ESET H1 2026 Threat Report: Malicious AI Agent Skills Surge Fivefold to 3,000+ Entries; PromptSpy Debuts as First Gemini-Powered Android Malware — Threadlinqs Intelligence
As of 2026-07-31, ESET H1 2026 Threat Report: Malicious AI Agent Skills Surge Fivefold to 3,000+ Entries; PromptSpy Debuts as First Gemini-Powered Android Malware is a medium-severity malware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 26 indicators of compromise.
Threat ID: TL-2026-1798 · Severity: MEDIUM · Status: ACTIVE · Category: MALWARE
ESET's H1 2026 Threat Report (Dec 2025-May 2026 telemetry) documents a fivefold surge in malicious AI agent "skills" between March and May 2026 -- from ~600 to 3,000+ malicious skills out of nearly
ESET Research's H1 2026 Threat Report, covering telemetry from December 2025 through May 2026, identifies two related but distinct developments in AI-enabled threats. First, ESET's tracking of the emerging AI agent "skill" ecosystem -- small, reusable instruction sets that tell an AI agent which tools, services, or data to use for a task -- found explosive growth in malicious content: unique skills analyzed grew from roughly 60,000 in March 2026 to nearly 900,000 by May 2026, suspicious skills grew from about 10,000 to 25,000, and outright malicious skills grew from about 600 to more than 3,000 over the same three-month window. Malicious skills identified by ESET wrap legitimate offensive-security tooling (Mimikatz for credential dumping, Impacket for lateral movement and remote execution) inside agent-consumable packages, include self-modifying skills that write their own persistence mechanisms (JSON-based) and rewrite their own Python logic, and include deliberately weak or fake "security" skills that create a false sense of protection. Warning-sign behaviors ESET flags across this skill supply chain include command execution, file access, credential loading, code injection, obfuscation, and third-party tool downloading -- capabilities that convert a small, seemingly benign automation add-on into a high-risk software-supply-chain component once an AI agent is granted the ability to browse, execute commands, access files, or reach third-party services.
Second, ESET researcher Lukas Stefanko documented PromptSpy, an advanced evolution of the existing VNCSpy Android RAT family and the first known Android malware to embed a call to a generative-AI model in its execution flow. Rather than relying on hardcoded tap coordinates and UI selectors -- which break across different devices, screen sizes, and app versions -- PromptSpy captures the current screen as an XML dump via Android's Accessibility Service, sends that XML together with a fixed "you are an Android automation assistant" prompt to Google's Gemini API, and receives back structured JSON (status, reasoning, action_type, coordinates) describing exactly which UI action to perform next. The malware then executes that action through the Accessibility Service and repeats the request/response loop until its task -- primarily locking the malicious app persistently into the device's recent-apps list -- is complete. PromptSpy additionally ships a built-in VNC module that gives operators full remote-desktop control of the infected device, can intercept lockscreen PINs/passwords, records the pattern-unlock gesture as video, takes screenshots, and uses invisible screen overlays to block the uninstall button. Samples were distributed outside Google Play via a dropper hosted at mgardownload[.]com that led to a phishing page at m-mgarg[.]com impersonating JPMorgan Chase Bank under the app identity "MorganArg," targeting Argentina-based users; the VNC module communicates with a hardcoded C2 host at 54.67.2[.]84. Debug strings and localized event handlers in Simplified Chinese indicate the malware was built in a Chinese-speaking development environment. ESET disclosed the findings to Google prior to publication; Google states no PromptSpy samples were found on Google Play and that Play Protect blocks known versions by default. As of publication, PromptSpy had not been observed in live ESET telemetry, indicating it remains at proof-of-concept / limited-test-campaign stage rather than a widely deployed threat -- but ESET assesses it as a preview of where AI-agent-integrated mobile malware is heading as LLM guardrails are the main current brake on broader adoption.
The same H1 2026 report places both findings in the context of a broader AI-accelerated threat landscape: ClickFix-style fake-error social engineering (detections up 108% H2 2025-H1 2026, now spanning AI-themed help pages, browser extensions/CrashFix, and OAuth-token-theft ConsentFix variants), record levels of QR-code phishing (
Target sectors: financial services, banking, technology, software supply chain, consumer general public
Target regions: argentina, Global
Detections & IOCs
As of 2026-08-17, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 26 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, MEDIUM, threat intelligence, cybersecurity, T1476, T1660, T1204, T1059, T1541, T1398, T1628, T1027, T1417, T1003