ESET report: criminals are teaching AI new tricks, and old malware new manners
The Slovak security firm's latest threat report says attackers are wiring AI assistants into their toolkits, dressing up scams as helpful pop-ups, and building ransomware that switches off the guards before it strikes.

Key points
- ESET's H2 2025 threat report says criminals are building malicious AI skills, small add-ons that make chatbots do harmful work on their attacker's behalf.
- ClickFix attacks, where a fake error message tricks a user into pasting a hostile command into their own computer, are now one of the most common ways ordinary people get infected.
- Quishing, phishing done with QR codes instead of links, hit record volumes in the reporting period.
- New ransomware families are shipping built-in tools to disable antivirus and endpoint detection software before encrypting files.
- AI-assisted malware, code partly written or refined by large language models, is showing up in real intrusions rather than lab demos.
Security vendor ESET has published its latest look at what criminals are actually doing right now, and the short version is that old tricks are getting an AI paint job. First reported by BleepingComputer, the report covers the second half of 2025 and lands on five shifts worth paying attention to.
None of them are science fiction. All of them are already hitting normal users and normal companies.
What are "malicious AI skills" in plain English?
They are small add-ons or plugins that make an AI assistant do a criminal's dirty work. Think of a helpful chatbot that a user installs a "skill" into, expecting it to summarise emails, and instead it quietly hunts for passwords or forwards sensitive files.
ESET's researchers say attackers are treating the AI assistant as the new browser extension: a trusted place inside your workflow where a bad add-on gets a lot of access before anyone notices. In practice, the failure mode here is the same one we saw with malicious Chrome extensions a decade ago. Users trust the store, the store trusts the developer, and nobody reads the permissions.
How does a ClickFix attack actually work?
A website shows the visitor a fake error, something like "your browser needs a quick fix," and gives them steps to "repair" it. Those steps involve copying a line of text and pasting it into the Windows Run box or a terminal. The user, trying to be helpful to themselves, runs the attacker's command by hand.
It sidesteps a lot of defences because the human, not the malware, is the one pressing the button. ESET says ClickFix has climbed sharply through 2025 and is now a mainstream infection route.
The headline numbers
| Trend | What ESET saw in H2 2025 |
|---|---|
| ClickFix attacks | Sharp rise, now a top infection vector |
| Quishing (QR-code phishing) | Record volume for the period |
| AI-assisted malware | Moved from proof-of-concept to real cases |
| Ransomware with EDR-killers | New families ship this by default |
Why does the QR-code stuff matter?
Because a QR code hides the destination. A printed poster, a PDF invoice, or a parking-meter sticker can all send someone's phone to a fake login page, and the victim has no URL to squint at first. ESET recorded record quishing activity in this period, driven by campaigns aimed at Microsoft 365 and banking logins.
For ordinary readers, the practical rule is boring but works: if a QR code takes you to a login screen, close it and type the site in yourself.
Ransomware that turns off the alarms
Several of the ransomware families ESET tracked now include what the industry calls EDR-killers, tools that try to shut down endpoint detection and response software, the modern antivirus that most companies rely on. One thing the post-mortem will say, again, is that the guard software was disabled minutes before the encryption started. Defenders should be alerting on the guard going quiet, not just on the guard shouting.
Operational takeaway: assume the human is the exploit, assume the AI plugin is the extension, and alert when your security tools stop talking.



