ESET's H1 2026: The Rise of Malicious AI Skills and Adaptable Malware
esetaicybersecurityadaptable malwarepromptspygoogle geminisocial engineeringransomwareedr killersllmsh1 2026cybercrime

ESET's H1 2026: The Rise of Malicious AI Skills and Adaptable Malware

AI in Cybercrime: Why 'Adaptable' is the Word That Matters

Discussions around AI in cybersecurity often swing wildly between optimistic predictions and dire warnings. However, ESET's H1 2026 threat report reveals a different truth: the rise of malicious AI skills. The concern isn't AI fabricating novel attack vectors; it's AI enhancing efficiency, scaling operations, and exacerbating existing vulnerabilities.

Instead of a sudden, dramatic shift, we're witnessing an accelerated evolution—a continuous cycle of adaptation and counter-adaptation—where attackers refine their methods, using AI to adapt faster and strike harder, showcasing the growing sophistication of malicious AI skills. This adaptability is the core challenge that demands our attention.

ESET's H1 2026: Malicious AI Skills Refine Attack Methods

ESET's latest threat landscape overview for the first half of 2026 confirms attackers are becoming more efficient. They are taking established techniques and adapting them to new platforms, technologies, and current user behaviors. The exploitation of trust remains a key asset for them.

What stands out in the report is the sheer volume of AI activity ESET tracked. They analyzed nearly 900,000 "AI skills"—AI agent components. Of these, tens of thousands were suspicious, and thousands were explicitly malicious AI skills. This number is growing rapidly, which points to a growing attack surface for malicious AI skills.

We are also observing AI, and specifically malicious AI skills, appearing directly within malware. The first AI-powered ransomware emerged in 2025. What was once theoretical is now being actively deployed.

Server room infrastructure at risk from malicious AI skills and adaptable malware
Server room infrastructure at risk from malicious AI
Server room: The expanding attack surface.

How AI Makes Old Tricks New Again

This adaptability manifests in several key areas:

Adaptive Malware and Generative AI: We are observing the emergence of Android malware that leverages generative AI in its execution flow. PromptSpy is the first known Android malware to use generative AI in this way. Instead of hardcoding specific UI elements or behaviors, such malware could use models like Google's Gemini to interpret screen content. This would allow it to adapt across diverse devices and environments.

A single malware instance could then understand and interact with a wider range of applications and Android versions without requiring constant updates for minor UI changes, representing a meaningful efficiency gain for attackers.

Social Engineering Evolves: Techniques using fake error messages, known as ClickFix, have expanded considerably. Initially seen with fake CAPTCHA prompts, these now appear in AI-themed help pages, browser extensions, and cloud authentication scenarios. ESET's telemetry indicates that detections of ClickFix more than doubled between H2 2025 and H1 2026. This represents a more convincing and varied iteration of existing social engineering methods, rather than an entirely new type.

QR code phishing, or "quishing," has also reached record levels in ESET's telemetry. Attackers embed malicious links in QR codes. This can bypass the cursory URL inspection many users perform and shifts the interaction to mobile devices, where vigilance may be lower. It's another example of an established tactic made more effective through a change in delivery.

Ransomware and EDR Killers: Ransomware activity persists. Attackers continue to use EDR killers—tools designed to disable security software during an attack. ESET Research has documented over 100 EDR killers in the wild, with new variants appearing regularly. This demonstrates a clear focus on operational resilience for attackers, ensuring payload execution without interruption.

The key point is that AI enhances existing social engineering, malware, and evasion techniques, making them more dynamic, scalable, and harder to detect with static signatures, highlighting the impact of malicious AI skills.

What This Means for Your Defenses

This translates to increased pressure on our defenses: adaptive malware, often driven by malicious AI skills, renders signature-based detection less effective, and faster, more convincing social engineering campaigns elevate user risks.

Despite these challenges, there's a silver lining: ESET notes that guardrails against abuse, integrated into Large Language Models (LLMs), are likely slowing the widespread adoption of malicious AI skills in malware. Major LLM providers are aware of the potential for abuse and are implementing protections, which provides some operational buffer. While not a perfect solution, it meaningfully impedes attackers attempting to directly weaponize these models.

A general observation is that public debate and social sentiment often lag behind these specific findings, indicating a disconnect. The general public, and even parts of the industry, remain focused on hyped or exaggerated notions of AI threats, rather than the practical, incremental ways malicious AI skills are already altering the threat scene. This gap needs to be addressed.

Smartphone targeted by quishing, a social engineering tactic enhanced by malicious AI skills
Smartphone targeted by quishing, a social engineering tactic
Mobile devices: A common target for quishing.

Stopping the AI-Augmented Threat

To counter these developments, our defenses must evolve. The enhanced adaptability of malicious AI skills in AI-augmented attacks means operational security can no longer solely rely on perimeter defenses; assuming compromise is now a baseline. This necessitates a shift towards robust detection and response *within* the network, leveraging advanced EDR and XDR solutions that identify anomalous behavior rather than just known signatures. For instance, an AI-powered malware like PromptSpy, adapting its UI interaction, would bypass traditional signature checks, making behavioral analysis critical.

Beyond technology, user education requires a significant upgrade. Generic advice like 'don't click suspicious links' is increasingly ineffective when malicious AI skills generate highly convincing phishing emails or dynamically adaptive malicious pages. Training must focus on recognizing *patterns of manipulation* and fostering skepticism toward *any* unexpected request for credentials or actions, regardless of apparent legitimacy. Consider how a ClickFix campaign, now appearing in AI-themed help pages, demands a more nuanced user awareness than a simple CAPTCHA prompt.

Furthermore, consistent patching and robust vulnerability management remain foundational. EDR killers, documented by ESET Research, specifically target known weaknesses. Keeping systems updated directly mitigates these prevalent attack vectors, reducing the operational resilience attackers seek.

Finally, for organizations leveraging LLMs internally, a thorough understanding of their guardrails and potential bypass methods is vital. Security must be integrated from the outset in LLM development, acknowledging that while current protections offer a buffer against malicious AI skills, attackers will continuously seek circumvention methods.

The Real AI Challenge

The ESET report underscores that AI's role in cybercrime, particularly the rise of malicious AI skills, is firmly rooted in reality, not speculation. It's about efficiency, scale, and adaptability, as attackers leverage AI to enhance existing methods rather than invent new ones. The true challenge lies in strengthening fundamental security hygiene and adapting defenses to counter these AI-augmented attacks, not in combating a phantom threat. This requires improved detection capabilities, smarter user training, and a consistent focus on foundational security practices.

Daniel Marsh
Daniel Marsh
Former SOC analyst turned security writer. Methodical and evidence-driven, breaks down breaches and vulnerabilities with clarity, not drama.