Sophos Finds Fake AI Installers Dominated Malware Cases

· Original article ↗

Summary

Sophos reviewed 38 AI-related MDR cases from July 2025 to June 2026 and found most involved attackers abusing AI brands, especially through fake installers, to deliver malware. Evidence of AI-assisted attack tooling was limited and often circumstantial.

Key points

  • Sophos confirmed 34 cases of adversarial AI activity among 86 MDR cases tagged for AI, then added four cases identified through further investigations, for 38 total.
  • Malicious targeting of AI accounted for 35 cases; AI software impersonation accounted for 30, with Claude the most-used brand lure in 26 cases.
  • Fake installers often used malicious ads or poisoned search results to direct users to typosquatted sites, where InstallFix or ClickFix instructions prompted them to run commands that installed malware.
  • Other cases involved AI-themed browser extensions that stole information or hijacked searches, credential-phishing lures, and two malicious AI-related software dependencies.
  • The clearest confirmed AI-assisted tooling case was a human-directed AI coding agent used to build a custom Slack-controlled RAT. Possible AI-generated ransomware tooling was supported only by circumstantial evidence.
  • Sophos found no confirmed cases of AI agents autonomously driving attacks in its telemetry. It recommends verified vendor downloads, extension and dependency reviews, behavioral protections, and closing endpoint and legacy-application coverage gaps.

Article Details

Publisher
Sophos Research
Report Period
2025-07-02 to 2026-06-29
Scope
Sophos MDR cases involving AI, supplemented by Counter Threat Unit intelligence and SophosLabs research.
Sample Size
86 AI-tagged MDR cases reviewed individually; four additional cases identified through analysts' investigations.
Key Statistics
  • Of 86 AI-tagged MDR cases reviewed, 34 were confirmed as genuine adversarial AI activity. Four additional cases brought the dataset to 38.
  • The other 52 tagged cases comprised 25 benign AI developer-tooling detections and 27 cases with only incidental AI keywords.
  • 35 of the 38 included cases involved malicious targeting of AI products, brands, or ecosystems.
  • AI software impersonation accounted for 30 of 38 cases; the Claude brand was used as a lure in 26 cases.
  • Four customers installed a fake Perplexity browser extension investigated by Sophos.
Recommendations
  • Acquire AI software only from verified vendor domains and block known typosquats.
  • Monitor for malicious command execution, installer behavior, and payload delivery rather than relying on AI branding to identify attacks.
  • Audit AI-themed browser extensions against publisher reputation.
  • Apply dependency review and supply-chain governance to AI software dependencies.
  • Close endpoint monitoring gaps and prioritize application-layer testing, patching, and web application firewall coverage for bespoke and legacy web applications.

Indicators of compromise

TypeIndicatorContext
DOMAINcode[.]verification-claude-cdn[.]beerCommand-and-control host used in an AI-themed social-engineering case.
DOMAINdownload-version[.]1-9-18[.]comPayload source for an mshta command presented by a fake Claude installation site.
DOMAINperplexity-ai[.]onlineDomain through which a malicious Perplexity-impersonating extension redirected browser searches.

MITRE ATT&CK

CVE

People

Threat Actors

Malware

Vendors

Products

ChatGPTthe surge in demand for AI software by faking the software itself: names users trust, like Claude, ChatGPT, and Copilot, become delivery vehicles for malware. For defenders that is good news – or at least, notChatGPT Atlasa ChatGPT share-link lure that matched public reporting. Separately, we observed a case in which a ChatGPT Atlas user was tricked into running a curl command that installed an infostealer.Claudeare exploiting the surge in demand for AI software by faking the software itself: names users trust, like Claude, ChatGPT, and Copilot, become delivery vehicles for malware. For defenders that is good news – or atCopilotin demand for AI software by faking the software itself: names users trust, like Claude, ChatGPT, and Copilot, become delivery vehicles for malware. For defenders that is good news – or at least, not all bad –CursorAdditionally, we identified a further four cases through analysts’ investigations: a Cursor-assisted detection-evasion case, a SonicWall SMA ransomware intrusion, a custom Slack-controlled RAT built with an AI codingLiteLLMtwo cases in which threat actors were targeting the AI software supply chain. In the first, a poisoned LiteLLM PyPI package executed on an endpoint, and in the second, a claude-mem npm plugin installed through NPXPerplexityIn a recent case Sophos investigated, four customers installed a fake Perplexity extension that functioned as a browser hijacker, intercepting searches, and exfiltrating browsing telemetry in real time throughQwen2.5-Coder-32B-Instructattributed with medium confidence to APT28/UAC-0001 (IRON TWILIGHT) and described as using Qwen2.5-Coder-32B-Instruct via Hugging Face to generate commands at runtime.Qwen3.5– macdeMac-Studio – in a Mandarin-language README file, in a Hugging Face repository for fine-tuning Qwen3.5. We cannot confirm this was actually the same device or operator, so we treated it only as a weakSonicWall SMAa further four cases through analysts’ investigations: a Cursor-assisted detection-evasion case, a SonicWall SMA ransomware intrusion, a custom Slack-controlled RAT built with an AI coding agent, and a fake Claude

Tools

Industries

Related Articles