Fake AI, Real Malware: Attackers Are Impersonating Your Favorite AI Brands

I have been warning for years that AI would become both the weapon and the target. A new report from Sophos confirms the target part is already here, and it is more brazen than I expected.

Sophos X-Ops reviewed 12 months of Managed Detection and Response cases tagged as AI activity. Out of 86 tagged incidents, 38 were genuine adversarial AI activity. Of those 38, 35 were not attackers using AI as a capability. They were attackers faking AI brands to trick people into installing malware.

Let that sink in. The dominant AI cyber threat right now is not a rogue model escaping a lab. It is a fake Claude download site served through a malicious ad, waiting for someone who just wants to try the latest AI coding tool.

The Numbers Are Ugly

Claude was the most frequently abused brand, showing up in 26 of the 30 AI software impersonation cases Sophos reviewed. Attackers typosquatted domains, bought malicious search ads, and set up polished installation guides that walked victims through running obfuscated PowerShell one-liners. In one case, the payload was delivered via an mshta command pulled from a domain that looked like a legitimate versioned download. In another, a claude.msixbundle installer was actually a malware loader.

Beyond fake installers, Sophos found AI-themed browser extensions in the Chrome Web Store impersonating Perplexity. These extensions acted as infostealers, intercepting searches and exfiltrating browsing telemetry in real time. One extension maintained a 4.7-star rating across 67 reviews and claimed 10,000 installs before Google took it down.

The Four Cases That Should Keep You Awake

Sophos also flagged four cases where attackers genuinely used AI as a capability, not just a lure. In one, a Cursor-assisted detection-evasion technique helped malware avoid discovery. In another, an AI coding agent built a custom Slack-controlled remote access trojan. A SonicWall SMA intrusion showed how AI can accelerate ransomware deployment. A fake Claude site delivered a previously undocumented backdoor Sophos named Beagle.

What This Means for Your Organisation

The good news, if there is any, is that these are malware delivery problems, not existential AI risks. Existing endpoint detections and download hygiene controls work against fake AI installers. The bad news is the scale: every new AI release creates a new phishing vector, and the demand for AI tools means users are primed to click without checking.

Practical steps that matter right now:

  • Whitelist approved AI tools. Only allow installations from confirmed vendor domains. Block everything else at the proxy and endpoint layer.
  • Audit browser extensions. AI-themed extensions are an easy social engineering win for attackers. Review installed extensions across your estate weekly.
  • Train users on the new lure. Security awareness programmes still treat fake software downloads as a generic risk. Name the brands: Claude, ChatGPT, Copilot, Perplexity. Make it specific.
  • Monitor for AI-branded C2 infrastructure. Sophos observed command-and-control URLs using AI brand names, such as code[.]verification-claude-cdn[.]beer. Add AI brand keywords to your threat hunting rules.

The broader takeaway is that AI has not created a new category of attack. It has supercharged social engineering. Attackers do not need a better model. They need a better pretext, and right now the AI hype cycle gives them the best pretext in a decade.


“Attackers do not need a better AI model. They need a better pretext, and right now the AI hype cycle gives them the best pretext in a decade.”

Related Reading

The views expressed on this site are my own and do not represent those of any current or former employer. Articles are based on publicly available information and are provided for general educational purposes.

Subscribe

Related articles

440 AI Agents Broke Into 395 Organisations in 26 Seconds. Nobody Stopped Them.

A swarm of 440 AI agents exploited two PaperCut flaws and compromised 395 organisations across 48 countries. The agents reached domain admin in 6 hours and ignored explicit instructions to stay out of 28 countries.

For $3,000 and a Few Days, Researchers Used Claude to Hack OpenAI

Security researchers used Anthropic's Claude AI to hack OpenAI's internal systems for less than $3,000 in tokens. What the HEIF Heist tells us about the new economics of cyber attacks.

The AI Hacking Crisis Is Already Here. Six New Incidents Prove It

OpenAI disclosed six new incidents where its models concealed mistakes, sought unauthorised credentials and uploaded files to the public internet. Cybersecurity experts say the real risk is powerful models meeting poor security controls.

Inside OpenAI’s Log of Misbehaving Models: Rewriting Jailbreaks and Covering Up Errors

OpenAI published six new reports of its models rewriting jailbreak instructions and concealing errors during training, alongside a faster public disclosure framework.

Australia faces growing threat from AI-enabled foreign interference, officials warn

Australia's new nightmare: when AI makes foreign interference "quicker,...
Philip Hall
Philip Hall
Philip Hall is a Sydney-based Cyber AI and Automation leader with more than 30 years of technology experience and a career in cyber security dating back to 2008. His work spans cyber architecture, cloud security, threat intelligence, assurance, incident support, AI-enabled defence and the security of autonomous agents.