ESET tracks rise in malicious AI skills and adaptable malware
ESET's H1 2026 Threat Report finds tens of thousands of malicious AI skills among nearly 900,000 analyzed, documents PromptSpy as the first Android malware using generative AI, and shows ClickFix and QR-code phishing detections doubling.
Intelligence analysis by Llama

ESET's H1 2026 Threat Report shows attackers scaling with AI rather than reinventing tactics: nearly 900,000 AI skills reviewed, thousands flagged as malicious, the first Android malware using Google's Gemini to adapt in real time, and surging ClickFix and QR-code phishing campaigns. Ransomware operators continue deploying EDR killers, though ransom payment rates are declining.
Imagine app store plugins that tell a robot helper what to do. ESET checked almost a million of them and found lots that are sneaky or mean. They also caught the first phone virus that asks Google's Gemini AI for help on what to click next, like a burglar asking a friend for directions instead of using a map.
Analysis
PromptSpy and the runtime-LLM malware era
ESET's identification of PromptSpy marks a practical milestone in the AI-abuse conversation. The malware, observed on Android, leans on Google's Gemini to interpret on-screen UI elements and adapt across devices and environments without the hardcoded behaviour that traditionally fingerprints mobile malware. For years, defenders have relied on the assumption that malware needs stable, repeatable code paths; a sample that asks an LLM what to click next breaks that assumption. ESET notes the variant is still rare and that built-in LLM guardrails are likely slowing widespread adoption. That caveat matters, but the direction of travel is clear: once one family demonstrates the technique, copycats tend to follow within months.
AI skills as a new supply chain
The headline number - roughly 900,000 AI skills reviewed in H1 2026, with tens of thousands rated suspicious and thousands outright malicious - reframes the agent ecosystem as an emerging software supply chain. AI skills are the small functional modules that AI agents invoke to perform tasks, and ESET's wording that the count is growing "as we speak" points to an attack surface that is expanding faster than any individual vendor can curate. The parallel with browser extensions, npm packages, and mobile SDKs is hard to miss: every new marketplace for reusable code eventually becomes a target for poisoning, and the defenders who named those earlier battles are now applying familiar triage playbooks to skill repositories.
Social engineering still does the heavy lifting
The report's non-AI findings are equally consequential. ClickFix detections more than doubled between H2 2025 and H1 2026 as the lure spread from fake CAPTCHAs into AI-themed help pages, browser extensions, and cloud authentication prompts. QR-code phishing reached record telemetry levels, with attackers leveraging the implicit trust users place in the codes to shift interaction onto mobile devices, where corporate protections are thinner. Against that backdrop, the noted decline in ransom payment rates is a small but real signal that operational pressure on victims and improved backup hygiene are starting to bite, even as ESET documents more than 100 distinct EDR killers in active use. The story is not that ransomware is retreating; it is that the economics of paying are shifting.
Key points
- ESET analyzed nearly 900,000 AI skills in H1 2026, flagging tens of thousands as suspicious and thousands as malicious
- PromptSpy is identified as the first known Android malware to use generative AI (Google's Gemini) in its execution flow
- ClickFix detections more than doubled between H2 2025 and H1 2026, expanding beyond fake CAPTCHAs into AI-themed lures
- QR-code phishing reached record levels in ESET telemetry as attackers exploit implicit user trust and shift targets to mobile
- ESET has documented over 100 EDR killers in the wild, even as the share of ransomware victims paying declines
ESET highlights a declining share of ransomware victims choosing to pay, suggesting backup hygiene, negotiation pressure, and law-enforcement disruption are beginning to shift attacker economics. Combined with LLM guardrails slowing the spread of PromptSpy-style malware, the report points to several defensive measures that are already bending the curve.
The same report warns that an expanding AI-skill marketplace is multiplying attacker entry points faster than curation can keep up, while ClickFix and QR-code phishing doubled in a single half-year. If defenders cannot meaningfully inspect AI-skill repositories and continue to lose the social-engineering battle on mobile, runtime-LLM malware could graduate from rarity to routine within a reporting cycle.



