From vibe hacking to flat-pack malware

March 2026 Information Security, AI & Data Analytics

HP issued its latest Threat Insights Report, with strong indications that attackers are using AI to scale and accelerate campaigns, and that many are prioritising cost, effort, and efficiency over quality. Despite being formulaic and low-effort, these AI-assisted attacks are slipping past enterprise defences.

The report provides an analysis of real-world cyberattacks, helping organisations keep up with the latest techniques that cybercriminals use to evade detection and breach PCs in the fast-changing cybercrime landscape. Based on the millions of endpoints running HP Wolf Security, notable campaigns identified by HP threat researchers include:

Vibe-hacking scripts using Booking.com redirects: Attackers are using AI to generate ready-made infection scripts – known as vibe-hacking – to automate malware delivery. In one campaign, a link in a fake invoice PDF triggers a silent download from a compromised site before redirecting victims to trusted platforms such as Booking.com.

Flat-pack malware speeds up campaign building: Threat actors are assembling attacks using inexpensive, off-the-shelf malware components, likely purchased from hacker forums. While lures and final payloads change, attackers are reusing the same intermediate scripts and installers, allowing them to quickly build, customise, and scale campaigns with minimal effort. Notably, this is not the work of a single threat group; multiple, unrelated actors are using the same building blocks.

Malware hidden in fake Teams installer ‘piggyback’ attack: Campaigns distributed malware using search engine poisoning and malicious adverts that promote fake Microsoft Teams websites. Victims download a malicious installer bundle in which hidden Oyster Loader malware piggybacks on the Teams installation process, allowing the real app to install, while the infection runs unnoticed, giving the attacker backdoor control of the user’s device.

Alex Holland, principal threat research, HP Security Lab, comments, “It is the c are seeing is that many attackers are optimising for speed and cost rather than quality. They are not using AI to raise the bar; they are using it to move faster and reduce effort. The campaigns themselves are basic, but the uncomfortable reality is they still work.”

The report, which examines data from October-December 2025, details how cybercriminals continue to diversify attack methods to bypass security tools with no reported breaches.

• At least 14% of email threats identified by HP Sure Click bypassed one or more email gateway scanners.

• Executable files were the most popular delivery type (37%), followed by .zip (11%) and .docx (10%).

Dr Ian Pratt, global head of security for personal systems at HP Inc., comments, “AI-assisted attacks are shining a spotlight on the limitations of detection-led security. When attackers can generate and repackage malware in minutes, detection-based defences cannot keep up. Instead of trying to spot every variant, organisations need to reduce exposure. By containing high-risk activities, like opening untrusted attachments or clicking unknown links within an isolated environment, businesses can stop threats before they cause damage and remove an entire class of risk.”

Visit the Threat Research blog to view the report.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Cybersecurity needs actual intelligence before artificial intelligence
Information Security AI & Data Analytics
Cybersecurity depends on interpretation. A tool can tell you that something unusual has happened, but people need to determine whether it is a genuine risk, the business impact, and how to respond without causing unnecessary disruption.

Read more...
Duxbury Cybersecurity sharpens reseller offering
Duxbury Networking Information Security News & Events
Duxbury Networking has strengthened its Duxbury Cybersecurity business unit by adding WatchGuard and Cynet, giving South African resellers broader, more integrated coverage for the security risks customers are now asking them to address.

Read more...
NEC XON detects and stops ransomware attack
NEC XON Information Security IoT & Automation
Ransomware attacks rarely begin with chaos. More often, they start quietly, with probing, mapping, and patient reconnaissance inside a target’s network. That was the situation facing a global recruitment firm when cybercriminals attempted to navigate its systems.

Read more...
Sara AI Pentesting available in South Africa
Information Security News & Events
Synack and Wolfpack Information Risk are offering Sara AI Pentesting to organisations across South Africa, helping companies move from point-in-time testing to continuous security validation with AI and human expertise.

Read more...
Sophos establishes South African legal entity to strengthen local operations
News & Events Information Security
Global cybersecurity company, Sophos, has announced the formation of its local legal entity, which will support local invoicing, partner enablement, compliance requirements and expanded regional investment.

Read more...
Cybersecurity in a digitally connected security industry
SA Technologies Information Security IoT & Automation
As more organisations move towards digital visitor management, cloud-based access control, mobile applications, biometric verification, and connected security platforms, cybersecurity must be viewed as part of the full security environment.

Read more...
Enterprises must prepare for digital conflict
Information Security
Cyberattacks can be launched remotely and at scale. A coordinated attack launched from anywhere in the world can disrupt supply chains, shut down utilities, or expose millions of customer records within minutes.

Read more...
Growing adoption of AI at work
News & Events AI & Data Analytics
AI adoption accelerates worldwide, with South Africa making gains amid uneven diffusion. Locally, South Africa ranks 46th of 147 economies measured, and its AI usage increased to 23,1% in Q1 2026.

Read more...
Enterprise AI hits the wall
News & Events AI & Data Analytics
Demands for AI privacy and sovereignty expose the limits of architectures built for centralised and borderless data flows. Organisations that redesign early are gaining a measurable edge in AI readiness and scale.

Read more...
71% of organisations suffered an identity breach
News & Events Information Security
The State of Identity Security 2026 report from Sophos finds human error and poor non-human identity management are the root causes of most attacks, as agentic AI accelerates the risk.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.