Malware Learns to Use AI During Attacks — ESET Warns of New Threats
Google/DeepMind
ESET's analysis of nearly 900,000 AI skills revealed tens of thousands of suspicious and thousands of clearly malicious instances. Malware now uses generative AI during execution, as seen with PromptSpy for Android, and attack vectors like ClickFix and QR phishing are expanding.
In the first half of 2026, attackers continued to increase the efficiency and scalability of their operations, with AI playing an increasing role. ESET analyzed nearly 900,000 AI skills — small functional components used by AI agents — and found tens of thousands of suspicious and thousands of outright malicious instances, whose numbers are continuously growing. AI is starting to be used inside malware itself: researchers identified an Android app called PromptSpy that uses generative AI during execution, calling on Google Gemini to interpret UI elements and adapt to different devices without hardcoded behavior. The ClickFix social engineering method, using fake error messages, has expanded beyond fake CAPTCHA prompts to AI help pages, browser extensions, and cloud authentication scripts, with detections more than doubling from H2 2025 to H1 2026. QR code phishing (quishing) reached record levels, with attackers embedding malicious links in QR codes to bypass inspection and redirect users to mobile devices. Ransomware activity shows no sign of slowing, with continued use of EDR killers — tools designed to disable security software — and over 100 have been documented in the wild. However, data indicates fewer victims are paying ransoms, suggesting some progress in mitigation.
- Сокращения
- EDR = Endpoint Detection and Response — обнаружение и реагирование на конечных точках
Source: 3DNews —
original
