Evolving Threat Landscape: Insights from ESET Research’s H1 2026 Report
TL;DR
ESET Research’s analysis highlights a surge in sophisticated cyber threats, including AI-powered malware and advanced phishing techniques in the first half of 2026. The report emphasizes the adaptation of existing tactics rather than the introduction of entirely new methodologies.
Main Analysis
ESET Research’s report for the first half of 2026 reveals ongoing enhancements in the efficiency and scalability of cyberattacks. Cybercriminals have shown a clear propensity to adapt established tactics to exploit new platforms and user behaviors. A notable trend is the increased integration of artificial intelligence in both the capabilities of attackers and the malware being deployed. ESET analyzed nearly 900,000 AI skills, identifying a concerning number of malicious instances that expand the attack surface for potential threats.
One significant development is the identification of PromptSpy, the first Android-based malware utilizing generative AI specifically in its operational workflow. By employing Google’s Gemini, this malware can interpret user interface elements and adjust its behavior dynamically across different devices and environments, surpassing traditional hardcoded methods. Although still in its nascent stage, the use of generative AI in malware indicates an evolving threat landscape that demands closer observation.
Within the realm of social engineering, ESET noted a marked increase in a technique referred to as ClickFix. This strategy has progressed beyond basic fake error messages to include AI-themed help pages and deceptive browser extensions, suggesting that attackers are becoming increasingly innovative in utilizing AI for malicious purposes. The detection of phishing campaigns, specifically the rising use of QR code phishing (or quishing), also indicates an alarming trend, with attackers embedding harmful links within QR codes to exploit user trust.
Defensive Context
Organizations should recognize the implications of these evolving techniques, particularly in sectors heavily reliant on mobile interactions, where QR codes are commonplace. The use of AI in malware represents a significant shift that may challenge existing detection capabilities. Entities utilizing mobile applications or web services, especially in customer-facing roles, must be vigilant against these adaptive threats.
Why This Matters
The surge in AI-integrated malware and advanced phishing tactics highlights a real and present danger for organizations operating online or interfacing with clients via mobile platforms. Industries focusing on digital transactions or user authentication processes are particularly at risk and should remain aware of these evolving tactics.
Indicators of Compromise (IOCs)
The article does not provide specific indicators of compromise to monitor. However, the behaviors associated with the identified malware and phishing tactics can serve as a basis for detection frameworks. Being aware of AI’s role in these attacks may assist organizations in modifying their response strategies accordingly.






