The ESET Threat Report H1 2026: Attackers Master AI and Evolve Tactics for Scaled Cybercrime

The first half of 2026 has underscored a concerning trend in the cyber threat landscape: attackers are not necessarily inventing entirely new methodologies, but rather demonstrating remarkable agility in adapting and scaling established techniques across emerging platforms, sophisticated technologies, and evolving user behaviors. This period, as meticulously documented by ESET’s latest threat intelligence report, reveals a sophisticated criminal ecosystem that leverages ingenuity and rapid adaptation to maximize efficiency and impact. The report, which analyzes data from the first six months of 2026, highlights the pervasive influence of artificial intelligence, the persistent threat of social engineering, and the relentless evolution of ransomware.

The Ascendancy of AI in Cybercriminal Toolkits

Artificial intelligence, once a frontier for legitimate technological advancement, is now a significant force within the cybercriminal domain. ESET’s research has identified a burgeoning ecosystem of AI skills—discrete functional components that power AI agents—with a substantial portion exhibiting malicious intent. In H1 2026, ESET analysts scrutinized nearly 900,000 AI skills, uncovering tens of thousands of suspicious instances and thousands classified as outright malicious. This rapid proliferation of AI components is not only expanding the attack surface but also offering attackers more dynamic and adaptable tools.

The integration of AI into malware itself represents a particularly alarming development. Following the emergence of the first AI-powered ransomware in 2025, ESET researchers have now identified PromptSpy, a significant milestone as the first known Android malware to incorporate generative AI directly into its operational workflow. PromptSpy’s sophisticated functionality allows it to leverage AI, specifically Google’s Gemini model, to interpret user interface elements. This enables the malware to adapt its behavior dynamically across different devices and environments, circumventing the limitations of hardcoded instructions. While the widespread adoption of such AI-infused malware is still nascent, likely due to built-in safeguards within large language models (LLMs) that aim to prevent abuse, PromptSpy serves as a potent indicator of the increased flexibility and evasiveness future mobile threats could possess.

Social Engineering: Trust as the New Exploitable Commodity

The ESET H1 2026 Threat Report places a significant emphasis on how cybercriminals are increasingly exploiting trust as a primary vector for their attacks. This is most evident in the evolution of social engineering tactics. ClickFix, a technique that relies on deceptive error messages to manipulate users, has demonstrated remarkable adaptability. It has expanded beyond its initial manifestations in fake CAPTCHA prompts to encompass AI-themed help pages, malicious browser extensions, and sophisticated cloud authentication scenarios. ESET observed a more than doubling of detections for this specific vector between the second half of 2025 and the first half of 2026, indicating sustained and evolving malicious activity.

Furthermore, phishing campaigns are rapidly responding to changing user behaviors. QR code phishing, colloquially known as "quishing," has reached unprecedented levels according to ESET telemetry. Attackers are embedding malicious links within QR codes, a tactic that effectively bypasses traditional security checks and shifts user interaction to mobile devices. This strategy exploits the implicit trust many users place in the ubiquitous black-and-white squares, often perceiving them as inherently safe. The visual familiarity and perceived convenience of QR codes have made them a potent tool for luring unsuspecting individuals into compromised websites or fraudulent schemes.

Ransomware’s Enduring Threat and Evolving Defenses

Despite advancements in cybersecurity, ransomware activity has shown no signs of abatement. A critical element in the sustained effectiveness of ransomware attacks is the continued and widespread use of EDR killers. These are specialized tools designed to disable Endpoint Detection and Response (EDR) security software, effectively blinding defenses before or during an attack. ESET Research has documented over 100 distinct EDR killers deployed in the wild, with new variants emerging with alarming regularity, demonstrating the ongoing arms race between attackers and defenders.

However, the report also points to a glimmer of progress in the fight against ransomware. Data from multiple sources indicates a declining proportion of victims opting to pay ransoms. This trend suggests a growing confidence in mitigation and response strategies, potentially due to improved incident response capabilities, more robust backup solutions, and a greater understanding of the risks associated with paying ransoms, including the possibility of future attacks. This shift in victim behavior, while not eliminating the threat, signifies a crucial step towards disrupting the financial incentives that fuel ransomware operations.

A Deeper Dive into the H1 2026 Threat Landscape

The ESET H1 2026 Threat Report, available for download, provides an in-depth analysis of the evolving threat landscape. It delves into the intricate details of how attackers are leveraging AI, social engineering, and ransomware innovations to achieve greater scale and evade detection. The report serves as a vital resource for businesses and individuals seeking to understand and counter the sophisticated threats of the current digital era.

Key Findings from the ESET H1 2026 Threat Report:

  • AI-Driven Attacks: The report quantifies the significant presence of malicious AI skills and highlights the emergence of AI-powered malware, such as PromptSpy, which exhibits unprecedented adaptability.
  • Sophisticated Social Engineering: The expansion of ClickFix and the record-breaking prevalence of quishing demonstrate attackers’ ability to exploit user psychology and trust across various digital touchpoints.
  • Ransomware Resilience: The continued use of EDR killers underscores the persistent threat of ransomware, while a declining ransom payment rate suggests progress in defensive measures.
  • Platform Adaptation: Attackers are effectively migrating established techniques to new platforms and technologies, including AI agents and cloud environments, broadening their potential reach.
  • Evolving User Behavior Exploitation: The adoption of tactics like quishing directly responds to and exploits how users interact with technology on a daily basis.

Implications for Cybersecurity Strategy

The findings from ESET’s H1 2026 Threat Report have profound implications for cybersecurity strategies moving forward. The increasing reliance on AI by attackers necessitates a proactive approach to AI security. This includes not only developing AI-powered defense mechanisms but also understanding the potential vulnerabilities introduced by AI tools themselves. Organizations must invest in robust AI security solutions that can detect and neutralize AI-driven threats, and also establish clear guidelines for the ethical and secure development and deployment of AI within their own operations.

The continued success of social engineering tactics like quishing and ClickFix highlights the enduring importance of human-centric security. Comprehensive and regular security awareness training for employees remains a critical defense layer. This training must evolve to address the latest social engineering ploys, emphasizing critical thinking and skepticism towards unsolicited communications and seemingly innocuous digital elements like QR codes.

The persistent threat of ransomware, coupled with the deployment of EDR killers, underscores the need for multi-layered security architectures. Organizations must ensure they have robust endpoint protection, advanced threat detection capabilities, and well-rehearsed incident response plans. The declining trend in ransom payments is encouraging, but it should not lead to complacency. Continuous improvement in backup and recovery strategies, along with a firm stance against paying ransoms, are essential to disincentivize attackers.

The agility of attackers in adapting existing techniques to new platforms is a stark reminder that cybersecurity is not a static discipline. Continuous monitoring, threat intelligence gathering, and a willingness to adapt security postures are paramount. The lessons from H1 2026 are clear: the future of cybercrime is increasingly intelligent, adaptive, and driven by the exploitation of evolving digital landscapes and human trust. Staying ahead requires a commitment to innovation, education, and a vigilant, multi-faceted defense.


This article was sponsored and written by ESET, based on their H1 2026 Threat Report. For more detailed information on the latest attack techniques and comprehensive analysis, readers are encouraged to download the full report.

Related Posts

Google Chrome to Block Malicious Extensions from Hijacking User Settings

Google is actively developing a significant new security enhancement for its Chrome browser designed to neutralize a persistent threat vector: malicious extensions that exploit enterprise policy mechanisms to hijack user…

U.S. Water Utilities Face Escalating Cyber Threat as CISA Warns of Targeted PLC Attacks

The United States Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a significant surge in cyberattacks specifically targeting internet-exposed programmable logic controllers (PLCs) within the nation’s…

Leave a Reply

Your email address will not be published. Required fields are marked *

You Missed

The Enduring Mystery: Fourteen Years After Kayla Berg Vanished in Central Wisconsin

The Enduring Mystery: Fourteen Years After Kayla Berg Vanished in Central Wisconsin

Silent Hill Townfall CRTV Gadget Development and the Evolution of the Psychological Horror Franchise

Silent Hill Townfall CRTV Gadget Development and the Evolution of the Psychological Horror Franchise

China’s Dongfang Suanxin Challenges NVIDIA Dominance with High-Bandwidth 14nm DF2000 Chips and TY64 SuperNodes

  • By admin
  • August 2, 2026
  • 3 views
China’s Dongfang Suanxin Challenges NVIDIA Dominance with High-Bandwidth 14nm DF2000 Chips and TY64 SuperNodes

Apple’s Siri AI Upgrade Could See Paywalled Limits, Signals Outgoing CEO Tim Cook in Final Earnings Call.

Apple’s Siri AI Upgrade Could See Paywalled Limits, Signals Outgoing CEO Tim Cook in Final Earnings Call.

Google Chrome to Block Malicious Extensions from Hijacking User Settings

Google Chrome to Block Malicious Extensions from Hijacking User Settings

The Enduring Lifespan of the PlayStation 5: Navigating Obsolescence Amidst PS6 Speculation and a Shifting Gaming Landscape

The Enduring Lifespan of the PlayStation 5: Navigating Obsolescence Amidst PS6 Speculation and a Shifting Gaming Landscape