Threat Report H1 2026: attackers adapt their methods to new technologies

Analytics2026-07-17, 15:17
ESET published Threat Report H1 2026, highlighting five key trends shaping the cyberthreat landscape during the first half of 2026:
1 AI agents’ “skills” are becoming a rapidly expanding attack surface. ESET analyzed nearly 900,000 AI-agent skills and found more than 25,000 suspicious and 3,000 malicious components. Back in March 2026, the total number of “skills” was just 60,000, with only 600 identified as malicious — the drastic increase occurred in just two months.
2 ClickFix attacks continue to evolve. Attackers are now using fake installation guides for AI tools (AI-fix), spoofed browser extensions (CrashFix), and OAuth-based schemes (ConsentFix) that let them hijack cloud accounts without stealing passwords and often bypass MFA. The number of detected ClickFix campaigns grew by 108% compared to the previous half-year.
3 QR phishing (quishing) has reached record levels. On average, ESET detected about 100,000 such attacks each month, and roughly 11% of all detected phishing emails contained QR codes with malicious content.
4 The first Android malware using AI at runtime has been discovered. PromptSpy calls on Google Gemini during execution to perform user gestures that are difficult to automate with traditional scripts because they depend on specific OS and UI versions.
5 Ransomware operators continue to actively use EDR Killers. ESET documented more than 100 tools designed to disable or evade security solutions, over 60 of which use the BYOVD technique.
One major trend highlighted in the report: attackers adopt new technological capabilities faster than organizations can establish secure usage practices. As a result, the attack surface expands not only through software vulnerabilities but also due to new ways users interact with technology — such as the rapidly proliferating AI tools.
Vendors
Eset
Google
Products
Ai Agents’ Skills
Ai-Fix
Clickfix
Consentfix
Crashfix
Edr Killers
More