ESET Threat Report: ClickFix fake error surges, spreads ransomware and other malware
ESET, June 25,2025
ESET has released its latest Threat Report, which summarizes threat landscape trends seen in ESET telemetry and from the perspective of both ESET threat detection and research experts, from December 2024 through May 2025
A deceptive fake error attack vector, ClickFix, surged by over 500%, becoming the second most common attack method after phishing, and responsible for nearly 8% of all blocked attacks.
SnakeStealer overtook Agent Tesla as the most detected infostealer, while ESET helped disrupt two major malware-as-a-service operations - Lumma Stealer and Danabot.
Rivalries among ransomware gangs, including RansomHub, caused internal chaos. Despite more attacks, ransom payments dropped due to takedowns and trust issues.
Android adware detections jumped 160% due to the Kaleidoscope malware, while NFC-based fraud spiked by more than thirty-five-fold ,with tools like GhostTap and SuperCard X enabling more digital wallet theft.