ctipilot.ch

ESET Threat Report H1 2026

report · report:eset-threat-report-h1-2026 single-source

ESET's semi-annual threat-landscape report (Dec 2025-May 2026 telemetry), published 2026-07-08: PromptSpy (first known Android malware using generative AI/Gemini at runtime), ClickFix detections more than doubling H2 2025->H1 2026, record-level QR-code phishing (~11% of detected phishing emails), and 100+ distinct EDR-killer tools documented in the wild (ESET/WeLiveSecurity, 2026-07-08).

Coverage timeline
2
first 2026-07-09 → last 2026-07-12
Peak priority
notable
2 notable
Sources cited
7
7 hosts
Sections touched
2
research, weekly-research
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
3
pinned v19.1 · see below

ATT&CK techniques

3 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-12/weekly-w28-ai-operationalized · ATT&CK page ↗

Execution TA0002

T1059Command and Scripting Interpreter×1

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.

Evidence: 2026-07-12/weekly-w28-ai-operationalized · ATT&CK page ↗

T1204User Execution×1

An adversary may rely upon specific actions by a user in order to gain execution. Users may be subjected to social engineering to get them to execute malicious code by, for example, opening a malicious document file or link. These user actions will typically be observed as follow-on behavior from forms of Phishing.

Evidence: 2026-07-12/weekly-w28-ai-operationalized · ATT&CK page ↗

Persistence TA0003

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-12/weekly-w28-ai-operationalized · ATT&CK page ↗

Privilege Escalation TA0004

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-12/weekly-w28-ai-operationalized · ATT&CK page ↗

Stealth TA0005

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-12/weekly-w28-ai-operationalized · ATT&CK page ↗

Story timeline

  1. 2026-07-12AI as operator, not target: this week's research showed adversaries using AI to run attacks faster, evade AI defences, and generate tooling
    weekly-researchAI-operationalised attacks deepened this week — 72h AI-assisted AWS compromise, prompt-injection RCE of defensive agents, AI-generated APT loader
  2. 2026-07-09ESET Threat Report H1 2026: first Android malware using generative AI at runtime, ClickFix detections more than double, record QR-phishing, 100+ EDR-killers
    researchESET Threat Report H1 2026: PromptSpy runs Gemini in its own execution flow, ClickFix 2x, QR-phishing at record levels, 100+ EDR-killers catalogued

Where this entity is cited

  • research1
  • weekly-research1

Source distribution

  • ainowinstitute.org1 (14%)
  • github.com1 (14%)
  • globenewswire.com1 (14%)
  • isc.sans.edu1 (14%)
  • securelist.com1 (14%)
  • sygnia.co1 (14%)
  • welivesecurity.com1 (14%)

explore in graph

Entries about ESET Threat Report H1 2026 (2)

2026-07-12 · view entry permalink →

NOTABLENATOB2

AI as operator, not target: this week's research showed adversaries using AI to run attacks faster, evade AI defences, and generate tooling

Last week's weekly framed AI as having "crossed from attack target to attack operator." This week's research does not repeat that thesis — it fills it in with concrete, independent data points that sharpen what defenders should change.

The clearest is operational tempo. Sygnia's incident responders documented a single actor going from an internet-facing-app foothold to broad compromise of AWS, CI/CD and source control in roughly 72 hours using no novel malware and no zero-day — every technique long-tracked, but chained and parallelised at a speed Sygnia attributes to AI/agentic assistance (four distinct IAM access keys used from one source in a single observed second) (Sygnia, 2026-07-08). The second is AI as attack surface turned back on defenders: the "Friendly Fire" brief showed prompt injection hijacking defensive AI code-review agents into remote code execution (AI Now Institute, 2026-07-11), and PraisonAI's agentic framework carried unsandboxed-LLM-code-execution and tool-call-RCE CVEs (PraisonAI GHSA, 2026-07-11). The third is AI in tooling and evasion: Kaspersky's Armored Likho APT shipped an AI-generated loader with the BusySnake stealer (Kaspersky Securelist, 2026-07-11), and SANS documented "comment stuffing" — padding HTML phishing attachments to dilute or exhaust AI/NLP email scanners (SANS ISC, 2026-07-10). This week's ESET Threat Report H1 2026, covered separately, independently records the first Android malware using generative AI at runtime.

Why this is a strategic-shift item, not a re-list: each finding is a distinct new-this-week research publication, and together they change a defender obligation rather than restate awareness — when access-to-impact compresses to hours and defensive AI itself becomes an exploitation target, detection can no longer wait for full visibility.

Builds on: 2026-07-09/sygnia-ai-orchestrated-aws-cloud-intrusion-72h · 2026-07-11/friendly-fire-prompt-injection-rce-defensive-ai-agents · 2026-07-11/armored-likho-busysnake-ai-generated-loader-python-stealer · 2026-07-10/comment-stuffing-html-phishing-ai-email-scanner-evasion · 2026-07-11/praisonai-agentic-framework-three-cves-code-exec-rce-ddli · 2026-07-09/eset-threat-report-h1-2026

research12 Jul 23:38Zmulti-sourceOpen finding ↗

2026-07-09 · view entry permalink →

NOTABLENATOB2

ESET Threat Report H1 2026: first Android malware using generative AI at runtime, ClickFix detections more than double, record QR-phishing, 100+ EDR-killers

ESET's semi-annual threat-landscape report (telemetry December 2025–May 2026) flags four developments a Tier 2/3 team should track (ESET / WeLiveSecurity, 2026-07-08; ESET press release, 2026-07-08).

First, ESET analysed roughly 900,000 "AI skills" — small functional components used by AI agents — and found tens of thousands suspicious and thousands outright malicious, an expanding attack surface in the emerging agentic-AI ecosystem. Second, it identified PromptSpy, described as the first known Android malware to use generative AI (specifically Google's Gemini) inside its own execution flow to interpret UI elements and adapt behaviour across devices at runtime rather than relying on hardcoded logic — following the first AI-powered ransomware disclosed in 2025 (ESET, 2026-07-08). Third, ClickFix (the fake-error social-engineering technique) has expanded beyond fake CAPTCHA prompts into AI-themed help pages, browser extensions and cloud-authentication scenarios, with ESET detections more than doubling between H2 2025 and H1 2026. Fourth, QR-code phishing ("quishing") reached record levels, with roughly 11% of all ESET-detected phishing emails in H1 2026 using QR codes to move victim interaction onto mobile devices and evade cursory inspection. Ransomware activity continued unabated with over 100 distinct EDR-killer tools now catalogued by ESET, though a declining share of victims are reportedly paying.

ESET researchers identified PromptSpy, the first known Android malware to use generative AI in its execution flow

ESET detections of this vector more than doubled between H2 2025 and H1 2026

ESET Research has documented over 100 EDR killers used in the wild, with new variants appearing regularly

ESET / WeLiveSecurity 2026-07-08
annual-report09 Jul 04:32Zsingle-sourceOpen finding ↗