Cyberattackers Get Smarter, Faster, with AI-Powered Malware on the Rise
The cybersecurity landscape is evolving rapidly, with threat actors leveraging artificial intelligence (AI) to improve their operations and evade detection. According to a new report from ESET, malicious AI skills and adaptable malware are on the rise, posing significant challenges for security professionals.
In the first half of 2026, ESET analyzed nearly 900,000 AI skills – small functional components used by AI agents – and identified tens of thousands of suspicious instances, with thousands more classified as outright malicious. The sheer volume of these skills is expanding rapidly, further increasing the attack surface. This growth in AI-powered threats is not surprising, given that attackers are increasingly using established techniques to adapt to new platforms, technologies, and user behaviors.
One notable example of this trend is PromptSpy, a type of Android malware discovered by ESET researchers. Unlike traditional malware, which relies on hardcoded behavior, PromptSpy uses generative AI – specifically Google’s Gemini – to interpret user interface elements and adapt across devices and environments. This flexibility allows the malware to evade detection and wreak havoc on unsuspecting victims.
The use of AI in malware is not limited to Android devices; it’s also starting to appear in other types of threats, such as ransomware. In 2025, ESET researchers identified the first AI-powered ransomware, which marked a significant shift in the threat landscape. Now, with the emergence of PromptSpy and similar malware, it’s clear that attackers are pushing the boundaries of what’s possible.
In addition to AI-powered malware, social engineering techniques are also becoming increasingly sophisticated. ClickFix, a tactic that leverages fake error messages, has expanded beyond CAPTCHA prompts into more complex scenarios involving AI-themed help pages, browser extensions, and cloud authentication. This evolution is concerning, as it demonstrates attackers’ ability to adapt and exploit user trust.
Phishing campaigns are also evolving in response to user behavior. QR code phishing – or “quishing” – has reached record levels, with attackers embedding malicious links in QR codes to bypass cursory inspection and shift user interaction to mobile devices. This tactic exploits the implicit trust people place in the black-and-white squares, making it harder for users to detect the threat.
Ransomware activity continues unabated, with over 100 EDR killers documented by ESET Research. These tools are designed to disable security software during attacks, allowing attackers to wreak havoc on victims’ systems. While some progress has been made in mitigating and responding to ransomware attacks – including a decline in the share of victims paying ransoms – there’s still much work to be done.
In conclusion, the rise of AI-powered malware and adaptable threats requires security professionals to stay vigilant and adapt their defenses accordingly. By understanding the tactics and techniques used by attackers, we can develop more effective countermeasures and protect our systems from these emerging threats. As a practical takeaway, it’s essential for users and organizations to remain cautious when interacting with unfamiliar websites or apps, especially those that use AI-themed interfaces or QR codes.
Source: Bleeping Computer — 2026-07-31