← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

ESET H1 2026 Threat Report details rise in malicious AI skills and adaptable malware

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • ESET identified tens of thousands of suspicious AI skills in H1 2026.
  • PromptSpy, the first Android malware using generative AI, was discovered.
  • ClickFix social engineering attacks doubled between H2 2025 and H1 2026.
  • QR code phishing reached record levels, and ransomware activity continued with EDR killers.

AI's Role in Cyberattacks

The first half of 2026 saw attackers integrating artificial intelligence into their operations. ESET analyzed nearly 900,000 AI skills, identifying tens of thousands as suspicious and thousands as malicious. This indicates a rapid expansion of the attack surface due to the growing number of AI skills.

Generative AI in Malware

AI is now appearing within malware itself. Following the emergence of AI-powered ransomware in 2025, ESET researchers discovered PromptSpy, the first known Android malware to use generative AI. PromptSpy leverages Google's Gemini to interpret user interface elements, allowing it to adapt across devices and environments without relying on hardcoded behaviors, illustrating potential for increased threat flexibility.

Evolving Social Engineering Tactics

Attackers are adapting social engineering techniques. ClickFix, which uses fake error messages, has expanded beyond CAPTCHA prompts to AI-themed help pages, browser extensions, and cloud authentication scenarios. ESET detections of this vector more than doubled between H2 2025 and H1 2026, showing sustained activity. QR code phishing, or quishing, also reached record levels, with malicious links embedded in QR codes to bypass inspection and shift user interaction to mobile devices.

Persistent Ransomware Threats

Ransomware activity showed no signs of slowing down in H1 2026. Attackers continued to use EDR killers, tools designed to disable security software during attacks. ESET Research has documented over 100 EDR killers in use, with new variants appearing regularly.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

ESET's H1 2026 Threat Report indicates a growing trend of attackers using AI to enhance efficiency and scalability, identifying tens of thousands of suspicious AI skills and the first Android malware, PromptSpy, leveraging generative AI. This development signifies an expanding attack surface and increased flexibility in future threats, alongside continued growth in social engineering tactics like QR code phishing and ransomware activity.