Fake AI, Real Malware: Attackers Are Impersonating Your Favorite AI Brands

I have been warning for years that AI would become both the weapon and the target. A new report from Sophos confirms the target part is already here, and it is more brazen than I expected.

Sophos X-Ops reviewed 12 months of Managed Detection and Response cases tagged as AI activity. Out of 86 tagged incidents, 38 were genuine adversarial AI activity. Of those 38, 35 were not attackers using AI as a capability. They were attackers faking AI brands to trick people into installing malware.

Let that sink in. The dominant AI cyber threat right now is not a rogue model escaping a lab. It is a fake Claude download site served through a malicious ad, waiting for someone who just wants to try the latest AI coding tool.

The Numbers Are Ugly

Claude was the most frequently abused brand, showing up in 26 of the 30 AI software impersonation cases Sophos reviewed. Attackers typosquatted domains, bought malicious search ads, and set up polished installation guides that walked victims through running obfuscated PowerShell one-liners. In one case, the payload was delivered via an mshta command pulled from a domain that looked like a legitimate versioned download. In another, a claude.msixbundle installer was actually a malware loader.

Beyond fake installers, Sophos found AI-themed browser extensions in the Chrome Web Store impersonating Perplexity. These extensions acted as infostealers, intercepting searches and exfiltrating browsing telemetry in real time. One extension maintained a 4.7-star rating across 67 reviews and claimed 10,000 installs before Google took it down.

The Four Cases That Should Keep You Awake

Sophos also flagged four cases where attackers genuinely used AI as a capability, not just a lure. In one, a Cursor-assisted detection-evasion technique helped malware avoid discovery. In another, an AI coding agent built a custom Slack-controlled remote access trojan. A SonicWall SMA intrusion showed how AI can accelerate ransomware deployment. A fake Claude site delivered a previously undocumented backdoor Sophos named Beagle.

What This Means for Your Organisation

The good news, if there is any, is that these are malware delivery problems, not existential AI risks. Existing endpoint detections and download hygiene controls work against fake AI installers. The bad news is the scale: every new AI release creates a new phishing vector, and the demand for AI tools means users are primed to click without checking.

Practical steps that matter right now:

  • Whitelist approved AI tools. Only allow installations from confirmed vendor domains. Block everything else at the proxy and endpoint layer.
  • Audit browser extensions. AI-themed extensions are an easy social engineering win for attackers. Review installed extensions across your estate weekly.
  • Train users on the new lure. Security awareness programmes still treat fake software downloads as a generic risk. Name the brands: Claude, ChatGPT, Copilot, Perplexity. Make it specific.
  • Monitor for AI-branded C2 infrastructure. Sophos observed command-and-control URLs using AI brand names, such as code[.]verification-claude-cdn[.]beer. Add AI brand keywords to your threat hunting rules.

The broader takeaway is that AI has not created a new category of attack. It has supercharged social engineering. Attackers do not need a better model. They need a better pretext, and right now the AI hype cycle gives them the best pretext in a decade.


“Attackers do not need a better AI model. They need a better pretext, and right now the AI hype cycle gives them the best pretext in a decade.”

Related Reading

Subscribe

Related articles

OpenAI Claims a $1M Millennium Prize With a Secret Model. The Credit Fight Is Only Beginning

OpenAI says an unreleased internal model ran 10,000 agents for 88 hours to prove the Navier-Stokes equations, one of the US$1 million Millennium Prize problems. Two mathematicians who spent a year on the same path are asking hard questions about credit and training data.

Rogue OpenAI Agents Used 10+ More Sites as Secret Message Boards

A week after the German wiki revelation, independent researchers told Reuters the same swarm of OpenAI agents used more than 10 other sites to chat between May and July. The collusion problem is bigger, and less visible, than the company has admitted.

Hidden Prompt Injection Is Hijacking AI Agents. The Poison Is in Your PDFs

New research shows hidden instructions inside document metadata, emails and images can silently hijack the AI agents businesses now trust with sensitive work. Here's how the attack works, and what you can do before the poison spreads.

3.1 Agent-Workdays Per Human Day: Inside OpenAI’s Push to Self-Improving AI

OpenAI says its automated research intern milestone is here, and the lab now logs 3.1 agent-workdays for every human workday. The company is also calling for mandatory public tracking of progress toward self-improving AI. The numbers matter far beyond one lab.
Phil Hall
Phil Hall
Philip Hall is a Sydney-based Cyber AI and Automation leader with more than 30 years of technology experience and a career in cyber security dating back to 2008. His work spans cyber architecture, cloud security, threat intelligence, assurance, incident support, AI-enabled defence and the security of autonomous agents.