“ESET analyzed nearly 900,000 AI skills — small functional components used by AI agents — and identified tens of thousands of suspicious and thousands of outright malicious instances.” That single tally, drawn from ESET’s H1 2026 Threat Report, frames the central shift: attackers are not just inventing new hacks, they are recombining old ones for a world in which AI components and mobile-first interactions multiply opportunities.
AI skills: scale, suspicious activity, and a growing attack surface
ESET’s analysis of almost 900,000 AI skills in the first half of 2026 found tens of thousands of suspicious and thousands of clearly malicious items. The company says the number of AI skills “is growing rapidly ‘as we speak,’” a phrase ESET uses to describe how quickly this ecosystem is expanding and broadening the potential attack surface. Those skills are small, reusable pieces that AI agents can call on — and at scale they create many new points an adversary can manipulate.
PromptSpy: the first known Android malware to embed generative AI
Shortly after the emergence of the first AI-powered ransomware in 2025, ESET researchers identified PromptSpy, which the report describes as the first known Android malware to use generative AI in its execution flow. PromptSpy leverages Google’s Gemini to interpret user-interface elements and to adapt across devices and environments without relying on hardcoded behavior. ESET notes that while such AI-driven flexibility is still rare today, it illustrates the potential for more adaptable threats — and that guardrails against abuse built into large language models are “likely slowing down the adoption.”
ClickFix and quishing: social engineering migrates to new vectors
Trust is now one of the most valuable assets for cybercriminals, ESET writes, and social engineering techniques are evolving to exploit it. ClickFix — a social engineering technique originally tied to fake CAPTCHA prompts — has expanded into AI-themed help pages, browser extensions, and cloud authentication scenarios. ESET’s detections of this vector more than doubled between H2 2025 and H1 2026, signaling sustained activity and rapid adaptation.
At the same time, QR code phishing, often called “quishing,” reached record levels in ESET telemetry. Attackers are embedding malicious links into QR codes to bypass quick cursory inspection and to shift interaction onto mobile devices, where the implicit trust in the black-and-white squares and the different UX patterns can make malicious links harder to spot.
Ransomware persistence: EDR killers and shifting ransom payments
Ransomware remains an active and adaptive threat, the report shows. ESET Research has documented over 100 EDR killers used in the wild — tools designed to disable endpoint detection and response software during attacks — and new variants continue to appear. That operational focus on eliminating defenses, combined with the other innovations documented in the report, underlines why ransomware actors still cause major disruptions.
At the same time, ESET points to data from multiple sources indicating a declining share of victims are choosing to pay ransoms. That trend suggests some progress in mitigation and incident response, even as the tools and tactics used by attackers remain highly dynamic.
What this means for technologists, end users, and enterprise leaders
- Technologists and security teams: Expect an expanding set of inputs to monitor. The rapid growth in AI skills and the arrival of AI inside malware like PromptSpy mean defenders must adapt detection and behavioral analytics to cover agent components and generative-model interactions, not just traditional binaries and scripts.
- End users and the general public: Social engineering techniques are moving into familiar UI elements and mobile-first behaviors. Users should be wary of AI-branded help pages, unexpected browser extensions, and QR codes that appear in unfamiliar contexts — the report shows attackers exploit implicit trust to shift users onto platforms where cursory checks are less common.
- Enterprise and procurement leaders: The proliferation of EDR killers and adaptive malware underscores the need to evaluate incident response capabilities and to prioritize resilience. The reported decline in ransom payments suggests mitigation and response investments can change outcomes, but the attack surface continues to widen as AI skills multiply.
ESET’s H1 2026 findings paint a picture of incremental but fast-moving change: attackers are repackaging established techniques for a landscape shaped by AI components, mobile interaction patterns, and continued ransomware pressure. The immediate takeaway is not a single novel exploit but a systemic expansion of opportunity — nearly 900,000 AI skills examined, tens of thousands flagged, and the first generations of malware that can call on generative models to adapt in real time. How defenders retool analytics, how organizations harden authentication flows, and whether model-level guardrails remain effective will determine whether that opportunity shrinks or continues to grow “as we speak.”




