Sophos Finds Fake AI Installers Dominated Malware Cases

Summary
Sophos reviewed 38 AI-related MDR cases from July 2025 to June 2026 and found most involved attackers abusing AI brands, especially through fake installers, to deliver malware. Evidence of AI-assisted attack tooling was limited and often circumstantial.
Key points
- Sophos confirmed 34 cases of adversarial AI activity among 86 MDR cases tagged for AI, then added four cases identified through further investigations, for 38 total.
- Malicious targeting of AI accounted for 35 cases; AI software impersonation accounted for 30, with Claude the most-used brand lure in 26 cases.
- Fake installers often used malicious ads or poisoned search results to direct users to typosquatted sites, where InstallFix or ClickFix instructions prompted them to run commands that installed malware.
- Other cases involved AI-themed browser extensions that stole information or hijacked searches, credential-phishing lures, and two malicious AI-related software dependencies.
- The clearest confirmed AI-assisted tooling case was a human-directed AI coding agent used to build a custom Slack-controlled RAT. Possible AI-generated ransomware tooling was supported only by circumstantial evidence.
- Sophos found no confirmed cases of AI agents autonomously driving attacks in its telemetry. It recommends verified vendor downloads, extension and dependency reviews, behavioral protections, and closing endpoint and legacy-application coverage gaps.
Article Details
- Publisher
- Sophos Research
- Report Period
- 2025-07-02 to 2026-06-29
- Scope
- Sophos MDR cases involving AI, supplemented by Counter Threat Unit intelligence and SophosLabs research.
- Sample Size
- 86 AI-tagged MDR cases reviewed individually; four additional cases identified through analysts' investigations.
- Key Statistics
- Of 86 AI-tagged MDR cases reviewed, 34 were confirmed as genuine adversarial AI activity. Four additional cases brought the dataset to 38.
- The other 52 tagged cases comprised 25 benign AI developer-tooling detections and 27 cases with only incidental AI keywords.
- 35 of the 38 included cases involved malicious targeting of AI products, brands, or ecosystems.
- AI software impersonation accounted for 30 of 38 cases; the Claude brand was used as a lure in 26 cases.
- Four customers installed a fake Perplexity browser extension investigated by Sophos.
- Recommendations
- Acquire AI software only from verified vendor domains and block known typosquats.
- Monitor for malicious command execution, installer behavior, and payload delivery rather than relying on AI branding to identify attacks.
- Audit AI-themed browser extensions against publisher reputation.
- Apply dependency review and supply-chain governance to AI software dependencies.
- Close endpoint monitoring gaps and prioritize application-layer testing, patching, and web application firewall coverage for bespoke and legacy web applications.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | code[.]verification-claude-cdn[.]beer | Command-and-control host used in an AI-themed social-engineering case. |
| DOMAIN | download-version[.]1-9-18[.]com | Payload source for an mshta command presented by a fake Claude installation site. |
| DOMAIN | perplexity-ai[.]online | Domain through which a malicious Perplexity-impersonating extension redirected browser searches. |
MITRE ATT&CK
T1059.001 · PowerShellAttack chains used PowerShell one-liners and encoded PowerShell scripts.T1190 · Exploit Public-Facing ApplicationAn attacker gained access to a financial services organization through SQL injection against a bespoke PHP application.T1218.005 · MshtaA fake Claude site instructed a victim to run an mshta command that retrieved a payload.T1574.002 · DLL Side-LoadingFake Claude delivery chains used malicious DLL side-loading.
CVE
People
Threat Actors
APT28One of the designations presented for the actor to which CERT-UA attributed LAMEHUG with medium confidence; the article also gives UAC-0001 and IRON TWILIGHT.IRON TWILIGHTOne of the designations presented for the actor to which CERT-UA attributed LAMEHUG with medium confidence; the article also gives APT28 and UAC-0001.The GentlemenRansomware group whose leaked internal chats reportedly promoted an uncensored Qwen3.5 build.UAC-0001One of the designations presented for the actor to which CERT-UA attributed LAMEHUG with medium confidence; the article also gives APT28 and IRON TWILIGHT.
Malware
BeagleClaude site that delivered a DLL-sideloading chain ending ina previously undocumented backdoor we dubbed ‘Beagle.’LAMEHUGnot, as of this writing, confirmed a case in our own telemetry, although a prominent public example is LAMEHUG, which CERT-UA attributed with medium confidence to APT28/UAC-0001 (IRON TWILIGHT) and described as usingLummaStealerIn other, related cases we observed LummaStealer being delivered through the same AI-branded infrastructure, using the classic ClickFix method of a fake CAPTCHA page, rather than the InstallFix technique described above.
Vendors
AnthropicWe found no confirmed instances of this, although the recent OpenAI-HuggingFace incident and Anthropic disclosures suggest the capability exists.OpenAIthat funneled victims to an EvilProxy adversary-in-the-middle (AitM) kit, and campaigns impersonating the OpenAI brand to harvest logins.SonicWalla further four cases through analysts’ investigations: a Cursor-assisted detection-evasion case, a SonicWall SMA ransomware intrusion, a custom Slack-controlled RAT built with an AI coding agent, and a fake ClaudeSophosSophos X-Ops reviewed a year of Managed Detection and Response (MDR) cases tagged as ‘AI activity.’ Of the 34 cases that held up, nearly all were attackers creating fake versions of legitimate AI sites and software to
Products
ChatGPTthe surge in demand for AI software by faking the software itself: names users trust, like Claude, ChatGPT, and Copilot, become delivery vehicles for malware. For defenders that is good news – or at least, notChatGPT Atlasa ChatGPT share-link lure that matched public reporting. Separately, we observed a case in which a ChatGPT Atlas user was tricked into running a curl command that installed an infostealer.Claudeare exploiting the surge in demand for AI software by faking the software itself: names users trust, like Claude, ChatGPT, and Copilot, become delivery vehicles for malware. For defenders that is good news – or atCopilotin demand for AI software by faking the software itself: names users trust, like Claude, ChatGPT, and Copilot, become delivery vehicles for malware. For defenders that is good news – or at least, not all bad –CursorAdditionally, we identified a further four cases through analysts’ investigations: a Cursor-assisted detection-evasion case, a SonicWall SMA ransomware intrusion, a custom Slack-controlled RAT built with an AI codingLiteLLMtwo cases in which threat actors were targeting the AI software supply chain. In the first, a poisoned LiteLLM PyPI package executed on an endpoint, and in the second, a claude-mem npm plugin installed through NPXPerplexityIn a recent case Sophos investigated, four customers installed a fake Perplexity extension that functioned as a browser hijacker, intercepting searches, and exfiltrating browsing telemetry in real time throughQwen2.5-Coder-32B-Instructattributed with medium confidence to APT28/UAC-0001 (IRON TWILIGHT) and described as using Qwen2.5-Coder-32B-Instruct via Hugging Face to generate commands at runtime.Qwen3.5– macdeMac-Studio – in a Mandarin-language README file, in a Hugging Face repository for fine-tuning Qwen3.5. We cannot confirm this was actually the same device or operator, so we treated it only as a weakSonicWall SMAa further four cases through analysts’ investigations: a Cursor-assisted detection-evasion case, a SonicWall SMA ransomware intrusion, a custom Slack-controlled RAT built with an AI coding agent, and a fake Claude
Tools
Chiseland used them to run discovery commands, attempt credential access, and execute an off-the-shelf build of Chisel, an open-source TCP tunnelling tool.EvilProxyfor credential phishing – including a fake Microsoft Copilot document share that funneled victims to an EvilProxy adversary-in-the-middle (AitM) kit, and campaigns impersonating the OpenAI brand to harvest logins.superpowersThe repository included documentation for superpowers, an open-source agentic skills framework for AI coding agents, and a planning document that set out the malware’s architecture: a Rust Windows binary that polls a