A new favorite disguise, and it’s not a bank logo or a shipping notification. It’s Claude, ChatGPT, Copilot, and Perplexity.
According to a yearlong review of Managed Detection and Response (MDR) casework by Sophos X-Ops, attackers are systematically impersonating trusted AI brands to distribute malware, turning the world’s AI boom into a ready-made social-engineering playbook.
Sophos X-Ops analyzed 86 MDR cases tagged with “AI activity” between July 2025 and June 2026, confirming 34 as genuine adversarial AI activity, later expanded to 38 with additional intelligence findings.
Hackers Exploit Claude, ChatGPT & Copilot Brands to Attack
The overwhelming majority, 35 cases, fell under what the researchers call “malicious targeting of AI,” meaning attackers weaponized AI branding and ecosystems rather than using AI itself as an attack tool.
Claude emerged as the most abused brand, appearing in 26 of the reviewed cases. The dominant technique was “InstallFix,” a variant of the well-documented ClickFix social engineering method.

Instead of a fake CAPTCHA, victims searching for AI coding tools land on typosquatted sites via malicious ads, then follow polished, step-by-step “installation guides” that end with them copying and running obfuscated commands, ultimately delivering malware like LummaStealer or, in one notable case, a previously undocumented backdoor dubbed “Beagle.”
Beyond fake installers, researchers found malicious browser extensions marketed as AI assistants that functioned as infostealers.
One fake Perplexity extension, distributed through the Chrome Web Store with a 4.7-star rating and 10,000 installs, hijacked searches and exfiltrated browsing telemetry through attacker-controlled infrastructure, a campaign that correlated with prior Microsoft reporting.
AI branding also surfaced purely as bait in phishing flows, including a fake Microsoft Copilot document-share lure that funnels victims into an EvilProxy adversary-in-the-middle kit and OpenAI-themed credential-harvesting campaigns.
The report’s most striking case involved a custom Remote Access Trojan controlled via Slack, built with direct assistance from an AI coding agent.
Sophos recovered the malware’s GitHub repository, showing commit history from both a human operator and a “claude” account contributing code alongside them, the clearest documented instance to date of an AI agent co-developing active attack tooling.

Separately, a ransomware intrusion via a compromised SonicWall SMA appliance (exploiting CVE-2026-15409 and CVE-2026-15410) showed circumstantial signs of AI-generated PowerShell, including templated, verbose comments and Mandarin-language artifacts linked to an uncensored Qwen3.5 model build previously promoted within the Gentlemen ransomware group’s internal chats.
Notably absent from the dataset were fully “AI-orchestrated” attacks, where an autonomous agent drives the entire kill chain with minimal human oversight.
Researchers point to recent incidents involving OpenAI and Anthropic test agents crossing into production systems as evidence the capability exists, even if criminal adoption remains uneven and often “clumsy.”
Mitigation
Sophos recommends organizations:
- Restrict AI software installs to verified vendor domains and block typosquats
- Audit AI-themed browser extensions against publisher reputation
- Bring AI dependencies under standard supply-chain governance
- Close MDR and monitoring gaps on legacy or unmanaged devices
- Harden custom web applications against injection attacks
The takeaway for defenders is reassuring in one sense: these attacks succeed through conventional delivery and payload behavior, not novel AI-specific tradecraft. Existing detection and download hygiene still work. The brand changes, but the blocking still holds.
Site: Thecyberdef.com
Follow TheCyberDef on Google News, LinkedIn & X for the latest cybersecurity updates. Stay informed.