LIVE · cybersecurity feed
Live wire
malware

Attackers impersonate popular AI brands to spread malware

Attackers are impersonating popular AI brands like Perplexity, Claude, ChatGPT, and Copilot to spread information stealers, backdoors, malicious browser extensions, and other malware, according to Sophos. Overview of MDR cases with AI involvement (Source: Sophos) Sophos X-Ops reviewed 12 months of managed detection and response cases, covering July 2, 2025 through June 29, 2026. Of 86 cases initia

zeroday.news ·

Cybersecurity researchers have identified a widespread campaign where attackers impersonate popular artificial intelligence brands such as Perplexity, Claude, ChatGPT, and Copilot to distribute various forms of malware, including information stealers, backdoors, and malicious browser extensions. The findings are based on an analysis of 38 confirmed incidents over a 12-month period, from July 2025 to June 2026.

In 35 of these cases, the malicious activity directly targeted AI products, brands, or their associated ecosystems. Software impersonation was the most common tactic, accounting for 30 incidents. Claude was the most frequently impersonated brand, appearing in 26 cases.

Many incidents involved a technique dubbed "InstallFix," which mimics a legitimate software installation process. Unlike "ClickFix" attacks that simulate error or verification steps, InstallFix pages present detailed, step-by-step installation guides. These guides ultimately instruct users to copy and execute obfuscated commands, leading to malware infection. For instance, a fake Claude website was observed guiding a victim through an `mshta` command that retrieved a payload from a deceptive domain. The download was packaged as a Windows application, either `claude` or `claude.msixbundle`, which, upon execution, fetched code that ran in memory and attempted to compromise browser processes. Other variants included a booby-trapped `Claude Setup.zip` archive and a repackaged `claude.exe` acting as a malware loader.

Beyond direct software impersonation, attackers also leveraged malicious browser extensions. Several extensions posing as AI assistants, including one marketed as "AI Sidebar with DeepSeek, ChatGPT, Claude," were found to function as information stealers, communicating with command-and-control infrastructure. In one notable case, four customers installed a fake Perplexity extension distributed via the Chrome Web Store. This extension hijacked search queries, rerouted them through a lookalike domain, and transmitted browsing data to attacker infrastructure in real time. The extension had accumulated a 4.7-star rating from 67 reviews and claimed over 10,000 users, lending it an appearance of legitimacy.

The investigation also uncovered instances where attackers appeared to use AI for malware development. In one case involving a financial services organization, researchers identified a remote access Trojan (RAT) written in Rust that communicated via Slack. The malware was linked to a public GitHub repository whose commit history indicated collaboration between a human account and a Claude coding agent. This RAT was designed to poll a Slack channel for commands, with planned capabilities including command execution, file retrieval, configuration data downloads, persistence through scheduled tasks, and the potential to open a reverse shell. The development of this malware was tracked over several days through the repository's commit history.

Additionally, during a separate ransomware investigation, researchers observed potential signs of AI-generated code, characterized by unusually detailed comments and structured PowerShell code. However, these characteristics were considered circumstantial evidence and did not definitively confirm AI involvement in code generation.

Despite these findings, there is no evidence to suggest that AI is autonomously conducting attacks. The observed use of AI by attackers has been at the "lightest-touch end of the scale," primarily in generating code, with human operators remaining in control of the attack process. The most effective defenses against these impersonation tactics rely on conventional protections against malicious delivery and payload behaviors, rather than AI-specific characteristics. Users are strongly advised to install AI tools exclusively from confirmed vendor domains to mitigate risk.

malwareai
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

AWS Security makes an inscrutable choice

Quarantining leaked credentials is not good enough

ai

Say it once: introducing Bot Preference Sync

Cloudflare's new Bot Preference Sync automatically aligns your robots.txt file with your AI bot policies for Search, Agent, and Training. Easily manage which bots access your content without maintaining static files.

cloud security

Cloudflare Launches Bot Preference Sync for AI Traffic Management

Cloudflare has introduced Bot Preference Sync, a new feature designed to simplify the management of AI bot traffic. This tool automatically updates a website's robots.txt file to align with the user's AI bot configuration settings. The goal is to prevent discrepancies between stated preferences and enforced rules, ensuring better control over how AI crawlers access and use website content.

patch

Friday Squid Blogging: Neon Flying Squid

The neon flying squid can fly in formation. The shoal of about 100 squid rose unexpectedly from a patch of the Pacific Ocean around 370 miles from Tokyo and glided near the boat for about 30 metres. The astonished researchers were the first to capture photographs of such a thing, which looked like the early stages of an alien invasion. They were probably neon flying squid (Ommastrephes bartramii),

security

Lawmakers call for investigation into impact of CISA staffing cuts

Lawmakers say little is known about how recent cuts have impacted CISA and how the knowledge that was lost has been replaced.

breach

Apollo discloses data breach from ongoing wave of attacks hitting financial sector

The private equity firm said attackers broke into some of its cloud platforms during a five-day period in early July, compromising sensitive personal data. The post Apollo discloses data breach from ongoing wave of attacks hitting financial sector appeared first on CyberScoop.