The Research Center of ESET published the Threat Report for the first half of 2026, based on its telemetry ESET and in the analyses of threat detection and research specialists, for the period from December of 2025 until the May 2026. According to the report, cybercriminals are increasingly leveraging artificial intelligence (AI) and can launch more effective attacks on a larger scale.
ESET analyzed nearly 900.000 AI skills (small functional elements used by AI agents) and identified tens of thousands of suspects, as well as thousands of confirmed malicious cases. At the same time, AI is starting to be integrated into malware itself. ESET researchers have identified PromptSpy, the first known Android malware that leverages genetic AI during its execution flow.
“Instead of relying on completely new methods and tools, attackers are rapidly adapting established techniques to new platforms, technologies and user behaviors. The number of AI skills in this new ecosystem is growing rapidly, further expanding the attack surface,” says Jiří Kropáč, Director of Threat Prevention Labs at ESET. “On the other hand, PromptSpy demonstrates the potential for greater agility in future threats. However, the anti-abuse measures built into large language models (LLMs) are likely slowing their adoption,” explains Kropáč.
Artificial intelligence skills (AI skills) are small additions or sets of instructions that guide a AI agent on how to perform a specific task, including the services or tools to use and the data to which it must have access.
Report details malicious AI skills that leverage tools hacking third parties, such as Mimikatz and PacketIt also presents a suspicious skill, designed to create a retention mechanism (via a file JSON), as well as a modification tool (in code Python). These functions may lead to unpredictable behavior of the AI agent or facilitate its abuse by an attacker.
The report also mentions well-intentioned but problematic skills, such as those promoted as security scanners. These skills create a false sense of security by applying only basic scanning techniques, similar to those of antivirus tools from the 1990s, or are limited to checking the reputation of hashes, URLs and IP addresses via VirusTotal.
Meanwhile, ClickFix, a social engineering technique that leverages fake error messages, has expanded beyond fake messages. CAPTCHA and now appears on AI-related support pages, browser extensions, and cloud authentication scenarios.
AI-fix demonstrates how attackers exploit trust in genetic AI by embedding ClickFix-style breach chains into AI-generated troubleshooting content for non-existent issues on pages that misuse the domains of leading AI companies.
At the same time, ConsentFix highlights a move towards token theft, combining a ClickFix-like interaction with OAuth abuse. This allows attackers to take over cloud accounts without having to steal credentials, often bypassing multi-factor authentication (MFA) and relying solely on legitimate login workflows.
ESET's detections of this technique more than doubled between the second half of 2025 and the first half of 2026, indicating ongoing activity and continued adaptation by attackers.
Phishing campaigns are constantly evolving, adapting to user behavior. QR code phishing, also known as “quishing,” has reached record levels, according to ESET data. Attackers embed malicious links in QR codes, bypassing control mechanisms and transferring user interaction to mobile devices. At the same time, they exploit the implicit trust that many users place in these two-dimensional barcodes.
Approximately 11% of all phishing emails detected in the first half of 2026 contained QR codes. QR code phishing threats were particularly prevalent in the US (19% of detections), Spain (17%), and Mexico (6%).
Finally, ransomware activity showed no signs of slowing down, as the use of “EDR killers,” tools designed to disable security software during attacks, continued. ESET Research has documented more than 100 different “EDR killers” in use, with new variants emerging on a regular basis.
The number of attacks ransomware continued to grow in the first half of 2026. However, the number of victims willing to pay the ransom fell to the lowest levels ever recorded. Three recent industry reports confirm this downward trend, reporting that only 14–28% of victims paid the ransom.
For more information, please refer to ESET Threat Report for the first half of 2026 at WeLiveSecurity.com.
Unique AI skills detected by ESET systems per day, seven-day average
Although the press releases will range from very select to rare, I said I'd pass...because sometimes the editors hide.



