PromptSpy, ClickFix, and Ransomware: Adaptive Threats in ESET's H1 2026 Threat Report
Explore ESET's H1 2026 Threat Report: PromptSpy Android malware, AI-driven ClickFix attacks, record quishing, and ongoing ransomware in the AI era.
Illustrative image generated with AI
ESET's Threat Report for the first half of 2026, released on July 31, 2026, captures a concerning acceleration in the malicious use of artificial intelligence and social engineering techniques.
The analysis combines telemetry data and research into new malware families, painting a picture where attackers' adaptability is on the rise—but not without obstacles.
The AI Skill Ecosystem: 900,000 Components Under Scrutiny
Over 900,000 skills for AI agents came under ESET's scrutiny during the half-year period.
Tens of thousands appeared suspicious, while a few thousand were confirmed as clearly malicious.
These skills—similar to extensions or plugins—enable agents to interact with services, perform actions, and access data.
Their proliferation, driven by open marketplaces and developer communities, broadens the attack surface in much the same way as mobile apps and browser extensions already have.
The lack of uniform review processes makes it difficult to intercept malicious code before it is distributed.
The potential impact is compounded by the semi-autonomous nature of AI agents, which could execute malicious commands without direct human oversight.
PromptSpy: The First Android Malware Leveraging Gemini
Among the analyzed threats, PromptSpy stands out, identified as the first Android malware to integrate a generative language model—Google Gemini—into its operational cycle.
Instead of relying on predefined command sequences, PromptSpy interprets UI elements in real time.
It observes, understands the context, and decides how to act, adapting to different devices and environments without the need for hardcoded variants.
ESET emphasizes that PromptSpy remains a rare threat.
The guardrails built into language models—prompt filters, code generation restrictions, and operational limits—are slowing the large-scale adoption of this technique.
Generative AI makes malware more flexible, but for now it is not yet uncontrollable.
ClickFix Evolves with AI, and Quishing Hits Record Volumes
Social engineering techniques haven't stood still.
ClickFix, which relies on fake error messages tricking users into executing commands or scripts, has evolved.
It now leverages AI-themed support pages, fake browser extensions, and scenarios mimicking cloud authentication.
ESET detections more than doubled from the second half of 2025 to the first half of 2026.
Phishing via QR codes (quishing) reached record volumes.
Attackers embed malicious links into the codes, shifting the interaction to mobile phones.
Here, security controls are often less stringent and trust in QR codes remains high: the user scans, lands on a fraudulent page, and risks handing over credentials or downloading malware.
Ransomware and EDR Killers: Attacks Persist, but Paying the Ransom Is Less Appealing
Ransomware activity remains at high levels, sustained by an arsenal of evasive tools.
Over 100 EDR killer variants—software designed to disable enterprise security solutions—have been documented by the ESET team, with new versions released regularly.
These tools attempt to neutralize sensors before they can detect data encryption.
There is, however, a counter-trend: the percentage of victims paying the ransom is declining.
This signals concrete progress in incident response capabilities and the adoption of mitigation strategies.
Effective backups, disaster recovery plans, and better preparedness reduce the need to give in to extortion, eroding the economic model on which ransomware depends.
Sources
This article is an original reworking based on the sources below.




