ESET tracks rise in malicious AI skills and adaptable malware
ESET's H1 2026 Threat Report highlights a rise in malicious use of AI skills and AI-assisted malware. Attackers are adapting established techniques to AI platforms and emerging technologies, including social engineering methods like ClickFix and increased QR code phishing (quishing). The report also notes ransomware tools designed to disable security software (EDR killers) remain prevalent. The use of AI in malware, such as the Android PromptSpy leveraging Google's Gemini, illustrates growing flexibility in threats. Overall, attackers are scaling campaigns by combining AI, social engineering, and ransomware innovations.
AI Analysis
Technical Summary
In the first half of 2026, attackers have increasingly integrated AI into their operations, adapting existing attack methods to new platforms and user behaviors. ESET analyzed nearly 900,000 AI skills, identifying thousands of malicious instances, indicating rapid growth of this attack surface. AI-assisted malware like PromptSpy uses generative AI to dynamically interpret user interfaces and adapt across devices. Social engineering techniques such as ClickFix have evolved beyond fake CAPTCHAs to AI-themed help pages and cloud authentication scams. QR code phishing has surged, exploiting user trust in QR codes. Ransomware activity continues with frequent use of EDR killers to disable security software. Despite these advances, fewer victims are paying ransoms, suggesting some mitigation progress.
Potential Impact
The integration of AI into malware and attack techniques increases the adaptability and scalability of cyber threats, potentially making detection and prevention more challenging. The rise of AI-assisted malware like PromptSpy can evade traditional static defenses by dynamically adapting to environments. Expanded social engineering tactics and increased quishing attacks raise the risk of successful user-targeted compromises. Continued use of EDR killers in ransomware attacks threatens endpoint security by disabling protective software. However, a decline in ransom payments may reduce attacker incentives and impact.
Mitigation Recommendations
No specific patch or official fix is applicable as this is a broad trend rather than a single vulnerability. Organizations should remain aware of evolving AI-assisted threats and social engineering tactics described by ESET. Monitoring for suspicious AI skill usage and emerging malware variants is advised. Since ransomware with EDR killers remains active, maintaining updated endpoint detection and response capabilities and applying best practices for ransomware defense remain important. Check ESET's official threat report for detailed guidance and updates.
ESET tracks rise in malicious AI skills and adaptable malware
Description
ESET's H1 2026 Threat Report highlights a rise in malicious use of AI skills and AI-assisted malware. Attackers are adapting established techniques to AI platforms and emerging technologies, including social engineering methods like ClickFix and increased QR code phishing (quishing). The report also notes ransomware tools designed to disable security software (EDR killers) remain prevalent. The use of AI in malware, such as the Android PromptSpy leveraging Google's Gemini, illustrates growing flexibility in threats. Overall, attackers are scaling campaigns by combining AI, social engineering, and ransomware innovations.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In the first half of 2026, attackers have increasingly integrated AI into their operations, adapting existing attack methods to new platforms and user behaviors. ESET analyzed nearly 900,000 AI skills, identifying thousands of malicious instances, indicating rapid growth of this attack surface. AI-assisted malware like PromptSpy uses generative AI to dynamically interpret user interfaces and adapt across devices. Social engineering techniques such as ClickFix have evolved beyond fake CAPTCHAs to AI-themed help pages and cloud authentication scams. QR code phishing has surged, exploiting user trust in QR codes. Ransomware activity continues with frequent use of EDR killers to disable security software. Despite these advances, fewer victims are paying ransoms, suggesting some mitigation progress.
Potential Impact
The integration of AI into malware and attack techniques increases the adaptability and scalability of cyber threats, potentially making detection and prevention more challenging. The rise of AI-assisted malware like PromptSpy can evade traditional static defenses by dynamically adapting to environments. Expanded social engineering tactics and increased quishing attacks raise the risk of successful user-targeted compromises. Continued use of EDR killers in ransomware attacks threatens endpoint security by disabling protective software. However, a decline in ransom payments may reduce attacker incentives and impact.
Mitigation Recommendations
No specific patch or official fix is applicable as this is a broad trend rather than a single vulnerability. Organizations should remain aware of evolving AI-assisted threats and social engineering tactics described by ESET. Monitoring for suspicious AI skill usage and emerging malware variants is advised. Since ransomware with EDR killers remains active, maintaining updated endpoint detection and response capabilities and applying best practices for ransomware defense remain important. Check ESET's official threat report for detailed guidance and updates.
Threat ID: 6a6e88eebf32cb7a348d6a89
Added to database: 08/02/2026, 00:01:50 UTC
Last enriched: 08/02/2026, 00:01:58 UTC
Last updated: 08/02/2026, 00:02:05 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.