Fake AI apps fuel surge in malware attacks, says Kaspersky

TechnologyCybersecurityFake AI apps fuel surge in malware attacks, says Kaspersky

Cybercriminals are increasingly exploiting the popularity of artificial intelligence services to distribute malware, according to new findings from Kaspersky. From January to early May 2026, the cybersecurity company detected more than 92,000 attacks involving malware and potentially unwanted applications disguised as popular AI agents and AI services.

The findings, presented during Kaspersky HORIZONS 2026 in Rome, highlight how threat actors are leveraging trusted AI brands to trick users into downloading malicious software. Fake ChatGPT applications accounted for nearly half of all detected attacks at 49%, while fake Claude and Gemini applications each represented 18%.

Researchers also identified more than 15,000 malware samples masquerading as AI software, including fake versions of emerging tools such as OpenClaw. These samples included banking trojans, spyware, exploits, and malware downloaders capable of deploying additional malicious payloads.

Silver Fox Campaign Targets AI Users

In May 2026, Kaspersky’s Global Research and Analysis Team uncovered a campaign linked to the Silver Fox advanced persistent threat group. Attackers distributed fake Claude AI applications for Windows, macOS, and Linux, targeting users searching for AI tools.

Once launched, the malicious installers silently deployed malware onto victims’ devices, potentially enabling long-term access to compromised systems and sensitive information.

AI Changes the Security Landscape

Kaspersky warns that the growing adoption of AI agents introduces new security considerations for both organizations and consumers. As automated systems become more deeply integrated into business processes, trust must extend beyond endpoints to include how intelligence, permissions, and decisions move across interconnected environments.

“Users should also keep in mind that attackers are actively leveraging popular AI services as a lure to steal victims’ confidential data and funds,” said Dmitry Galov, head of Russia and CIS units at Kaspersky GReAT.

Recommendations for Organizations

To address evolving threats, Kaspersky recommends deploying security platforms that provide real-time protection, threat visibility, investigation capabilities, and advanced response tools. The company also advises organizations to strengthen threat intelligence capabilities and consider managed security services when internal cybersecurity resources are limited.

Staying Safe as an AI User

For consumers, Kaspersky recommends using AI services only from reputable providers with established privacy and security practices. Users should avoid downloading unknown AI applications or interacting with anonymous AI bots that may be designed to harvest personal information.

The company also advises maintaining up-to-date security software capable of blocking phishing sites and preventing malware from being installed.

Related Posts