Browsing: Combines hardened browsers with virtualization for safe, flexible internet browsing.
  • Simplified Management: Cloud-based controls make deployment and policy management effortless.

What to Expect in Your Virtual Demo
In this exclusive session with an HP Security Tech Expert, you will:
  • See real-time demonstrations of threat containment using hardware-enforced isolation technology.
  • Learn how HP Wolf Pro Security protects against phishing, ransomware or zero-day attacks.
  • Discover easy-to-use tools for managing endpoint security.
  • Get answers to your specific security questions.

Spots are limited, book yours today!

Access the full content offline

a. HP Wolf Enterprise Security is an optional service and may include offerings such as HP Sure Click Enterprise and HP Sure Access Enterprise. HP Sure Click Enterprise requires Windows 8 or 10 and Microsoft Internet Explorer, Google Chrome, Chromium or Firefox are supported. Supported attachments include Microsoft Office (Word, Excel, PowerPoint) and PDF files, when Microsoft Office or Adobe Acrobat are installed. HP Sure Access Enterprise requires Windows 10 Pro or Enterprise. HP services are governed by the applicable HP terms and conditions of service provided or indicated to Customer at the time of purchase. Customer may have additional statutory rights according to applicable local laws, and such rights are not in any way affected by the HP terms and conditions of service or the HP Limited Warranty provided with your HP Product. For full system requirements, please visit www.hpdaas.com/requirements. b. HP Wolf Security Controller requires HP Sure Click Enterprise or HP Sure Access Enterprise. HP Wolf Security Controller is a management and analytics platform that provides critical data around devices and applications and is not sold as a standalone service. HP Wolf Security Controller follows stringent GDPR privacy regulations and is ISO27001, ISO27017 and SOC2 Type 2 certified for Information Security. Internet access with connection to the HP Cloud is required. For full system requirements, please visit http://www.hpdaas.com/requirements. c. HP Security is now HP Wolf Security. Security features vary by platform, please see product data sheet for details. HP Services are governed by the applicable HP terms and conditions of service provided or indicated to Customer at the time
HP Services are governed by the applicable HP terms and conditions of service provided or indicated to Customer at the time of purchase. Customer may have additional statutory rights according to applicable local laws, and such rights are not in any way affected by the HP terms and conditions of service or the HP Limited Warranty provided with your HP Product.