Cybercriminals Mimic Popular AI Brands to Distribute Malware

www.news4hackers.com-cybercriminals-mimic-popular-ai-brands-to-distribute-malware-cybercriminals-mimic-popular-ai-brands-to-distribute-malware

Attackers are leveraging deceptive tactics to distribute malicious software by mimicking well-known artificial intelligence platforms, according to a report from Sophos.

Sophos Report on AI-Related Cyberattacks

Sophos X-Ops reviewed 12 months of incident data spanning from July 2, 2025, to June 29, 2026. Of the 86 cases initially flagged for AI-related involvement, 34 were confirmed as malicious activities. Additional investigations added four more incidents, bringing the total to 38. In 35 of these cases, threat actors specifically targeted AI products, brands, or associated infrastructure.

Software Impersonation and Fake Installation Processes

Software impersonation accounted for 30 of the 38 incidents, with the Claude brand being the most frequently imitated, appearing in 26 cases. A common method involved the use of fake installation processes, such as the InstallFix technique. Unlike traditional ClickFix attacks that rely on deceptive verification steps, InstallFix presents users with a seemingly legitimate, step-by-step setup guide. These pages often conclude with users executing obfuscated commands that deploy malware.

In one instance, a counterfeit Claude website guided victims through an mshta command that retrieved a malicious payload from a domain designed to mimic the official site.

Browser Extensions as a Malicious Vector

Browser extensions also emerged as a vector for malicious activity. Researchers identified several extensions masquerading as AI assistants, including one labeled AI Sidebar with DeepSeek, ChatGPT, and Claude. These extensions functioned as information stealers, transmitting user data to attacker-controlled infrastructure. A case involving a fake Perplexity extension distributed through the Chrome Web Store highlighted the scale of this threat. The extension, which had a 4.7-star rating and 10,000 installations, altered search traffic to redirect it through a counterfeit domain, exfiltrating browsing data in real time.

AI Tools in Malware Development

AI tools were also implicated in malware development. A financial services organization’s breach revealed a remote access Trojan communicating via Slack. The malware, linked to a public GitHub repository, showed evidence of collaboration between a human developer and a Claude coding agent. Written in Rust, the tool monitored a Slack channel for commands, with capabilities including file retrieval and command execution.

During a separate ransomware investigation, Sophos noted potential signs of AI-generated code, such as detailed comments and structured PowerShell scripts. However, the firm cautioned that these features alone did not confirm AI involvement.

Key Takeaways and Recommendations

Sophos emphasized that defensive measures against such attacks focus on identifying conventional malware delivery patterns rather than AI-specific characteristics. The report advised users to obtain AI tools exclusively from verified vendor domains. The analysis underscores the evolving tactics of cybercriminals, who increasingly exploit AI brand recognition to deceive users. The findings reinforce the importance of verifying software sources and monitoring for anomalous behavior in AI-related systems.

“The analysis underscores the evolving tactics of cybercriminals, who increasingly exploit AI brand recognition to deceive users. The findings reinforce the importance of verifying software sources and monitoring for anomalous behavior in AI-related systems.”

Conclusion

Sophos stated that its telemetry found no evidence of autonomous AI-driven attacks, with human operators maintaining control over AI-assisted tools. The report highlights the need for vigilance in identifying deceptive tactics and emphasizes the role of user education and secure software practices in mitigating risks.


Blog Image

About Author

en_USEnglish