2 Sources
[1]
ESET tracks rise in malicious AI skills and adaptable malware
The first half of 2026 shows how attackers continue to improve the efficiency and scalability of their operations. Rather than relying on entirely new methods and tools, they are quickly adapting established techniques to new platforms, technologies, and user behaviors. Artificial intelligence is playing a growing role in this development. In H1 2026, ESET analyzed nearly 900,000 AI skills - small functional components used by AI agents - and identified tens of thousands of suspicious and thousands of outright malicious instances. The number of AI skills within this new ecosystem is growing rapidly "as we speak", further expanding the attack surface. AI is also beginning to appear within malware itself. Shortly after the emergence of the first AI-powered ransomware in 2025, ESET researchers identified PromptSpy, the first known Android malware to use generative AI in its execution flow. The malware leverages AI - specifically, Google's Gemini - to interpret user interface elements and adapt across devices and environments without relying on hardcoded behavior. While still rare, PromptSpy illustrates the potential for increased flexibility in future threats - although guardrails against abuse included in LLMs are likely slowing down the adoption. ClickFix - a social engineering technique leveraging fake error messages - has expanded beyond fake CAPTCHA prompts into AI-themed help pages, browser extensions, and cloud authentication scenarios. ESET detections of this vector more than doubled between H2 2025 and H1 2026, indicating sustained activity and adaptation. Phishing campaigns are also evolving in response to user behavior. QR code phishing - also known as quishing - has reached record levels in ESET telemetry, with attackers embedding malicious links in QR codes to bypass cursory inspection and shift user interaction to mobile devices, while exploiting the implicit trust many people place in the black-and-white squares. Last but not least, ransomware activity showed no signs of slowing down, with continued use of EDR killers - tools designed to disable security software during attacks. ESET Research has documented over 100 EDR killers used in the wild, with new variants appearing regularly. At the same time, data from multiple sources shows that a declining share of victims are choosing to pay ransoms, suggesting some progress in mitigation and response measures. Learn more about the latest attack techniques by reading the ESET Threat Report H1 2026.
[2]
ESET Threat Report H1 2026 Highlights AI-Driven Cyber Threats and Quishing
QR code phishing also known as quishing has reached record levels in ESET telemetry, with attackers embedding malicious links in QR codes to bypass inspection and shift user interaction to mobile devices while exploiting the implicit trust many people place in the barcodes with square patterns. Approximately 11% of all detected phishing emails in H1 2026 utilized QR codes, and QR code phishing threats were most prevalent in the US (19% of detections), Spain (17%), and Mexico (6%). India mirrors this trend closely: QR code phishing was India's second most-detected email threat category in the same period, underscoring the need for Indian enterprises and consumers alike to "stop before they scan." Meanwhile, ClickFix - a social engineering technique leveraging fake error messages - has expanded beyond fake CAPTCHA prompts into AI-themed help pages, browser extensions, and cloud authentication scenarios. AI-fix shows how adversaries exploit trust in generative AI, embedding ClickFix compromise chains into AI-generated troubleshooting content to nonexistent issues on pages that abuse domains of AI powerhouses. ConsentFix highlights an evolution toward token theft, combining ClickFix-style interaction with OAuth authorization abuse to hijack cloud accounts without the need to steal credentials, often bypassing MFA and relying entirely on legitimate login workflows. ESET detections of this vector more than doubled between H2 2025 and H1 2026, indicating sustained activity and adaptation. Phishing campaigns are also evolving in response to user behavior. QR code phishing - also known as quishing - has reached record levels in ESET telemetry, with attackers embedding malicious links in QR codes to bypass inspection and shift user interaction to mobile devices while exploiting the implicit trust many people place in the barcodes with square patterns. Approximately 11% of all detected phishing emails in H1 2026 utilized QR codes, and QR code phishing threats were most prevalent in the US (19% of detections), Spain (17%), and Mexico (6%). Last but not least, ransomware activity showed no signs of slowing down, with the continued use of EDR killers - tools designed to disable security software during attacks. ESET Research has documented over 100 different EDR killers used in the wild, with new variants appearing regularly. The number of ransomware attacks continued to grow in H1 2026, but the number of victims willing to pay reached all-time lows. Three recent industry reports confirmed this downward trend, reporting a 14-28% share of paying victims.
Share
Copy Link
ESET's H1 2026 report reveals a dramatic rise in AI-driven cyber threats, with nearly 900,000 AI skills analyzed and thousands flagged as malicious. QR code phishing reached record highs at 11% of all phishing emails, while ClickFix social engineering detections more than doubled, signaling attackers are rapidly adapting established techniques to exploit new technologies and user trust.

The ESET Threat Report for H1 2026 exposes a troubling evolution in cyberattack methodologies, with artificial intelligence now embedded directly into malicious operations
1
. ESET researchers analyzed nearly 900,000 AI skills—small functional components used by AI agents—and identified tens of thousands of suspicious instances, with thousands confirmed as outright malicious1
. This rapidly expanding ecosystem of malicious AI skills is growing "as we speak," according to ESET, creating an ever-widening attack surface that security teams must now monitor1
.The integration of AI-driven cyber threats extends beyond standalone tools. Following the first AI-powered ransomware detected in 2025, ESET identified PromptSpy, the first known Android malware to incorporate generative AI into its execution flow
1
. This adaptable malware leverages Google Gemini to interpret user interface elements and adjust behavior across different devices and environments without hardcoded instructions1
. While still rare, PromptSpy demonstrates how AI can enable unprecedented flexibility in future threats, though built-in guardrails against abuse in large language models are currently slowing broader adoption1
.QR code phishing, commonly known as quishing, reached record levels in ESET telemetry during H1 2026
1
2
. Attackers embed malicious links within QR codes to bypass cursory inspection and shift user interaction to mobile devices, exploiting the implicit trust many people place in these black-and-white squares1
. Approximately 11% of all detected phishing emails in H1 2026 utilized QR codes2
. The United States led in QR code phishing threats with 19% of detections, followed by Spain at 17%, and Mexico at 6%2
. India mirrors this alarming trend, with QR code phishing ranking as the country's second most-detected email threat category during the same period2
.ClickFix social engineering, a technique leveraging fake error messages, has evolved significantly beyond its original fake CAPTCHA prompts
1
2
. The method now encompasses AI-themed help pages, browser extensions, and cloud authentication scenarios2
. ESET detections of this vector more than doubled between H2 2025 and H1 2026, indicating sustained activity and rapid adaptation by threat actors1
2
.A particularly concerning variant called AI-fix demonstrates how adversaries exploit trust in generative AI by embedding ClickFix compromise chains into AI-generated troubleshooting content for nonexistent issues on pages that abuse domains of AI powerhouses
2
. Meanwhile, ConsentFix represents an evolution toward token theft through OAuth authorization abuse, combining ClickFix-style interaction with cloud account hijacking techniques that bypass multi-factor authentication and rely entirely on legitimate login workflows2
.Related Stories
Ransomware activity showed no signs of slowing down in H1 2026, with continued deployment of EDR killers—tools specifically designed to disable security software during attacks
1
2
. ESET Research has documented over 100 different EDR killers used in the wild, with new variants appearing regularly1
2
. However, data from multiple sources reveals a declining share of victims choosing to pay ransoms, with three recent industry reports confirming ransom payments declining to a 14-28% share of paying victims—reaching all-time lows2
. This downward trend suggests some progress in mitigation and response measures, even as the number of ransomware attacks continued to grow during the period1
2
. Watch for continued innovation in AI-themed social engineering tactics and increased sophistication in adaptable malware as attackers refine techniques to exploit emerging technologies and user behaviors.Summarized by
Navi
[1]
04 Sept 2025•Technology

02 Jan 2026•Technology

23 Jul 2026•Technology

1
Technology

2
Technology

3
Technology
