Malware News ESET tracks rise in malicious AI skills and adaptable malware

Brownie2019

Level 23
Thread author
Verified
Well-known
Forum Veteran
Mar 9, 2019
1,105
5,828
2,168
Germany
The first half of 2026 shows how attackers continue to improve the efficiency and scalability of their operations. Rather than relying on entirely new methods and tools, they are quickly adapting established techniques to new platforms, technologies, and user behaviors.

Artificial intelligence is playing a growing role in this development. In H1 2026, ESET analyzed nearly 900,000 AI skills – small functional components used by AI agents – and identified tens of thousands of suspicious and thousands of outright malicious instances.

The number of AI skills within this new ecosystem is growing rapidly “as we speak”, further expanding the attack surface.

AI is also beginning to appear within malware itself. Shortly after the emergence of the first AI-powered ransomware in 2025, ESET researchers identified PromptSpy, the first known Android malware to use generative AI in its execution flow.

The malware leverages AI – specifically, Google’s Gemini – to interpret user interface elements and adapt across devices and environments without relying on hardcoded behavior.

While still rare, PromptSpy illustrates the potential for increased flexibility in future threats – although guardrails against abuse included in LLMs are likely slowing down the adoption.
 
Key security implications

The passage highlights an important shift: attackers are increasingly optimizing existing techniques rather than depending on entirely new attack methods. The main risks described are:

  • AI-related supply-chain and ecosystem risks involving malicious or suspicious AI-agent components.
  • Malware using generative AI to interpret changing user interfaces, potentially reducing reliance on hardcoded workflows.
  • ClickFix campaigns expanding into AI-themed support pages, browser extensions, and cloud-login scenarios.
  • QR-code phishing moving victims from monitored desktops to mobile devices, where link inspection may be less likely.
  • Ransomware operators continuing to target endpoint protection, including through EDR-killing tools.

The claims about PromptSpy, the number of malicious AI skills, detection increases, and ransomware payment trends should be verified against ESET’s original report and methodology. Detection telemetry does not necessarily represent the total number of attacks, and an “AI-powered” component may have limited capability rather than autonomous reasoning.

From a defensive perspective, organizations should prioritize phishing-resistant MFA, browser and endpoint hardening, application allowlisting where practical, tested offline backups, and monitoring for attempts to tamper with security tools. Users should never paste commands into a terminal merely because a webpage presents them as a CAPTCHA or troubleshooting step.

The central takeaway is that AI may increase attacker adaptability, but familiar controls—least privilege, user awareness, strong authentication, patching, and tested recovery procedures—remain highly relevant.