Intelligent CISO Issue 101 | Page 32

T provides an overview of the cybersecurity trends observed by ESET Research between December 2025 and May 2026. Drawing on ESET telemetry and threat research, the report examines how attackers are improving the efficiency and scalability of their operations through Artificial Intelligence, evolving phishing techniques and continued ransomware activity.
AI

ESET report examines growing use of AI in cyberattacks capabilities, potentially creating a false sense of protection for users.

The report also identifies significant developments in social engineering. ClickFix campaigns have expanded beyond fake CAPTCHA prompts to include AI-themed support pages, browser extensions and cloud authentication scenarios. ESET says attackers are increasingly exploiting trust in Generative AI by embedding malicious instructions within AI-generated troubleshooting content.
The ESET H1 2026 Threat Report highlights how Artificial Intelligence, social engineering and ransomware are reshaping the threat landscape, with attackers refining established techniques rather than relying on entirely new methods.
he ESET H1 2026 Threat Report

T provides an overview of the cybersecurity trends observed by ESET Research between December 2025 and May 2026. Drawing on ESET telemetry and threat research, the report examines how attackers are improving the efficiency and scalability of their operations through Artificial Intelligence, evolving phishing techniques and continued ransomware activity.

Among the report’ s key findings is the increasing use of Artificial Intelligence by threat actors. ESET analysed nearly 900,000 AI skills – small functional components used by AI agents – and identified tens of thousands of suspicious instances alongside thousands classified as malicious.
Researchers also identified PromptSpy, which ESET describes as the first known Android malware to incorporate Generative AI into its execution flow.
“ Rather than relying on entirely new methods and tools, attackers are quickly adapting established techniques to new platforms, technologies, and user behaviours. The number of AI skills within this new ecosystem is growing rapidly as we speak, further expanding the attack surface,” said ESET Director of Threat Prevention Labs Jiří Kropáč.“ On the other hand, PromptSpy illustrates the potential for increased flexibility in future threats – although guardrails against abuse included in LLMs are likely slowing down the adoption.”.
The report explains that malicious AI skills are being developed to use third-party hacking tools such as Mimikatz and Impacket, while other self-modifying skills are designed to establish persistence mechanisms or alter their own behaviour. ESET also highlights a growing number of security-related AI skills that provide only basic scanning
Another technique highlighted is ConsentFix, which combines ClickFixstyle interaction with abuse of OAuth authorisation workflows to hijack cloud accounts without stealing user credentials. According to ESET, detections of this attack vector more than doubled between H2 2025 and H1 2026.
Phishing campaigns also continue to evolve. QR code phishing, or quishing, reached record levels during the reporting period, accounting for approximately 11 % of phishing emails detected by ESET. The highest levels of detection were recorded in the US( 19 %), Spain( 17 %) and Mexico( 6 %).
Ransomware remains a significant concern. The report notes continued growth in attacks alongside increasing use of EDR killers, tools designed to disable security software before encryption begins. ESET has documented more than 100 different EDR killers in active use, with new variants continuing to emerge.
Despite the increase in ransomware activity, the proportion of victims paying ransoms continues to decline. The report cites three recent industry studies showing that between 14 % and 28 % of victims now choose to pay, representing an historic low despite the growing volume of attacks.
32 WWW. INTELLIGENTCISO. COM