Cybercrime’s Next Frontier: Malicious AI Skills and Adaptable Malware on the Rise
As we navigate the ever-evolving threat landscape, a disturbing trend has emerged in the first half of 2026. Cyber attackers are increasingly leveraging artificial intelligence (AI) to enhance their operations, making them more efficient, scalable, and adaptable. According to ESET’s latest research, this shift is driven by the rapid growth of malicious AI skills – small functional components used by AI agents – with thousands of suspicious and outright malicious instances identified in just six months.
The proliferation of AI skills within the cybercrime ecosystem has expanded the attack surface exponentially, making it even more challenging for defenders to keep pace. This trend is not limited to standalone attacks; AI is also being integrated into malware itself. In a concerning development, ESET researchers have discovered PromptSpy, an Android malware that utilizes generative AI to interpret user interface elements and adapt across devices without relying on hardcoded behavior.
The integration of AI in malware execution flows demonstrates the potential for increased flexibility in future threats. While still rare, this capability has significant implications for security measures, as attackers can now evade detection more effectively. The inclusion of guardrails against abuse in large language models (LLMs) may slow down the adoption of such techniques, but it is unlikely to halt them entirely.
ESET’s H1 2026 Threat Report highlights another concerning trend: the increasing use of AI-themed social engineering tactics. ClickFix, a technique that leverages fake error messages, has expanded beyond CAPTCHA prompts to include AI-themed help pages, browser extensions, and cloud authentication scenarios. This tactic has seen a significant surge in detections between H2 2025 and H1 2026, indicating sustained activity and adaptation by attackers.
Phishing campaigns are also evolving in response to user behavior, with QR code phishing reaching record levels in ESET telemetry. Attackers are embedding malicious links in QR codes to bypass cursory inspection and shift user interaction to mobile devices, where they can exploit the implicit trust people place in these black-and-white squares.
Ransomware activity remains a persistent threat, with continued use of EDR killers – tools designed to disable security software during attacks. ESET Research has documented over 100 EDR killers used in the wild, with new variants appearing regularly. While a declining share of victims are choosing to pay ransoms, suggesting some progress in mitigation and response measures, this remains a concerning trend that demands attention.
As the threat landscape continues to evolve, it is essential for individuals and organizations to stay informed about the latest attack techniques. The ESET Threat Report H1 2026 provides valuable insights into the trends and tactics employed by cyber attackers. By understanding these threats, we can better prepare ourselves against them and mitigate their impact.
To protect yourself from AI-powered attacks, focus on staying vigilant with your security software and regularly updating it to ensure you have the latest protections. Be cautious when interacting with unfamiliar links or QR codes, and never rely solely on implicit trust in seemingly innocuous symbols. By taking these steps, you can reduce your risk of falling victim to the increasingly sophisticated threats lurking online.
Source: Bleeping Computer — 2026-07-31