Monday, September 7, 2026

ESET Threat Report H1 2026 Highlights Malicious AI Skills, ClickFix Surge, and EDR Killers

ESET’s H1 2026 threat report shows attackers accelerating the use of familiar playbooks with AI-flavored lures, social engineering, and defense evasion rather than inventing entirely new ones.

The clearest signals are the rise of malicious AI skills, a doubled ClickFix footprint, first-wave AI-powered Android malware, record QR-code phishing, and a growing ecosystem of EDR killers.

That matters because AI agents access are increasingly allowed to browse, execute commands, access files, and interact with third-party services, which turns small “skills” into high-risk supply-chain components.

The report highlights behaviors such as credential loading, obfuscation, command execution, and tool downloading as warning signs that can mask abuse inside otherwise useful automation.

For defenders, the key shift is that compromise is no longer limited to prompt injection; it can now land in the agent’s extensions, scripts, and dependencies.

ClickFix continues to be one of the most effective initial-access patterns because it exploits urgency and user trust.

ESET says detections under HTMLFakeCaptcha grew 108 percent between H2 2025 and H1 2026, with the technique moving beyond fake CAPTCHA boxes into AI-themed help pages, browser environments, workspace workflows, and even macOS lures.

ESET Researchers said that, nearly 900,000 AI skills from public repositories and found 25,000 suspicious and more than 3,000 outright malicious entries.


QRCode/Phishing detection trend (Source : ESET).
QRCode/Phishing detection trend (Source : ESET).

The newer AI-fix variant is especially telling: attackers reuse legitimate AI branding to make fake troubleshooting steps look authoritative, while the actual execution chain remains the same old copy-paste-and-run payload path.

ESET Threat Report H1 2026

CrashFix and ConsentFix show the same trend in different settings, using browser errors and OAuth token theft to hijack sessions without traditional credential capture.

PromptSpy stands out as the first known Android malware to use generative AI at runtime, according to ESET. It behaves like a remote-access trojan, but it also calls Gemini to interpret on-screen UI elements and decide which gestures to execute, helping the malware adapt across devices without relying on hardcoded taps.

That is a meaningful evolution because Android UI automation has always been brittle, and the use of LLMs can make malware more resilient to interface changes.

Top 10 malware detections in H1 2026 (Source : ESET).
Top 10 malware detections in H1 2026 (Source : ESET).

Even if current guardrails slow adoption, the report suggests this design pattern could become attractive for thin-client malware that offloads logic to AI services.

Ransomware crews still rely heavily on EDR killers to blind defenses before encrypting systems. ESET says it tracks more than 100 such tools, with BYOVD remaining the dominant method because a vulnerable but legitimate driver can terminate protected processes from the kernel.

The report notes more than 60 EDR killers abusing over 40 different drivers, with new variants appearing weekly. That is a strong indicator that defense evasion has become a commodity layer in ransomware operations, not a specialty skill.

Cryptocurrency threat detection trend in H2 2025 and H1 2026 (Source : ESET).
Cryptocurrency threat detection trend in H2 2025 and H1 2026 (Source : ESET).

The operational theme across H1 2026 is adaptation speed. Attackers are packaging old techniques inside newer interfaces, whether that means AI branding, QR codes, browser prompts, or autonomous agent tooling.

For defenders, this reinforces three priorities: inspect AI supply chains, harden user-assisted execution paths, and treat EDR tampering as a core ransomware signal rather than a post-compromise afterthought.

Relevant related details in the report include QR-code phishing reaching record levels, continued ransomware pressure despite lower ransom payment rates, and the emergence of additional defense-evasion tooling used in active intrusions.

Stop Accepting SLAs Written for 2019 SOCs – Here’s the 2026 AI SLA Vendor Checklist – Download Free AI SOC SLA Guide

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

PoisonedRefresh Malware Backdoors F5 BIG-IP Servers With Memory-Only PHP Web Shells

A sophisticated Linux implant linked to compromised F5 BIG-IP...

Natural Resources Wales Data Breach Exposes Sensitive Employee Diversity Data

Natural Resources Wales (NRW) has reported a personal data...

ConnectWise ScreenConnect Remote Access Flaw Impacts Guest File Transfer Sessions

ConnectWise has announced a security issue affecting file transfer...

Global Phishing Campaign Abuses Google Infrastructure to Evade Security and Steal Credentials

A large-scale phishing operation is abusing trusted Google services...

OpenAI Commits $1 Billion in Daybreak AI Cyber Tools to Protect Critical Infrastructure

OpenAI has announced a $1 billion global commitment to...

Tengu Mirai-Style Linux Bot Hides as Kernel Worker to Launch DDoS and Proxy Attacks

A newly analyzed Linux malware sample, dubbed Tengu, combines...

The 12 Best Wireless / Wi-Fi Security Solutions, Compared and Priced

Best value overall: Ubiquiti. Published hardware pricing, no mandatory...

The 12 Best Network Sandboxing Solutions, Compared and Priced

Best value overall: ANY.RUN. It publishes its pricing, offers...

Related Articles

Recent News