AI-Powered Threats and Evolving Social Engineering Dominate H1 2026 Cyber Landscape
The first half of 2026 reveals a significant shift in the cyber threat landscape, as attackers increasingly leverage artificial intelligence to enhance the efficiency and scalability of their operations. Rather than inventing entirely new methods, adversaries are adeptly adapting established techniques to new platforms and user behaviors, as detailed in **ESET**'s latest threat report. This period saw a rise in AI-powered malware, sophisticated social engineering tactics, and record levels of QR code phishing.

Cybercriminals are refining their strategies, moving away from novel attack vectors and towards optimizing existing techniques with the help of advanced technologies.
### The AI Factor in Cyberattacks
Artificial intelligence is emerging as a critical component in the evolution of cyber threats. In H1 2026, **ESET** analyzed nearly 900,000 AI skills β functional components used by AI agents β identifying tens of thousands of suspicious instances and thousands of outright malicious ones. The rapid expansion of this AI ecosystem significantly broadens the attack surface.
AI is also being integrated directly into malware. Following the appearance of the first AI-powered ransomware in 2025, **ESET** researchers discovered **PromptSpy**, the first known Android malware to incorporate generative AI into its execution flow. **PromptSpy** utilizes **Google's Gemini** to interpret user interface elements, allowing it to adapt across various devices and environments without relying on rigid, hardcoded behaviors. While still rare, this development highlights the potential for greater flexibility in future threats, though guardrails in Large Language Models (LLMs) may be mitigating rapid adoption.
### Evolving Social Engineering Tactics
Trust remains a prime target for cybercriminals, with social engineering techniques becoming more sophisticated.
**ClickFix**, a technique that uses fake error messages, has expanded beyond bogus CAPTCHA prompts. It now appears in AI-themed help pages, malicious browser extensions, and cloud authentication scenarios. **ESET**'s detections of **ClickFix** more than doubled between H2 2025 and H1 2026, indicating its sustained effectiveness and adaptation.
Phishing campaigns are also evolving in response to user habits. **QR code phishing**, or **quishing**, has reached unprecedented levels, according to **ESET** telemetry. Attackers embed malicious links within QR codes to bypass traditional email security checks and shift user interaction to mobile devices, exploiting the inherent trust many users place in these codes.
### Ransomware Persistence and EDR Evasion
Ransomware activity shows no signs of abating. Adversaries continue to employ **EDR killers** β tools designed to disable endpoint detection and response software during attacks. **ESET Research** has documented over 100 distinct **EDR killer** variants in the wild, with new versions emerging regularly.
Despite this persistence, data from multiple sources suggests a declining trend in victims choosing to pay ransoms. This indicates potential progress in the effectiveness of mitigation strategies and incident response measures.
To delve deeper into these and other emerging threats, IT security professionals are encouraged to download the full **ESET Threat Report H1 2026**.