Poland ranked first worldwide for the number of detected downloaders—malicious programs designed to download additional threats onto infected devices—and for detections of CloudEye, a tool used to conceal and deliver malware.
The country also ranked second for email-distributed threats and among the most frequently targeted countries for web-based attacks.
Meanwhile, ESET analysed almost 900,000 add-ons and instruction packages created for artificial intelligence agents. More than 25,000 were classified as suspicious, while over 3,000 were identified as malicious.
During the first half of 2026, Poland ranked among the countries most heavily affected by several categories of cyberthreats detected by ESET systems.
The country recorded the highest number of downloader detections and CloudEye incidents. It also ranked second for email threats and web-based attacks, third for ransomware and attacks targeting Remote Desktop Protocol services, and fourth for information-stealing malware.
The latest ESET Threat Report H1 2026 indicates that cybercriminals are increasingly improving the effectiveness of established attack methods by adapting them to new platforms, cloud services and the growing trust users place in artificial intelligence.
The report covers the period from December 2025 to May 2026. One of its key conclusions is the growing importance of AI for individual users and businesses, as well as for cybercriminals.
ESET analysed almost 900,000 so-called AI skills. These are small add-ons or sets of instructions defining which tasks an AI agent can perform, which tools it should use and which data it may access.
More than 25,000 of the analysed AI skills were considered suspicious, while over 3,000 were classified as clearly malicious.
Poland among the world’s most targeted countries
According to ESET telemetry data, Poland ranked:
- First for downloader detections, ahead of Turkey and Italy;
- First for CloudEye detections, ahead of Turkey and Spain;
- Second for email-based threats, behind Japan;
- Second for web-based threat targets, behind Japan;
- Third for ransomware detections, behind Turkey and the United States;
- Third for attacks targeting Remote Desktop Protocol services, behind Spain and the United States;
- Fourth for information-stealing malware, behind Turkey, Japan and Spain.
Poland’s high position is therefore not associated with a single type of security incident. It covers a broad range of threats, from attacks initiated through emails and websites to information theft, ransomware and attempts to exploit remote-access services.
The country’s first-place ranking for downloader detections is particularly significant.
Downloaders are malicious programs whose main purpose is to install additional components on an infected device. These may include information-stealing tools, ransomware or software enabling criminals to take control of a computer system.
Detecting a downloader may therefore indicate the beginning of a much more extensive infection chain.
Ransomware remains a major threat to Polish businesses
For another consecutive six-month period, Poland ranked among the three countries most frequently targeted by ransomware.
Ransomware encrypts data and demands payment in exchange for restoring access. It has remained one of the most dangerous threats in cyberspace for many years.
Poland’s high position in ransomware detection rankings is not solely the result of external threats. It also reflects weaknesses within Polish businesses.
According to the Cyber Profile of Polish Business 2026 report by ESET and DAGMA IT Security, only 17% of employees know what ransomware is. Half of Polish employees who use computers at work have not received any cybersecurity training in the past five years.
“The financial consequences of failing to invest in cybersecurity can be calculated by estimating the cost of a successful attack,” said Dawid Zięcina of DAGMA IT Security.
“A security strategy should therefore begin with a risk analysis: which attacks are most likely and how much would the company lose if they succeeded?”
“A straightforward calculation combining the probability of a particular threat with the estimated cost of its consequences provides much stronger arguments during budget discussions than references to regulations or general statistics.”
“Once an organisation understands the scale of the risk, it can establish rational priorities, because it is impossible to secure everything at the same time. The key is to identify the most valuable assets and begin investment with their protection.”
Artificial intelligence creates new opportunities for cybercriminals
The AI agent add-ons analysed by ESET included components that used offensive security tools such as Mimikatz and Impacket.
Researchers also identified self-modifying scripts whose behaviour could change after installation.
Some apparently safe add-ons were advertised as security scanners. In practice, however, several used only very basic analysis methods, potentially creating a false sense of security among users.
Artificial intelligence is also beginning to appear directly within malicious software.
ESET identified PromptSpy, the first known Android threat to actively use generative artificial intelligence during its operation.
The malware uses Google’s Gemini model to interpret elements of a device’s interface and adapt its behaviour to different devices and operating environments.
Such cases remain relatively rare, but they demonstrate how AI could make future cyberthreats more flexible and adaptable.
“Instead of relying entirely on new methods and tools, attackers are quickly adapting proven techniques to new platforms, technologies and user behaviour,” said Kamil Sadkowski.
“The number of add-ons developed for AI agents is growing rapidly, simultaneously expanding the potential attack surface.”
Fake error messages lead to real attacks
The ClickFix technique also continued to develop during the first half of 2026.
In this type of attack, criminals display a fake error message or warning about an alleged technical problem. They then provide what appears to be a simple instruction for resolving the issue.
In reality, the victim is tricked into manually running a malicious command.
ClickFix detections increased by 108% between the second half of 2025 and the first half of 2026.
New variants use websites featuring instructions presented as AI-generated content, malicious browser extensions and cloud-service login processes.
A variation known as ConsentFix attempts to steal an authorisation token. In certain scenarios, this may allow criminals to access an account without asking the user to re-enter their password and without triggering an additional login confirmation.
QR codes increasingly lead users into traps
Phishing attacks involving QR codes, known as quishing, also reached record levels.
During the first half of 2026, approximately 11% of detected phishing messages contained a QR code. ESET systems recorded an average of around 100,000 such detections every month.
Attackers use QR codes to conceal the destination address and transfer the interaction to a smartphone, where it may be more difficult for users to verify the full website address.
The widespread use of QR codes for payments, restaurant menus and login systems means that many users scan them automatically without first checking their source.
Ransomware attacks continue, but fewer victims pay
ESET documented more than 100 tools known as EDR killers, which are designed to disable, freeze or blind endpoint detection and response software before the main ransomware component is launched.
More than 60 of these tools exploit vulnerable drivers to interfere with security protections at the operating-system level.
Despite the continued rise in ransomware attacks, the proportion of victims choosing to pay a ransom has fallen to a historically low level.
Industry reports analysed by ESET suggest that between 14% and 28% of attacked organisations paid the demanded ransom.
The country rankings presented in the report refer to detections recorded by ESET security solutions. They should not be interpreted as a complete ranking of all cyberattacks occurring worldwide.
The full ESET Threat Report H1 2026 contains detailed telemetry data, analysis of emerging attack techniques and descriptions of the most important threats recorded between December 2025 and May 2026.
Source: Managerplus.pl





