Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2155+ Articles
156+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. ESET Threat Report: Malicious AI Skills and Adaptable Malware on the Rise
ESET Threat Report: Malicious AI Skills and Adaptable Malware on the Rise
NEWS

ESET Threat Report: Malicious AI Skills and Adaptable Malware on the Rise

ESET's mid-2026 threat report reveals attackers adapting established techniques to AI platforms — deploying malicious AI skills, AI-assisted malware, record quishing activity, and ransomware tools engineered to defeat security software.

Dylan H.

News Desk

August 1, 2026
4 min read

ESET's mid-2026 threat report paints a clear picture: threat actors are not abandoning proven attack techniques — they are adapting them to new platforms and user habits with remarkable speed. The report, released July 31, 2026, highlights four converging trends that are reshaping the malware landscape.

Malicious AI Skills Take Center Stage

The most notable emerging threat in the report is the weaponization of AI assistant plugins and skills. As enterprises and consumers increasingly rely on AI platforms — from Microsoft Copilot integrations to standalone AI assistants — attackers have identified the skill/plugin ecosystem as a new infection vector.

Malicious AI skills mimic legitimate productivity tools (file organizers, email drafters, code generators) while secretly:

  • Exfiltrating sensitive data entered into AI prompts
  • Harvesting credentials from connected applications
  • Using AI platform permissions to access integrated cloud services
  • Persisting through the AI platform's update mechanism

"The abuse of AI platforms represents a natural evolution," ESET researchers noted. "Attackers go where users are spending time and where trust is high."

AI-Assisted Malware Development Accelerates

Beyond targeting AI platforms, adversaries are using AI tools to accelerate their own development pipelines. ESET observed a measurable increase in malware samples showing characteristics of AI-generated code: consistent formatting, well-commented logic, and rapid variant production that suggests automated generation.

The practical impact: the barrier to entry for capable malware development continues to fall, and the volume of unique samples requiring analyst review continues to climb.

ClickFix Attacks Reach New Audiences

The ClickFix social engineering technique — which tricks victims into executing malicious commands by presenting fake browser or application errors — remains extremely active. ESET's telemetry shows ClickFix campaigns broadening their target base beyond IT-savvy users:

  • Fake CAPTCHA pages presenting PowerShell execution instructions
  • Bogus document rendering errors on cloud-hosted files (OneDrive, Google Docs)
  • Impersonated IT support portals instructing users to "fix" issues by running scripts
  • QR code lures on physical media left in public spaces, pointing to ClickFix pages

The technique's persistence reflects a fundamental truth: social engineering that instructs users to act — rather than exploiting software — bypasses most technical controls.

Record Quishing Activity

Quishing (QR code phishing) hit record levels in the first half of 2026. Attackers favor QR codes because:

AdvantageDetail
Email filter bypassQR codes are images — no embedded URLs for scanners to inspect
Mobile targetingScanning shifts the attack to personal devices with fewer controls
Fake legitimacyQR codes on physical objects (parking meters, restaurant menus, conference badges) appear credible
MFA bypass potentialQR-based "re-authentication" lures capture real-time credentials

ESET observed quishing campaigns impersonating Microsoft, DocuSign, and parcel delivery services at scale.

Ransomware Tools Engineered to Disable Security Software

The report documents a troubling refinement in ransomware tooling: purpose-built components designed to identify and terminate security software before encryption begins. These tools — often deployed via bring-your-own-vulnerable-driver (BYOVD) techniques — target EDR and antivirus solutions at the kernel level.

Notable observed capabilities include:

  • Driver-based EDR termination using signed-but-vulnerable kernel drivers
  • Process injection to hollow legitimate system processes and hide ransomware activity
  • Shadow copy deletion executed via COM object hijacking to evade detection by VSS-monitoring tools
  • Selective encryption targeting high-value file types while avoiding OS files to maintain system function

Recommendations

Organizations should address each of these trends directly:

AI skill hygiene: Audit installed AI plugins and skills across your environment. Establish an allowlist policy for AI integrations and review permissions granted to each skill.

ClickFix defense: User awareness training remains the primary control. Reinforce that IT support will never instruct users to run PowerShell commands from browser pop-ups. Disable PowerShell for standard users where possible.

Quishing protection: Deploy mobile threat defense (MTD) solutions that inspect URLs accessed from QR scans on managed devices. Train users to scrutinize QR code destinations before entering credentials.

EDR resilience: Ensure your EDR platform uses tamper protection and kernel-level self-defense. Monitor for BYOVD activity — legitimate driver loads at unusual times from non-standard paths.

Ransomware preparation: Maintain offline, immutable backups tested for recovery. Segment networks to limit ransomware spread and validate that shadow copy protection is monitored.

Source

  • ESET Threat Report — BleepingComputer coverage
#Malware#AI#Ransomware#ClickFix#Threat Intelligence#ESET

Related Articles

ESET H1 2026: Malicious AI Skills Surge to 3,000+ as ClickFix and Quishing Break Records

ESET's H1 2026 threat report reveals 3,000+ malicious AI skills in open repositories, a 108% ClickFix surge, record quishing activity, and the first Android malware to use generative AI at runtime.

6 min read

LeakNet Ransomware Weaponizes ClickFix and Deno Runtime for Stealthy Corporate Attacks

The LeakNet ransomware gang is using ClickFix social engineering for initial access and a Deno-based malware loader to execute fileless payloads from...

6 min read

Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge

Cisco Talos has detailed msaRAT, a Rust-based implant used by the Chaos ransomware group that hides its command-and-control channel inside the victim's own browser — using headless Chrome or Edge, WebRTC, and Twilio TURN to make C2 traffic appear as legitimate browser activity.

6 min read
Back to all News