A stranger knocking on your door wearing a familiar uniform is more likely to be let in than one wearing none at all. Cybercriminals understand this simple truth better than most. Cyber attackers have long abused the brands of banks, software companies and online services to make malicious files appear trustworthy. Artificial intelligence (AI) is now becoming one of their favourite disguises.
At the Cyber Security Weekend (CSW) conference, Sergey Lozhkin, Kaspersky’s Head of the Global Research and Analysis Team for the APAC and META regions, laid out how cybercriminals are increasingly disguising malware as trusted artificial intelligence applications. His warning was blunt: attackers are not inventing new tricks. They are simply finding new disguises for old ones, and the AI boom has handed them the perfect costume.
In 2026, cyber attackers are not knocking as strangers. They are arriving dressed in the very tools millions of people now trust with their work and their data.
Trust is becoming the attack surface
Generative AI has become part of daily working life for millions of people across the world. That popularity has made AI brand names among the most valuable pieces of digital real estate a criminal can imitate. Cyberthreats mimicking ChatGPT increased by 115% during the first four months of 2025 compared to the same period the previous year, according to Kaspersky research.
The firm found that in 2025, nearly 8,500 users from small and medium-sized businesses (SMBs) faced cyberattacks where malicious or unwanted software was disguised as popular online productivity tools. Based on the unique malicious and unwanted files observed, the most common lures included Zoom and Microsoft Office, with newer AI-based services like ChatGPT and DeepSeek being increasingly exploited by attackers.
Kaspersky’s Global Research and Analysis Team says artificial intelligence is one of the biggest drivers shaping cyber threats in 2026, with criminals increasingly using large language models to generate phishing emails, write malicious code and create supporting content for attacks. Lozhkin has said AI is reshaping attacker workflows and accelerating their operations, lowering the time and cost needed to develop and adapt malicious tools.
Fake installers, real damage
The most common trick is deceptively simple: a fake download page. From January to early May 2026, security researchers detected more than 92,000 separate attacks worldwide involving malware and unwanted applications disguised as popular AI tools, with fake ChatGPT applications accounting for nearly half of all detected incidents and Claude and Gemini impersonations each making up 18 percent.
Sophos, the British cybersecurity firm, reached a similar conclusion after a year-long review of its own casework. Reviewing twelve months of managed detection and response cases, Sophos confirmed dozens of genuine incidents in which trusted AI brand names such as Claude, ChatGPT and Copilot were turned into delivery vehicles for malware. Investigators found tampered installer files, including a Claude Setup archive that staged a malicious loader file, and a repackaged Claude executable that was in fact a malware loader. In one case, a fake Claude website delivered a DLL-sideloading chain ending in a previously undocumented backdoor, which researchers dubbed “Beagle.”
Developer-focused tools are a particular target. Kaspersky has separately flagged a malvertising campaign built around Claude Code, Anthropic’s coding assistant. People searching for terms such as “Claude Code download” were shown malicious adverts at the top of search results, leading to websites that closely resembled the genuine pages built by Anthropic and OpenAI. Because installing such tools typically involves pasting a command into a terminal rather than running a conventional installer, the deception is harder to spot. Victims on Windows machines were served the Amatera infostealer, while those on Mac systems received AMOS, malware designed to expose developers to the risk of leaked source code, corporate data and credentials.
When the platform itself is the bait
Some campaigns go a step further, abusing the legitimate infrastructure of AI companies themselves. Researchers at Push Security have documented attackers hijacking the “shared chat” feature on claude.ai. One shared Claude.ai conversation, styled as a “Claude Code on Mac” installation guide and falsely attributed to Apple Support, contained a command that, once pasted into a terminal, downloaded and executed malware. Because the web address itself is genuine, even a cautious user checking the URL before clicking would see nothing suspicious.
A related campaign, tracked by the threat-hunting firm Huntress, showed how far attackers are prepared to go. Victims searching for how to install Claude on a Mac were served sponsored results leading to a weaponised Claude.ai shared conversation dressed up as an Apple Support guide, which ultimately triggered a six-stage attack chain culminating in the MacSync Stealer.
Microsoft has documented the phishing side of the same problem. Microsoft Threat Intelligence has identified multiple phishing and malvertising campaigns impersonating ChatGPT, Anthropic’s Claude and DeepSeek to steal credentials, financial data and authentication tokens, stressing that none of these campaigns represents any actual compromise of the AI services themselves. In one instance, Microsoft detected a ChatGPT-themed campaign that sent thousands of emails warning recipients their ChatGPT Plus subscription would be downgraded unless payment details were updated, routing victims through several intermediary services before a fake payment page harvested their card details.
Browser extensions and mobile clones
The threat is not confined to desktop installers. Malicious browser extensions marketed as AI sidebars have also surfaced. Sophos found extensions marketed as AI sidebars for DeepSeek, ChatGPT and Claude that in fact acted as infostealers, communicating with attacker-controlled servers. One fake Perplexity extension, distributed through the official Chrome Web Store, carried a superficially credible rating, dozens of reviews and thousands of installs, before hijacking browser searches and exfiltrating browsing data in real time.
Mobile users are not spared either. Security researchers have uncovered malicious ChatGPT clone applications capable of persistent surveillance and credential theft, distributed through third-party app stores with polished graphics designed to look like genuine AI products. Earlier research by the threat intelligence firm Cyble found dozens of such apps circulating on official and unofficial platforms, some engaged in billing fraud and others hiding spyware behind an AI assistant’s interface.
Beyond disguise: AI as a genuine tool for attackers
Lozhkin’s warning was not limited to impersonation. He and his colleagues have also pointed to a second, more troubling trend: AI being used directly to build and refine malicious code. Kaspersky researchers cited campaigns linked to the FunkSec group, which used AI-assisted development to build Rust-based malware capable of stealing data, encrypting files and manipulating system processes. Separately, the company has warned that generative models can rewrite malware in different programming languages or architectures, making malicious code harder to detect and faster to deploy at scale.
The most striking illustration came from an attack on Mexican government institutions. The attack on Mexican government institutions by a single operator between December 2025 and February 2026 is widely considered a watershed moment in AI-assisted cybercrime.
Israeli cybersecurity firm Gambit Security has revealed that threat actors leveraged Claude Code, an AI-powered coding assistant, to build cyberattack tools. The attackers used the AI system to generate intrusion scripts and ultimately exfiltrated more than 150GB of data from systems belonging to Mexican government agencies. The incident highlights the growing risk of generative AI being weaponised in real-world cyber operations.
What organisations and users should do
For all the sophistication of the branding, the underlying attack methods remain familiar: malicious adverts, poisoned search results, fake download pages, booby-trapped browser extensions and phishing emails. Sophos notes that this is, in one sense, good news for defenders, because malware delivered this way is a problem that existing security controls are designed to address. The company advised users to install AI tooling only from confirmed vendor domains.
Cybersecurity experts advised organisations to restrict AI software downloads to verified vendor domains, block known imitation websites, and train staff to treat unsolicited terminal commands — however official they appear — with suspicion. Legitimate AI companies generally do not require users to paste installation commands copied from a chat conversation or a third-party page.
The key security question should no longer be, “Does this look like AI?” It should be, “Who made it, where did it come from, what can it access and what will it do?”
Cyber criminals do not always need to invent a new trick. Sometimes they only need to disguise an old one as something people already trust.


