Fake ChatGPT and Claude apps drive surge in AI-Themed cyberattacks

Kaspersky identified more than 92,000 cyberattacks involving malware disguised as agentic AI tools, including fake versions of platforms such as OpenClaw.

 


Cybercriminals are increasingly exploiting the popularity of artificial intelligence platforms to distribute malware and steal sensitive information.

According to Kaspersky, fake applications impersonating ChatGPT, Claude and Gemini accounted for tens of thousands of attack attempts during the first months of 2026.


From January to May 2026, Kaspersky solutions detected more than 92,000 cyberattacks disguised as artificial intelligence tools and services.

According to the company, attackers used well-known AI brands to lure victims into downloading malicious files.

Fake ChatGPT applications accounted for 49% of detected attacks, while Claude and Gemini each represented 18%.

Since the beginning of the year, Kaspersky researchers have also identified more than 15,000 malware samples disguised as agentic AI software, including fake versions of emerging tools such as OpenClaw.

Fake AI applications expand malware and fraud campaigns.

Among the detected threats were banking trojans, spyware, exploits and malware downloaders capable of deploying additional malicious payloads onto compromised devices.

In May 2026, Kaspersky’s Global Research and Analysis Team (GReAT) also identified a new campaign linked to the advanced persistent threat (APT) group Silver Fox.

According to the investigation, attackers distributed fake Claude AI applications for Windows, macOS and Linux targeting users interested in artificial intelligence tools.

The company stated that the malicious installers silently deployed malware, enabling prolonged access to compromised systems and sensitive information.

According to specialists, these campaigns reflect how cybercriminals are increasingly exploiting the trust and popularity surrounding AI platforms to expand both the reach and effectiveness of malicious operations.

Cybercriminals exploit trust in popular AI platforms.

Dmitry Galov, Head of Kaspersky’s Global Research & Analysis Team for Russia and CIS, noted:

“The integration of AI agents into enterprise environments changes the very nature of trust. Every automated action becomes part of a broader chain of systems and data exchanges, meaning security is no longer only about protecting endpoints, but also about controlling how intelligence, permissions and decisions propagate through interconnected AI-driven processes.”

Specialists warn that the growing adoption of artificial intelligence tools is creating new opportunities for phishing campaigns, credential theft and malware distribution through fake applications and fraudulent bots.

Kaspersky recommended that organizations and users rely on AI services from trusted providers and use security solutions capable of blocking phishing sites and preventing malware installation.


Share:
Hosting Web
Most Read