ESET Threat Report H1 2026 exposes a new attack playbook

The ESET Threat Report H1 2026 shows a cyber threat landscape that is becoming more efficient rather than simply more aggressive. From December 2025 through May 2026, attackers continued adapting familiar techniques to new platforms, technologies and user habits. AI is now becoming part of that shift.
ESET analysed nearly 900,000 AI skills and small functional components used by AI agents. It identified tens of thousands of suspicious instances and thousands that were outright malicious. At the same time, researchers identified PromptSpy, described as the first known Android malware to use generative AI in its execution flow.
For businesses and users, the message is clear. The attack surface is no longer limited to traditional malware and phishing. It is also moving into the tools and workflows built around AI.
AI boosts cyber attackers' efficiency as new risks emerge
AI skills are small add-ons or sets of instructions that tell an AI agent how to perform a task, including which services or tools to use and what data to access.
ESET found malicious AI skills using third-party hacking tools such as Mimikatz and Impacket. It also identified a suspicious self-modifying skill designed to create persistence and support tool modification.
The concern is not only that these skills exist. Their growing number could create new ways for AI agents to behave unpredictably or be abused by attackers.
PromptSpy offers another indication of where this could lead. The Android malware uses generative AI within its execution flow, pointing to the possibility of more flexible threats.
Quishing email threat India shows a local shift
QR code phishing, or quishing, has also reached record levels in ESET telemetry. Attackers hide malicious links inside QR codes, shifting the interaction from email inspection to mobile devices.
Around 11% of all detected phishing emails in H1 2026 used QR codes. India followed the wider trend closely. QRCode/Phishing trojan was the country's second most-detected email threat, accounting for around 7.4% of malicious email detections.
It also ranked among India's top 10 malware detections, with a share of around 2.5%.
The shift highlights a simple problem. Users may be more cautious about clicking suspicious links in emails, but scanning a familiar-looking QR code can feel harmless.
QR code phishing trends are changing user behaviour
The wider QR code phishing trends show how attackers are adapting to the way people interact with technology.
The US recorded the highest prevalence in ESET's telemetry at 19% of detections, followed by Spain at 17% and Mexico at 6%.
India's position as the second-highest detected email threat category makes the trend especially relevant for local businesses and consumers. The key risk is not a new piece of malware. It is the use of a familiar action in a less familiar attack chain.
AI agent skills cybersecurity risk is growing
The report also highlights how trust itself is becoming a target.
ClickFix campaigns have moved beyond fake CAPTCHA prompts into AI-themed help pages, browser extensions and cloud authentication scenarios. AI-fix takes this further by using AI-related troubleshooting content to deliver ClickFix compromise chains.
ConsentFix represents another shift. It combines ClickFix-style interaction with OAuth authorisation abuse to hijack cloud accounts without directly stealing credentials. ESET detections of this vector more than doubled between H2 2025 and H1 2026.
The broader pattern is worth watching. Attackers are not always trying to break through security controls. Increasingly, they are finding ways to make users complete the attack themselves.
India sees a different malware picture
India's threat profile also differs from the global picture in several areas.
Android/SpyLoan PUA, involving malicious loan apps that harvest personal data and enable harassment or extortion, was India's most-detected Android threat at around 24.5% of Android detections.
Python/Filecoder was India's most-detected ransomware family, accounting for 25% of detections. Globally, Win/RiskWare.LockScreen was the most detected ransomware.
JS/Agent was India's most-detected overall threat at 11.2%. HTML/Phishing. Agent, the leading global threat, ranked second in India at 9.1%.
Ransomware keeps growing, but payment falls
Ransomware activity continued to grow in H1 2026. Attackers also continued using EDR killers, tools designed to disable security software during attacks.
ESET Research documented more than 100 EDR killers used in the wild, with new variants appearing regularly.
Yet there is another side to the ransomware story. The number of victims willing to pay reached all-time lows, with three recent industry reports cited by ESET putting the share of paying victims at 14–28%.
The ESET Threat Report H1 2026 therefore points to a threat landscape built around adaptation. AI is adding new possibilities, quishing is changing phishing behaviour, and social engineering is finding new ways around traditional security habits. For organisations, the challenge is to recognise that familiar threats may no longer arrive in familiar forms.
Read More:
UPES and HPE Launch AI-Driven Centre of Excellence to Address India’s 600,000 AI Talent Deficit
UltraLED Displays Onboards EIS TechInfra Solutions as Official ULTRA NEXUS Regional Distributor
BD Soft channel partner expansion reaches Rajasthan
Nutanix explains how hybrid multi-cloud services will define channel growth






