ProBackend
ai malware warfare
2 hours ago6 min read

AI Cybersecurity Threats 2026: How Attackers Scale Through AI and Adaptation

Analysis of how cybercriminals leveraged AI and adaptation to scale attacks in H1 2026. ESET tracks rise in malicious AI skills, PromptSpy, ClickFix evolution, quishing trends, and EDR killers.

AI Cybersecurity Threats 2026: The Adaptation Advantage

The first half of 2026 didn't bring entirely new attack methodologies. What it brought was something arguably more dangerous: attackers getting really, really good at adapting what already works. Rather than chasing the next big breakthrough, threat actors focused on improving efficiency and scalability across their operations. They're taking established techniques and bending them to new platforms, technologies, and user behaviors. The result? A faster, more resilient, and more annoying adversary.

Artificial intelligence sits at the center of this shift. It's not just a tool anymore—it's infrastructure. And attackers know it.

The AI Skills Explosion: Nearly 900,000 Components Analyzed

ESET researchers analyzed nearly 900,000 AI skills in the first half of 2026. For those unfamiliar with the term, "AI skills" are small, functional components used by AI agents to perform specific tasks. Think of them as building blocks—some legitimate, some not. The sheer volume here is staggering. ESET identified tens of thousands of suspicious skills and thousands that were outright malicious.

What makes this particularly troubling isn't just the numbers. It's the velocity. As ESET itself noted, the number of AI skills is growing rapidly "as we speak." Every new skill expands the attack surface. Every malicious skill lowers the barrier for someone who wants to weaponize AI without building it from scratch.

The ecosystem is self-reinforcing. More skills mean more exploitation possibilities. More exploitation possibilities mean more incentive to create or steal skills. It's an arms race, and right now, attackers are winning on volume.

PromptSpy: When Malware Calls on Generative AI

PromptSpy represents something genuinely new in the Android malware landscape. ESET identified it as the first known Android malware to incorporate generative AI directly into its execution flow. Here's what that means in practice: the malware leverages Google's Gemini to interpret user interface elements on the fly.

Why does that matter? Because hardcoded malware is brittle. It breaks when screen resolutions change, when apps update their layouts, when devices vary. PromptSpy doesn't care. It asks Gemini to look at the UI, figure out what's where, and adapt. No hardcoded behavior. No static patterns to signature-based detection can latch onto.

It's still rare. Guardrails built into large language models have slowed adoption—attackers can't just freely abuse any AI they want. But PromptSpy proves the concept works. And when the concept works, someone will figure out how to work around the guardrails. The question isn't whether this technique spreads. It's how quickly.

ClickFix's Evolution: From Fake CAPTCHAs to AI Deception

ClickFix started as a relatively simple social engineering trick: fake error messages that tricked users into running malicious commands in their terminal. By H1 2026, it had evolved into something far more sophisticated.

ESET tracked ClickFix expanding beyond those original fake CAPTCHA prompts into AI-themed help pages, suspicious browser extensions, and even cloud authentication scenarios. The common thread? Exploiting the implicit trust users place in interfaces that look legitimate.

The numbers tell the story. ESET detections of ClickFix more than doubled between the second half of 2025 and the first half of 2026. That's not a blip. That's sustained, growing activity. The technique is clearly working, and attackers are iterating on it faster than defenders can patch the human psychology angle.

For deeper technical analysis of how ClickFix evades defenses, see Why ClickFix Bypasses AI Cybersecurity Defenses.

Quishing at Record Levels: QR Codes as Attack Vectors

QR code phishing—quishing, for short—hit record levels in ESET's H1 2026 telemetry. Attackers embed malicious links inside QR codes and rely on a simple but effective psychological shortcut: people trust those black-and-white squares.

The strategy serves two purposes. First, it bypasses the cursory inspection most users give to links. You can't hover over a QR code to check the destination. Second, it shifts interaction to mobile devices, where security controls are often looser and user attention is thinner.

It's low effort, high reward. And it's working. The record numbers ESET reported aren't theoretical—they're real compromises, real data theft, real financial damage. Until users develop the same skepticism toward QR codes that they've developed toward suspicious email attachments, quishing will remain a top-tier vector.

EDR Killers: The Ransomware Playbook Gets Hardened

Ransomware didn't slow down in H1 2026. If anything, it got more sophisticated. A key part of that evolution: the continued deployment of EDR killers—tools specifically designed to disable endpoint detection and response security software before ransomware strikes.

ESET Research has documented over 100 EDR killers in active use, with new variants appearing regularly. This isn't random experimentation. This is a mature, evolving toolkit. Every new variant represents an attempt to stay one step ahead of security teams.

There's a silver lining, though faint. Data from multiple sources suggests a declining share of victims are choosing to pay ransoms. That's progress, however incremental. Better incident response, improved backups, and growing organizational resilience are all contributing. But don't mistake that for safety. The underlying threat landscape remains aggressive and adaptive.

Defending Against 2026 Threats: A Complete Security Practices Guide

Securing organizations against these evolving threats requires more than just deploying the latest antivirus. It demands a comprehensive, multi-layered approach. Here's what security teams should prioritize:

Monitor AI Skill Ecosystems. The 900,000 AI skills ESET analyzed aren't going away. Security teams need visibility into what AI components are being deployed across their environments, especially those that interact with user interfaces or execute commands autonomously.

Treat AI-Integrated Malware as a Growing Category. PromptSpy proves that generative AI can be weaponized inside malware execution flows. Detection strategies that rely on static signatures will miss adaptive threats. Behavioral analysis and anomaly detection become essential.

Educate Users on Quishing. QR codes are everywhere now—in storefronts, on business cards, in public spaces. Security awareness training needs to cover QR code risks specifically. Users should question the source before scanning, just as they would before clicking an unfamiliar link.

Update EDR Strategies. With over 100 EDR killers in circulation, relying on a single endpoint protection tool is insufficient. Defense-in-depth, network segmentation, and least-privilege access controls remain the best insurance against ransomware, regardless of whether the EDR agent is running.

Embrace Proactive Threat Intelligence. The rapid evolution of AI-powered attacks means reactive security is already behind. Organizations should integrate real-time threat intelligence feeds, subscribe to industry reports like ESET's H1 2026 Threat Report, and stay informed about emerging techniques before they become mainstream.

The ai cybersecurity threats landscape in 2026 isn't defined by any single breakthrough. It's defined by accumulation, adaptation, and speed. Attackers who can iterate quickly, leverage existing tools intelligently, and exploit human psychology will continue to outpace defenders who rely on static, signature-based approaches. The organizations that survive will be those that treat adaptation as a constant, not an exception.

Source

ESET's H1 2026 Threat Report, published July 31, 2026, provides the foundational data for this analysis. Key findings include the analysis of nearly 900,000 AI skills, identification of PromptSpy as the first Android malware using generative AI (Google's Gemini) in its execution flow, ClickFix detections more than doubling between H2 2025 and H1 2026, record quishing levels, and documentation of over 100 EDR killers in active use. The report is sponsored by ESET and independently reported by BleepingComputer.

ai cybersecurity threats

More blogs