Tuesday, July 21, 2026

News

Poland Tops Global Cyberattack Rankings, ESET Warns of First AI-Powered Android Malware

PolicyPatryk Raba
Fot. Tima Miroshnichenko, Pexels (Pexels License)

The latest ESET Threat Report H1 2026 places Poland first in the world for detected downloaders and the CloudEye obfuscation tool. Analysts also describe PromptSpy, the first known Android malware actively using generative AI.

Contents
  1. Poland in the crosshairs
  2. AI as an attack tool
  3. QR codes and fake error messages
  4. What it means for Polish companies

Poland ranked first in the world for the number of detected downloaders, programs that fetch further stages of an attack, and for CloudEye, a tool used to obfuscate malware. That is according to the latest ESET Threat Report H1 2026, published in July 2026 and covering the period from December 2025 to May 2026.

The ESET report is one of the most extensive semiannual compilations of global cyberthreat telemetry, based on data collected from the company's protection systems installed at millions of users and thousands of organizations. This year's H1 2026 edition pays particular attention to how criminals are exploiting users' growing trust in AI tools.

Poland in the crosshairs

Poland's high rankings in nearly every threat category are not a one-off. The country has appeared at the top of global cyberattack statistics in several consecutive ESET reports, which analysts attribute to a combination of a large number of active internet users, a developed digital economy, and still uneven levels of security investment among companies of different sizes.

The result in the downloader and CloudEye categories, where Poland outranked every other monitored country, is especially concerning. Downloaders are typically the first stage of a multi-stage attack, opening the door to installing further, more harmful components, including ransomware or infostealers.

AI as an attack tool

The most significant thread running through the report, however, is the role generative AI plays on the attackers' side. For the first time, ESET analyzed at scale the ecosystem of so-called AI skills, add-ons that extend the capabilities of AI agents. Among nearly 900,000 components analyzed, more than 25,000 raised suspicion among analysts, and over 3,000 were classified as clearly malicious.

Researchers also described PromptSpy, described as the first known Android threat that actively and in real time uses a generative AI model, in this case Google Gemini, to adapt its behavior to the specific compromised device. That marks a step beyond PromptLock, an experimental ransomware previously documented by ESET that used a locally run model to generate malicious Lua scripts.

Attackers are quick to adapt proven techniques to new platforms - Kamil Sadkowski, ESET cyberthreat analyst

QR codes and fake error messages

The report highlights two techniques that grew fastest over the past half year. The first is quishing, phishing using QR codes, which exploits the fact that users verify the address hidden behind a graphic code less often than a plain text link. The second is ClickFix, which displays a fake system error message that convinces the victim to paste and run a malicious command in their own system.

ClickFix detections rose 108 percent year over year, making it one of the fastest-growing threat categories in the entire report. ESET also documented more than 100 different EDR killer tools, used to disable antivirus software and threat detection systems before launching the actual attack.

What it means for Polish companies

Experts commenting on the report in Poland stress that the country's high ranking in attack statistics translates directly into a need to invest in basic security measures before organizations move on to costly enterprise-grade solutions.

The cost of not investing in cybersecurity can be calculated in real terms, the key is identifying your most valuable assets - Dawid Zięcina, DAGMA Bezpieczeństwo IT

The low share of companies paying a ransom, between 14 and 28 percent of victims, suggests that more and more organizations have backups and recovery plans in place that let them sidestep criminals' demands. That is a positive signal, though it does not reduce the scale of the attack attempts themselves, which according to the report keep rising regardless of ransom payout rates.

For Polish companies and public institutions, the report is further confirmation that the country remains one of the main targets of cybercriminals in Europe, and that growing access to AI tools is lowering the barrier to entry for less sophisticated criminal groups that previously lacked the resources to build complex malware.

Share: