ESET report: criminals are teaching AI new tricks, and old malware new manners
The Slovak security firm's latest threat report says attackers are wiring AI assistants into their toolkits, dressing up scams as helpful pop-ups, and building ransomware that switches off the guards before it strikes.

Key points
- ESET's H2 2025 threat report says criminals are building malicious AI skills, small add-ons that make chatbots do harmful work on their attacker's behalf.
- ClickFix attacks, where a fake error message tricks a user into pasting a hostile command into their own computer, are now one of the most common ways ordinary people get infected.
- Quishing, phishing done with QR codes instead of links, hit record volumes in the reporting period.
- New ransomware families ship built-in tools to disable antivirus and endpoint detection software before encrypting files.
- AI-assisted malware is showing up in real intrusions rather than lab demos.
ESET has published its latest look at what criminals are actually doing, and the short version is that old tricks are getting an AI coat of paint. First reported by BleepingComputer, the report covers the second half of 2025 and lands on five shifts worth paying attention to. None of them are science fiction, and all of them are already hitting ordinary users and ordinary companies.
What are "malicious AI skills" in plain English?
They're small add-ons or plugins that make an AI assistant do a criminal's dirty work. A user installs a "skill" expecting it to summarize emails; it quietly hunts for passwords instead.
ESET's researchers say attackers are treating the AI assistant as the new browser extension: a trusted place inside your workflow where a bad add-on gets a lot of access before anyone notices. The failure mode is identical to what we saw with malicious Chrome extensions a decade ago. Users trust the store, the store trusts the developer, and nobody reads the permissions.
How does a ClickFix attack actually work?
A website shows the visitor a fake error, something like "your browser needs a quick fix," then hands them steps to "repair" it. Those steps involve copying a line of text and pasting it into the Windows Run box or a terminal. The user, trying to help themselves, runs the attacker's command by hand.
It sidesteps a lot of defences because the human, not the malware, is pressing the button. We covered two variants of exactly this technique on 16 July, TELEPUZ hiding behind fake pop-ups and ClickLock persuading Mac users to hand over passwords, so ESET's finding that ClickFix is now a mainstream infection route tracks with what we've been seeing all summer.
The headline numbers
| Trend | What ESET saw in H2 2025 |
|---|---|
| ClickFix attacks | Sharp rise, now a top infection vector |
| Quishing (QR-code phishing) | Record volume for the period |
| AI-assisted malware | Moved from proof-of-concept to real cases |
| Ransomware with EDR-killers | New families ship this by default |
Why does the QR-code stuff matter?
A QR code hides the destination. A printed poster or a PDF invoice can send someone's phone to a fake login page, and the victim has no URL to squint at beforehand. ESET recorded record quishing activity in this period. The practical rule is boring but it works: if a QR code drops you on a login screen, close it and type the site address yourself. We reported on fake QR stickers placed over real parking-meter instructions in Christchurch on 17 July, the physical-world version of exactly this playbook.
Ransomware that turns off the alarms
Several of the ransomware families ESET tracked now include what the industry calls EDR-killers: tools that shut down endpoint detection and response software, the modern antivirus most companies rely on. The post-mortem will say, again, that the guard software was disabled minutes before encryption started. Defenders should alert when the guard goes quiet, not just when it starts shouting.
The pattern across all five trends is the same one it's always been. Assume the human is the exploit. Assume the AI plugin is the extension. Watch what goes silent.



