I have been warning for years that AI would become both the weapon and the target. A new report from Sophos confirms the target part is already here, and it is more brazen than I expected.
Sophos X-Ops reviewed 12 months of Managed Detection and Response cases tagged as AI activity. Out of 86 tagged incidents, 38 were genuine adversarial AI activity. Of those 38, 35 were not attackers using AI as a capability. They were attackers faking AI brands to trick people into installing malware.
Let that sink in. The dominant AI cyber threat right now is not a rogue model escaping a lab. It is a fake Claude download site served through a malicious ad, waiting for someone who just wants to try the latest AI coding tool.
The Numbers Are Ugly
Claude was the most frequently abused brand, showing up in 26 of the 30 AI software impersonation cases Sophos reviewed. Attackers typosquatted domains, bought malicious search ads, and set up polished installation guides that walked victims through running obfuscated PowerShell one-liners. In one case, the payload was delivered via an mshta command pulled from a domain that looked like a legitimate versioned download. In another, a claude.msixbundle installer was actually a malware loader.
Beyond fake installers, Sophos found AI-themed browser extensions in the Chrome Web Store impersonating Perplexity. These extensions acted as infostealers, intercepting searches and exfiltrating browsing telemetry in real time. One extension maintained a 4.7-star rating across 67 reviews and claimed 10,000 installs before Google took it down.
The Four Cases That Should Keep You Awake
Sophos also flagged four cases where attackers genuinely used AI as a capability, not just a lure. In one, a Cursor-assisted detection-evasion technique helped malware avoid discovery. In another, an AI coding agent built a custom Slack-controlled remote access trojan. A SonicWall SMA intrusion showed how AI can accelerate ransomware deployment. A fake Claude site delivered a previously undocumented backdoor Sophos named Beagle.
What This Means for Your Organisation
The good news, if there is any, is that these are malware delivery problems, not existential AI risks. Existing endpoint detections and download hygiene controls work against fake AI installers. The bad news is the scale: every new AI release creates a new phishing vector, and the demand for AI tools means users are primed to click without checking.
Practical steps that matter right now:
- Whitelist approved AI tools. Only allow installations from confirmed vendor domains. Block everything else at the proxy and endpoint layer.
- Audit browser extensions. AI-themed extensions are an easy social engineering win for attackers. Review installed extensions across your estate weekly.
- Train users on the new lure. Security awareness programmes still treat fake software downloads as a generic risk. Name the brands: Claude, ChatGPT, Copilot, Perplexity. Make it specific.
- Monitor for AI-branded C2 infrastructure. Sophos observed command-and-control URLs using AI brand names, such as code[.]verification-claude-cdn[.]beer. Add AI brand keywords to your threat hunting rules.
The broader takeaway is that AI has not created a new category of attack. It has supercharged social engineering. Attackers do not need a better model. They need a better pretext, and right now the AI hype cycle gives them the best pretext in a decade.
“Attackers do not need a better AI model. They need a better pretext, and right now the AI hype cycle gives them the best pretext in a decade.”
Related Reading
- AI Agents, Copilot and the New Security Risk: When Helpful Becomes Dangerous
- Nine Out of Ten Companies Are Not Ready for AI-Driven Attacks
- IBM Report: AI-Generated Breaches Now Cost $5.72 Million
The views expressed on this site are my own and do not represent those of any current or former employer. Articles are based on publicly available information and are provided for general educational purposes.

