# Malware That Reads Screens: How AI Is Teaching Attackers to Stop Hardcoding Everything


For years, mobile malware authors faced a tedious problem: every new Android version, every new app layout, every new device skin broke their hardcoded automation. Screen coordinates shifted. UI strings changed. Bots failed. Humans had to update the code.


PromptSpy solves that problem. And that should concern anyone who tracks where mobile threats are heading.


Identified by ESET researchers in the first half of 2026, PromptSpy is the first documented Android malware to embed generative AI — specifically Google's Gemini — directly into its execution flow. Rather than navigating a phone's interface through hardcoded taps and text matches, it reads what's on the screen and reasons about what to do next. It adapts. It doesn't break when the UI changes because it understands the UI.


That's a qualitative shift, not a quantitative one. The threat isn't that PromptSpy is widespread — it's currently rare. The threat is what it signals about where mobile malware is going when the tooling matures.


## The New Attack Surface Nobody Had a Name For Last Year


Alongside PromptSpy, ESET's H1 2026 Threat Report surfaces a category most security teams haven't operationalized defenses against yet: malicious AI skills.


AI skills are the small functional components that AI agents use to take actions — query a database, send a message, call an API, access a file. As agentic AI deployments have accelerated through 2025 and into 2026, this ecosystem has expanded fast. ESET analyzed nearly 900,000 of these skills and found tens of thousands of suspicious entries and thousands of outright malicious ones.


Think about what that means structurally. Organizations deploying AI agents are effectively trusting a plugin ecosystem they have almost no established tools to audit. Traditional vulnerability management looks for CVEs in software. There's no CVE system for a malicious AI skill that tells your agent to exfiltrate data to an attacker-controlled endpoint. The discovery surface, the triage workflow, and the remediation playbook — none of it exists in mature form yet.


The number of AI skills is growing rapidly, ESET notes, which means the attack surface is expanding in real time regardless of whether security tooling catches up.


## ClickFix Doubles Down — And Follows the User


ClickFix is a social engineering technique built on a simple insight: if you show someone a fake error message and give them a "fix," many will run whatever you tell them to. It started with fake CAPTCHA prompts — pages that instructed victims to paste a command into their terminal or browser.


That worked. So attackers expanded it.


ESET's telemetry shows ClickFix detections more than doubled between H2 2025 and H1 2026. The technique has now migrated into AI-themed help pages (capitalizing on user confusion about new AI tools), browser extension prompts, and cloud authentication flows. Each expansion follows where user attention and uncertainty already live. When millions of people are confused about why their AI assistant isn't working, a page that offers to "fix" it has a ready-made audience.


This is the pattern worth watching: ClickFix isn't a technique that attackers invented and defenders will eventually neutralize. It's a framework that attackers evolve by tracking which UI contexts users trust. The specific lure changes; the social engineering core stays constant. Security awareness training that teaches employees to recognize "the CAPTCHA version" won't catch the AI-themed version six months later.


## QR Codes Reach Record Highs — And the Trust Problem Is Structural


QR code phishing — quishing — hit record levels in ESET's H1 2026 telemetry. The reason it keeps working is worth being explicit about: QR codes are visually opaque by design. There is no URL to hover, no sender address to inspect, no link text to scrutinize. A malicious QR code and a legitimate one are indistinguishable without scanning them.


Worse, scanning usually happens on a mobile device, which is typically outside of an organization's endpoint detection scope. Enterprise security tools protecting a managed laptop have no visibility into what the employee's phone does after scanning a QR code in a phishing email printed out and left on a conference room table — a documented attack vector.


The trust problem is structural. Black-and-white squares became culturally normalized during the pandemic and have never lost that association with legitimacy. Attackers are simply exploiting an implicit social contract about a visual format.


## 100 EDR Killers and the Defenders Who Can't Stop Writing That Number Up


Ransomware groups have turned EDR-killing into industrial production. ESET has documented over 100 distinct EDR killer variants used in real-world attacks — tools built specifically to disable the security software that should detect ransomware before it runs. New variants appear regularly.


There is some genuine good news buried in the ransomware data: the share of victims choosing to pay ransoms is declining, according to multiple data sources. That indicates progress. Organizations are getting better at restoring from backups, incident response is improving, and the FBI's disruption campaigns have had measurable effects on threat actor economics.


But the EDR killer number tells a parallel story. Ransomware operators are spending engineering effort to defeat endpoint protection at scale, and they're succeeding often enough to keep investing. A declining payment rate doesn't mean ransomware is retreating — it means the cost of defense is rising alongside the cost of attack.


---


## HackWire Analysis


The through-line in ESET's H1 2026 report isn't any single technique. It's adaptability as a first-class design goal.


PromptSpy doesn't hardcode behavior because hardcoding breaks. ClickFix doesn't stick to one lure because one lure burns out. QR phishing doesn't need to explain the malicious URL because it never shows one. EDR killers are produced in variants because defenders patch signatures.


We've spent decades building security tools calibrated to known signatures, known behaviors, and known patterns. The threat ecosystem is now explicitly engineered to minimize the surface area those tools can grip.


The AI skill finding deserves more attention than it's getting in broader coverage. Most security teams have not yet built an inventory, let alone a vetting process, for the AI skills their agents are authorized to execute. This is the 2026 version of the "shadow IT" problem — but instead of unsanctioned SaaS apps, it's unsanctioned agentic capabilities running with whatever permissions your AI orchestration layer holds. In many organizations, that's broad.


Concrete priorities for defenders right now: audit every AI agent deployment for what skills it can execute and what data it can access; establish a ClickFix-specific module in phishing training that updates when the lure format shifts; and treat QR codes in email as requiring the same scrutiny as any hyperlink. On the ransomware front, EDR tamper protection isn't optional anymore — vendors offer it, but not every team has enabled it.


The payment rate declining is the only unambiguously good signal in this report. Don't let it become a reason for complacency — the operators who aren't getting paid are still running attacks. They're just losing money while they refine their tools.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)