Agentic AI arms cyber attackers to up their game
Ransomware and phishing surge in Africa as AI lets threat actors scale up attacks, ESET research shows.
Cybercriminals are leveraging artificial intelligence (AI) to enhance their phishing, quishing, and ransomware attacks on African companies, including those in South Africa (SA), according to the ESET H1 2026 Threat Report. AI serves as a powerful tool for attackers to improve the efficiency and scope of their campaigns. The report reveals that phishing constitutes 29.9% of threats targeting Africa, with a higher rate of 45.4% in South Africa.
Tony Anscombe, chief security evangelist at ESET, explains that South Africa is a more lucrative market due to the higher potential for monetisation and increased success rates in campaigns, either through higher click rates or better success once a click is made.
ESET's findings highlight the increasing use of EDR killers, tools designed to disable security solutions on targeted systems. The most common method used is the "bring your own vulnerable driver" approach, where attackers introduce a vulnerable version of a legitimate driver to exploit and eliminate security processes. A generic screen-lock tool, classified as an opportunistic attack using script keys, topped the threat list in Africa at 44.7%.
This scareware targets users and businesses lacking the skills or resources to recover compromised systems.
Ransomware groups, operating at a higher level, target specific individuals or organizations with a higher impact and greater likelihood of payout. ESET warns about AI skills—small pieces of third-party code downloaded from public repositories without verification or governance. Analyzing about 900,000 skills from popular repositories, ESET found 25,000 suspicious and more than 3,000 malicious.
The primary purpose behind malicious AI skills is credential theft, which is the same objective underlying most network intrusions. Eighty-four percent of the analyzed skills execute commands without user initiation, while 31% download additional tools into environments. Some malicious AI skills can rewrite themselves after installation, modifying their behavior beyond their intended limits.
Despite the rise of AI, traditional phishing and threat manipulation remain significant risks, with a 108% increase in ClickFix—a technique involving a fake problem and quick fix—and the emergence of newer variants like CrashFix and ConsentFix. ClickFix has become more prevalent, reaching record levels, with 11% of all detected phishing emails containing QR codes.
QR code phishing, or quishing, has seen a record rise and entered the top 10 threats for both Africa and South Africa. The success of phishing messages typically leads to the harvesting of credentials by information stealers like SnakeStealer, which accounted for 10.7% of infostealer detections in South Africa, compared to 5.4% across Africa.
SnakeStealer, offered as malware as a service with dashboards and data storage, allows low-skilled operators to carry out credential theft they would otherwise be unable to perform.
Written by urgent.news from ITWeb's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.