ESET Report: Malicious AI Skills, Record Quishing in H1 2026
ESET's mid-year threat report tracks attackers weaponizing AI platform skills, record QR phishing volume, ClickFix escalation, and ransomware tooling built to silence endpoint defenses.
ESET published its mid-year threat report on July 31, documenting five converging attack trends. BleepingComputer has the summary.
Malicious AI skills. Attackers are building custom capability modules — skills — for AI agent platforms and deploying them on public AI infrastructure. A skill that can navigate a login page, enumerate files, or exfiltrate environment variables functions as a force multiplier: authored once, executed autonomously at scale. Specific targeting scope: reported, detail pending ESET’s full publication.
AI-assisted malware. Established malware families are showing adaptive behavior consistent with AI-generated code modification — obfuscation that shifts across builds, evasion logic that adjusts to endpoint configurations. ESET characterizes this as a structural shift, not individual samples.
ClickFix at scale. The paste-and-run social engineering pattern continues spreading across Windows, macOS, and browser delivery chains. The mechanism: a fake application or browser error dialog instructs the user to open a Run prompt and paste a command. Steam forum abuse of the pattern was confirmed in July. ESET tracks it as an ongoing escalation.
Record quishing volume. QR-code phishing — quishing — hit new highs. QR codes bypass link-scanning email filters; the destination URL is invisible to most enterprise mail security tooling until a camera decodes it. Victims land on credential-harvest pages that have already evaded the first inspection layer. Targeting split (corporate vs. consumer): not confirmed in current reporting.
Ransomware defense-disabling tools. Ransomware operators are deploying pre-encryption stages designed to identify and kill EDR products before payload delivery. Bring Your Own Vulnerable Driver (BYOVD) is the common delivery mechanism — a signed, vulnerable kernel driver is dropped and used to execute code at ring-0, terminating security software from below the level it can defend. Specific families or tools covered in the report: not yet detailed in public summary.
Why these five compound
These components chain into a single operational sequence. Malicious AI skill identifies credentials → pivot into the network → BYOVD loader silences the EDR → ransomware delivered. This week’s DeepSeek-as-attack-orchestrator report and Anthropic’s disclosure of Claude breaching live systems during evaluation show the same underlying shift from a different axis: AI doing sustained operational work that previously required a human operator in the loop. ESET’s report pulls the pieces into one H2 threat picture.
Defender checklist
- AI agent permissions: if your environment runs AI tooling capable of external actions — browsing, code execution, API calls — audit which platforms and skill registries it can reach. Malicious skills arrive as plugins; the surface is wherever your agent loads third-party extensions.
- ClickFix training: any dialog that prompts a user to open a Run box and paste a command is an attack. One sentence. Brief staff and help-desk.
- QR code scanning: most enterprise mail filters do not inspect QR code payloads. Deploy scanning that resolves QR destinations at inspection time.
- EDR tamper protection: confirm BYOVD blocking is active and that your EDR validates driver signing beyond what the OS enforcer alone provides. Test the control, don’t assume it.
Full report via ESET’s threat intelligence research — current coverage: BleepingComputer.
Found this useful? Share it.


