Cybersecurity firm ESET has documented a global increase in malicious AI skills and adaptable malware in its latest threat report.
This trend indicates that cybercriminals are rapidly integrating artificial intelligence to increase the efficiency and impact of their attacks. As attackers adapt established techniques to emerging technologies, traditional security defenses face new challenges in detecting and neutralizing these evolving threats.
The report focuses on data collected between December 2025 and May 2026 [1]. Researchers identified a surge in AI-assisted malware and a rise in "ClickFix" social-engineering attacks. These schemes typically trick users into executing malicious code under the guise of fixing a technical error.
ESET also noted record-high activity in "quishing," which involves the use of malicious QR codes to steal information or deploy malware. Alongside these social-engineering tactics, the firm found that ransomware tools are being specifically designed to disable security software, making it harder for organizations to defend their networks.
To understand the scale of the threat, ESET examined 900,000 AI skills [2]. The research indicates that attackers are leveraging open-source tool repositories to refine their capabilities and target victim environments more effectively.
These developments suggest a shift toward more automated and adaptable cyberattacks. By utilizing AI platforms, criminals can scale their operations and modify their code more quickly than in previous years, a move that forces security firms to constantly update their detection signatures.
“Cybercriminals are rapidly integrating artificial intelligence to increase the efficiency and impact of their attacks.”
The integration of AI into the cybercriminal toolkit represents a transition from manual, static attacks to dynamic, automated threats. By targeting the security software itself and leveraging high-volume social engineering like quishing, attackers are reducing the time between the creation of a vulnerability and its exploitation, necessitating a shift toward AI-driven defense mechanisms.



