VYPR
researchPublished Jul 31, 2026· 1 source

ESET Report: AI Fuels Evolving Cybercrime with Adaptable Malware and Sophisticated Scams

ESET's latest threat report reveals attackers are increasingly leveraging AI for malicious purposes, developing adaptable malware and sophisticated social engineering tactics.

The first half of 2026 has seen cybercriminals significantly enhance the efficiency and scalability of their operations, not by inventing entirely new methods, but by rapidly adapting existing techniques to new technologies and user behaviors. A key driver of this evolution is the growing role of artificial intelligence. ESET researchers analyzed nearly 900,000 AI skills – small functional components used by AI agents – and identified tens of thousands of suspicious and thousands of outright malicious instances, highlighting the expanding attack surface within the burgeoning AI ecosystem.

Beyond AI skills, the integration of AI directly into malware is becoming a reality. Following the emergence of the first AI-powered ransomware in 2025, ESET researchers have identified PromptSpy, the first known Android malware to incorporate generative AI into its execution flow. This malware utilizes Google's Gemini to interpret user interface elements, allowing it to adapt across different devices and environments without relying on hardcoded behaviors. While still a rare phenomenon, PromptSpy serves as a potent illustration of the potential for increased flexibility and evasion in future mobile threats, though built-in guardrails within large language models are likely slowing widespread adoption.

Trust, a fundamental human asset, is increasingly being weaponized by cybercriminals. ESET's H1 2026 Threat Report details how attackers are exploiting AI, social engineering, and ransomware innovations to scale their campaigns and bypass security measures. One such evolving social engineering technique is "ClickFix," which has expanded beyond fake CAPTCHA prompts to include AI-themed help pages, browser extensions, and cloud authentication scenarios. ESET detections of this vector more than doubled between the second half of 2025 and the first half of 2026, indicating sustained and adaptive malicious activity.

Phishing campaigns are also adapting to user behaviors, with QR code phishing, or "quishing," reaching record levels in ESET's telemetry. Attackers embed malicious links within QR codes to bypass initial scrutiny and redirect user interaction to mobile devices, exploiting the implicit trust many users place in these ubiquitous black-and-white squares. This tactic allows them to circumvent traditional email-based defenses and target users on their more frequently used mobile platforms.

Ransomware activity shows no signs of abating, with attackers continuing to employ EDR (Endpoint Detection and Response) killers – tools specifically designed to disable security software during attacks. ESET has documented over 100 unique EDR killers in the wild, with new variants emerging regularly. Despite this persistent threat, data from multiple sources suggests a declining share of victims are choosing to pay ransoms, indicating some progress in organizational mitigation and response strategies.

The report underscores a broader trend of cybercrime maturing into a sophisticated, subscription-based ecosystem. Attack capabilities, malware, and infrastructure are offered on demand, making cybercrime more efficient, automated, and consequently, harder to combat. This commercialization, fueled by advancements in AI and the rapid adaptation of existing attack vectors, presents a significant and evolving challenge for cybersecurity professionals worldwide.

Synthesized by Vypr AI