← All news

vulnerability

ESET: 3,000+ Malicious AI Agent Skills Found in the Wild

2026-07-09

AI agents are the new interns. They browse, they click, they run commands, they poke around your files, all on your behalf. To do any of that, they lean on things called skills, little modular capabilities that teach the agent how to talk to a service or handle a bit of data. According to ESET's H1 2026 Threat Report, a worrying number of those skills are working for the other team.

The numbers

ESET's researchers scanned roughly 900,000 AI skills. More than 25,000 came back suspicious. Over 3,000 were flagged as outright malicious. And the growth curve is the part that should give people pause: between March and May 2026, the volume of unique skills scanned jumped from 60,000 to nearly 900,000, and the malicious count went from around 600 to over 3,000 in the same window.

The capabilities on offer read like a pentester's shopping list:

  • Command execution
  • File access
  • Credential loading
  • Code injection
  • Obfuscation

All perfectly useful for legitimate automation. Also perfectly useful for quietly siphoning data or running malware through an agent that a staff member trusts by default.

ClickFix keeps climbing, now with AI dressing

Elsewhere in the report, ClickFix attacks rose 108% between H2 2025 and H1 2026. These are the ones where a fake error message convinces someone to paste a malicious command into their own terminal to "fix" a problem that never existed. New variants include AI-fix pages styled to look like troubleshooting flows from Anthropic, OpenAI or Microsoft, and a spin-off called ConsentFix that lifts Microsoft OAuth tokens through bogus verification prompts.

QR code phishing is not going anywhere either. It now accounts for about 11% of detected phishing emails, roughly 100,000 a month.

Malware learns to prompt

On Android, ESET flagged PromptSpy as the first malware they've observed using generative AI at runtime. It calls Google's Gemini to read what's on the screen and generate the gestures needed to keep itself alive on the device. Persistence, but written by an LLM on demand.

Ransomware crews are also getting more industrial about defence evasion. ESET is tracking more than 100 EDR killers in the wild, with over 60 abusing vulnerable drivers to disable endpoint tooling before the payload runs. The share of victims paying is down to 28%, but the median payment has climbed 368% to nearly $60,000. Fewer payers, much bigger cheques.

The thread pulling it together

The interesting part is where all these trends meet. Attackers aren't building parallel infrastructure and hoping people wander into it. They're piggybacking on the legitimate AI stack: a skill in an agent's toolbox, a page hosted on Anthropic's domain, Gemini itself doing the heavy lifting for a piece of Android malware.

The tools organisations are starting to lean on for productivity are the same tools the other side is learning to weaponise. Which means the review process for what an AI agent is allowed to install, load, or call needs to catch up to the rest of the security programme, and quickly.

ESET: 3,000+ Malicious AI Agent Skills Found in the Wild | RiskSense