AI-Driven Cyber Threats and Quishing Reach Record Levels in ESET's H1 2026 Threat Report

2 Sources

Share

ESET's H1 2026 report reveals a dramatic rise in AI-driven cyber threats, with nearly 900,000 AI skills analyzed and thousands flagged as malicious. QR code phishing reached record highs at 11% of all phishing emails, while ClickFix social engineering detections more than doubled, signaling attackers are rapidly adapting established techniques to exploit new technologies and user trust.

News article

AI Skills Emerge as New Attack Vector

The ESET Threat Report for H1 2026 exposes a troubling evolution in cyberattack methodologies, with artificial intelligence now embedded directly into malicious operations

1

. ESET researchers analyzed nearly 900,000 AI skills—small functional components used by AI agents—and identified tens of thousands of suspicious instances, with thousands confirmed as outright malicious

1

. This rapidly expanding ecosystem of malicious AI skills is growing "as we speak," according to ESET, creating an ever-widening attack surface that security teams must now monitor

1

.

The integration of AI-driven cyber threats extends beyond standalone tools. Following the first AI-powered ransomware detected in 2025, ESET identified PromptSpy, the first known Android malware to incorporate generative AI into its execution flow

1

. This adaptable malware leverages Google Gemini to interpret user interface elements and adjust behavior across different devices and environments without hardcoded instructions

1

. While still rare, PromptSpy demonstrates how AI can enable unprecedented flexibility in future threats, though built-in guardrails against abuse in large language models are currently slowing broader adoption

1

.

Quishing and QR Code Phishing Hit Record Levels

QR code phishing, commonly known as quishing, reached record levels in ESET telemetry during H1 2026

1

2

. Attackers embed malicious links within QR codes to bypass cursory inspection and shift user interaction to mobile devices, exploiting the implicit trust many people place in these black-and-white squares

1

. Approximately 11% of all detected phishing emails in H1 2026 utilized QR codes

2

. The United States led in QR code phishing threats with 19% of detections, followed by Spain at 17%, and Mexico at 6%

2

. India mirrors this alarming trend, with QR code phishing ranking as the country's second most-detected email threat category during the same period

2

.

ClickFix Social Engineering Expands with AI-Themed Tactics

ClickFix social engineering, a technique leveraging fake error messages, has evolved significantly beyond its original fake CAPTCHA prompts

1

2

. The method now encompasses AI-themed help pages, browser extensions, and cloud authentication scenarios

2

. ESET detections of this vector more than doubled between H2 2025 and H1 2026, indicating sustained activity and rapid adaptation by threat actors

1

2

.

A particularly concerning variant called AI-fix demonstrates how adversaries exploit trust in generative AI by embedding ClickFix compromise chains into AI-generated troubleshooting content for nonexistent issues on pages that abuse domains of AI powerhouses

2

. Meanwhile, ConsentFix represents an evolution toward token theft through OAuth authorization abuse, combining ClickFix-style interaction with cloud account hijacking techniques that bypass multi-factor authentication and rely entirely on legitimate login workflows

2

.

Ransomware Activity Persists Despite Declining Payments

Ransomware activity showed no signs of slowing down in H1 2026, with continued deployment of EDR killers—tools specifically designed to disable security software during attacks

1

2

. ESET Research has documented over 100 different EDR killers used in the wild, with new variants appearing regularly

1

2

. However, data from multiple sources reveals a declining share of victims choosing to pay ransoms, with three recent industry reports confirming ransom payments declining to a 14-28% share of paying victims—reaching all-time lows

2

. This downward trend suggests some progress in mitigation and response measures, even as the number of ransomware attacks continued to grow during the period

1

2

. Watch for continued innovation in AI-themed social engineering tactics and increased sophistication in adaptable malware as attackers refine techniques to exploit emerging technologies and user behaviors.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved