ESET's H1 2026 Threat Report highlights attackers adapting established techniques to new platforms rather than inventing entirely new methods. Key trends include the emergence of PromptSpy (first Android malware using generative AI in its execution flow), the rapid expansion of malicious AI skills, doubling of ClickFix social engineering detections, record-level QR code phishing (quishing), and continued proliferation of EDR killers alongside declining ransom payment rates.
AI Malware
2 posts
ESET Threat Report H1 2026 Analyzing the Current State of AI Use in Malware Unit 42 analyzed two malware samples leveraging Large Language Models (LLMs) for remote decision-making. One is a .NET infostealer using GPT-3.5-Turbo for superficial 'AI theater', while the other is a Golang dropper that uses GPT-4 to evaluate system telemetry and determine if the environment is safe to deploy a Sliver payload.