ESET's Threat Report for H1 2026 finds that artificial intelligence is amplifying existing cybercrime methods rather than creating entirely new techniques. Researchers examined nearly 900,000 AI skills between December 2025 and May 2026 and identified about 25,000 suspicious and more than 3,000 clearly malicious skills.
What are AI skills?
AI skills are task-specific modules and instruction sets that enable AI agents to perform requests autonomously — for example, summarizing calendar entries, extracting documents from email, or collecting and sharing travel booking details with designated recipients. ESET warns that such skills can be weaponized by malicious actors.
Generative AI inside malware: PromptSpy
ESET's security researchers discovered an Android malware named PromptSpy, the first known sample to employ generative AI in its operation. This demonstrates that AI is appearing not only as a tool used by attackers but also embedded directly within malware.
"Artificial intelligence is not a new threat by itself, but it allows attackers to apply well-established fraud techniques faster, cheaper and more effectively, thereby multiplying the power, quality and quantity of attacks," said Béres Péter, IT director of Sicontact Kft., which distributes ESET products.
ClickFix and ConsentFix: exploiting trust in AI and cloud auth
One prominent recent trend is the spread of so-called ClickFix attacks. These use fake CAPTCHA or repair dialogs that trick users into executing malicious commands on their own machines. Attack chains often hide inside AI-generated troubleshooting content or abuse domains associated with major AI providers.
ConsentFix is a more sophisticated variant that combines ClickFix with abuse of OAuth authorization flows to gain access to cloud accounts without stealing credentials. OAuth allows an application to authenticate to another service without exposing passwords; ConsentFix manipulates authorization requests to obtain access. ESET telemetry shows ClickFix detections rose by about 108 percent over the past six months, while ConsentFix-type attacks more than doubled.
Record levels of QR-code phishing (quishing)
As more people scan QR codes with phones, attackers increasingly exploit the implicit trust users place in them. Quishing uses QR codes instead of clickable links; victims who scan a compromised code can be directed to fraudulent pages and have payment or login data stolen. In Hungary some attackers covered genuine parking-machine QR codes with fake stickers so drivers were redirected to scam sites.
According to ESET, 11 percent of all detected phishing emails in the first half of 2026 contained a QR code.
"Many people treat QR codes as automatically trustworthy, and attackers exploit that psychological factor. You should be as suspicious of an unknown QR code as of a suspicious link in an email," Béres Péter warned.
Ransomware: more attacks, fewer payments
Ransomware incidents continued to increase in H1 2026. Attackers are increasingly deploying so-called EDR-killers — tools that attempt to disable or circumvent enterprise security software as a first step. ESET has documented more than 100 different EDR-killer variants, with new variants continuing to appear.
On the positive side, fewer organizations are paying ransoms: industry studies now estimate that only 14–28 percent of compromised organizations pay, a historic low.
Recommendations to reduce risk
ESET's researchers recommend:
- Always verify the website you are on before following any instructions.
- Do not execute commands or install software just because an online guide tells you to, unless you are certain of the source.
- When scanning a QR code, preview the destination URL before proceeding.
- Enable multi-factor authentication, but be aware that malicious authorization requests can still bypass it.
- Use up-to-date, proactive security solutions capable of detecting new-generation attacks before they succeed.
"AI does not make the internet inherently more dangerous, but it gives scammers a tool to adapt faster to new situations. One of the key challenges in coming years will be for users to learn to question not only what they see, but also what a seemingly intelligent system advises them," Béres Péter added.
ESET's Threat Report H1 2026 (English) provides detailed technical analysis and telemetry supporting these findings.



