ESET's H1 2026 Threat Report highlights attackers adapting established techniques to new platforms rather than inventing entirely new methods. Key trends include the emergence of PromptSpy (first Android malware using generative AI in its execution flow), the rapid expansion of malicious AI skills, doubling of ClickFix social engineering detections, record-level QR code phishing (quishing), and continued proliferation of EDR killers alongside declining ransom payment rates.
PROMPTSPY
2 posts
ESET Threat Report H1 2026 GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access Google Threat Intelligence Group (GTIG) reports an escalation in adversaries leveraging generative AI for vulnerability discovery, autonomous malware orchestration, and defense evasion. Notable developments include the AI-assisted discovery of a zero-day 2FA bypass, the PROMPTSPY Android backdoor utilizing the Gemini API for autonomous UI navigation, and supply chain attacks by TeamPCP targeting AI dependencies like LiteLLM to extract cloud secrets.