In the fast-evolving theater of global cybersecurity, the first half of 2026 has served as a definitive turning point. According to the latest comprehensive telemetry report from ESET Research, the threat landscape is no longer defined by the invention of exotic, "never-before-seen" malware, but by the relentless, surgical refinement of existing tactics. Cybercriminals are moving away from brute-force disruption toward high-efficiency operations, weaponizing Artificial Intelligence (AI) and social engineering to bypass the modern defenses of enterprises and individuals alike.
As security teams globally struggle to keep pace with the democratization of AI-driven tools, ESET’s findings provide a sobering look at how threat actors are adapting to the post-generative-AI era.
The Main Facts: Efficiency Over Novelty
The core takeaway from ESET’s H1 2026 analysis is the shift toward "operational efficiency." Modern attackers are functioning less like experimental researchers and more like streamlined corporations. They are repurposing proven methods—such as social engineering and credential theft—and scaling them across new platforms and cloud-based technologies.
The most significant headline is the integration of AI into the very fabric of malicious activity. ESET has identified a surge in "AI skills"—functional, often modular code snippets used by AI agents to automate tasks. With nearly 900,000 such skills analyzed in the first six months of the year, ESET identified tens of thousands of suspicious instances and thousands of outright malicious components. This ecosystem is expanding at a breakneck pace, creating an attack surface that is increasingly difficult to monitor.
Chronology: The Escalation of AI-Powered Threats
The timeline of H1 2026 illustrates a clear trajectory of increasing sophistication:
- Q1 2026 (The AI Integration Phase): The industry began to see the widespread deployment of AI agents in phishing campaigns. These agents are no longer just writing emails; they are actively scanning target environments to tailor social engineering lures based on real-time data.
- Late Q1 – Early Q2 2026 (The Rise of PromptSpy): Following the initial emergence of AI-powered ransomware in 2025, researchers documented the discovery of PromptSpy. This marked a milestone as the first Android malware to utilize generative AI (specifically Google’s Gemini) to interpret user interface (UI) elements. By "seeing" the screen, the malware can adapt its behavior dynamically to whatever application it is interacting with, moving beyond static, hardcoded instructions.
- Q2 2026 (The ClickFix Proliferation): The ClickFix technique—which uses deceptive, professional-looking error messages to trick users into executing malicious scripts—underwent a massive expansion. Originally restricted to fake CAPTCHA prompts, it has evolved to mimic cloud authentication portals and AI-themed help pages, leading to a doubling of ESET’s detection metrics in just six months.
Supporting Data: By the Numbers
ESET’s telemetry paints a quantitative picture of a landscape under siege:

- AI Skill Proliferation: Out of 900,000 analyzed AI skills, a statistically significant portion—well into the thousands—are confirmed malicious. These skills are often lightweight and easily injected into legitimate workflows.
- The ClickFix Surge: Detections for ClickFix-based vectors more than doubled between H2 2025 and H1 2026. This data suggests that the "human element" remains the weakest link, as users continue to trust familiar interface designs even when they appear in anomalous contexts.
- Quishing (QR Code Phishing): QR code-based attacks reached record levels in H1 2026. By offloading malicious links to mobile devices, attackers effectively bypass the security stacks installed on traditional desktops, exploiting the inherent trust users place in scanning a quick response code.
- Ransomware Resilience: EDR (Endpoint Detection and Response) killers remain a staple of the ransomware toolkit. ESET has now documented over 100 distinct EDR-killing tools in the wild, indicating that attackers are consistently developing new variants to stay ahead of security patches.
Official Perspectives: Expert Analysis
Jiří Kropáč, a lead threat researcher at ESET, emphasizes that while the potential for AI-powered threats is immense, it is currently moderated by the guardrails built into major LLMs (Large Language Models).
"PromptSpy is a harbinger of the future," Kropáč notes. "It shows that malware no longer needs to be told exactly what to do; it can ‘look’ at the screen, understand the context of the environment, and decide how to proceed. However, the friction imposed by AI providers on generating malicious content is currently the primary barrier preventing a massive explosion of automated, AI-driven malware."
From a defensive standpoint, ESET researchers argue that the decline in ransom payments—a trend noted in multiple industry reports—is a positive sign. It suggests that organizations are becoming more resilient, investing in backups, and adopting more rigorous incident response strategies. The "pay-or-not-pay" dilemma is gradually shifting in favor of resilience, effectively starving the criminal economy of its primary funding source.
Implications: A New Defensive Paradigm
The findings from H1 2026 suggest that the traditional "perimeter-based" security model is effectively dead. As threats move to mobile devices via quishing and cloud environments via AI-powered social engineering, the defensive strategy must evolve to match.
1. The Death of Hardcoded Logic
Malware like PromptSpy renders traditional signature-based detection insufficient. Security vendors must now pivot toward behavioral analysis that focuses on the intent of an application rather than its code structure. If a process is attempting to interpret UI elements or simulate human input in an unauthorized manner, it must be flagged regardless of its pedigree.
2. The Human Firewall
With the rise of sophisticated ClickFix campaigns, employee training must move beyond basic "don’t click on links" advice. Organizations must implement "Zero Trust" interfaces where users are trained to verify every authentication prompt through secondary, out-of-band communication, regardless of how legitimate the browser-based warning appears.

3. The Need for Threat Intelligence
As attackers leverage automated AI skills, organizations cannot rely on manual threat hunting alone. ESET emphasizes that integrating automated threat intelligence feeds—which provide real-time updates on the latest EDR killers and phishing tactics—is no longer a luxury for large enterprises, but a baseline requirement for survival in the current climate.
4. The Future of AI Regulation
The prevalence of malicious AI skills highlights a looming conflict between the democratization of technology and security. As these skills become easier to package and distribute, software platforms will need to implement more robust scanning and verification processes for AI agents, similar to the vetting processes currently used for mobile app stores.
Conclusion: The Road Ahead
The first half of 2026 has proven that cyber-resilience is a moving target. Attackers are clearly betting on the fact that humans will remain the most vulnerable component in the digital chain, and they are using AI to make their deceptions more convincing, more persistent, and more difficult to trace.
However, the trend of decreasing ransom payments offers a glimmer of hope. It indicates that the defensive community is learning. By combining advanced threat intelligence with a shift toward proactive, AI-aware security architectures, organizations can strip away the advantages that malicious actors have gained over the last eighteen months.
As ESET Research continues to monitor the emergence of new AI-driven tools and social engineering techniques, the message remains clear: the era of passive defense is over. To stay ahead, one must anticipate the next adaptation before it becomes a standard, and above all, remain skeptical of the digital environment, even when it appears to be helpful.

