Cybersecurity in the first half of 2026 has faced an unprecedented challenge: attackers are not only scaling up their operations but are also radically changing their nature by integrating artificial intelligence directly into the structure of malware. Experts at ESET, after analyzing nearly 900,000 AI skills — functional components for artificial intelligence agents — identified tens of thousands of suspicious and thousands of overtly malicious instances. Their numbers are growing continuously, opening up new attack vectors for hackers.
Malicious AI: From Theory to Practice
Artificial intelligence has ceased to be merely a tool for creating phishing emails and is now being embedded directly into malicious software. A striking example is the recently discovered Android Trojan named PromptSpy. This threat uses generative AI in real-time, interacting with the Google Gemini model to analyze user interface elements.
Unlike traditional viruses, PromptSpy does not rely on hard-coded behavior. It can adapt to various devices and operating environments, making its detection and blocking significantly more difficult. This demonstrates how the flexibility of AI increases the effectiveness of future cyber threats.
The Evolution of Social Engineering and Phishing
Methods of deceiving users have also undergone significant changes. The social engineering technique ClickFix, previously known for fake error messages, has moved beyond fake CAPTCHA requests. It now extends to AI-related technical support pages, browser extensions, and cloud authentication scenarios. According to ESET, detections of this attack vector more than doubled from the end of 2025 to mid-2026.
Particular attention should be paid to the phenomenon of "quishing" — phishing via QR codes. Attackers have achieved record-breaking results here by embedding malicious links into black-and-white squares. This allows them to bypass superficial link inspections on PCs and redirect victims to mobile devices, exploiting users' implicit trust in QR technology.
Fighting Ransomware: New Tools and Old Methods
Ransomware activity shows no signs of slowing down. To successfully encrypt data, hackers are actively using EDR-killers — tools designed to disable security systems (EDR) during an attack. ESET researchers have documented more than 100 such tools used in real-world scenarios, with new variants appearing regularly.
However, there is a positive trend: data shows that fewer victims are agreeing to pay the ransom. This may indicate that mitigation measures and user training are beginning to yield results, forcing cybercriminals to seek new vulnerabilities.