Attackers are increasingly impersonating popular AI brands to deliver malware and steal credentials, with Sophos reporting that fake installers and malicious browser extensions tied to names such as ChatGPT, Claude, Copilot, Perplexity, and Gemini now account for a significant share of confirmed AI-related incident cases. In a 12-month review of 86 MDR cases tagged for suspected AI activity, Sophos confirmed 38 as genuine adversarial AI incidents; 35 involved malicious targeting of AI, and 30 specifically involved AI software impersonation. The company said it found no confirmed cases of fully AI-orchestrated intrusions in its telemetry, indicating that the dominant threat remains conventional social engineering wrapped in AI branding.
One recent case investigated by Darktrace used a fake Google Gemini installer to deploy the Vidar infostealer inside an EMEA company network. The campaign abused Google Colab as a trust-building lure before redirecting the victim to a fake "Windows Software Hub" page hosting Download_Google_Gemini_For_Windows.exe; the payload was a newer Go-compiled Vidar variant using Telegram-based infrastructure and the command-and-control domain dtm[.]kijangturbo88[.]top. Darktrace said the malware activity was consistent with browser credential theft and other data theft, and that it blocked the outbound communications and quarantined the affected device, underscoring the need for verified software sources, browser extension controls, supply-chain review, and better visibility into unmanaged systems.

Pull IOCs and campaign context straight into your stack.
10 events from the most recent confirmed update back to the earliest known activity.
The 12-month Sophos MDR review window closed on June 29, 2026, forming the basis for its analysis of attacker abuse of AI brands and other adversarial AI activity.
Sophos X-Ops began the MDR casework review window it later used to analyze suspected AI-related activity, covering cases from July 2, 2025 through June 29, 2026.
In a separate incident, attackers compromised a financial services organization's custom PHP application through SQL injection and deployed a Rust-based remote access Trojan that polled Slack for commands. Sophos linked the malware to a public GitHub repository whose commit history indicated a human developer working with a Claude coding agent.
Darktrace said its Autonomous Response system blocked the malware's communications, including traffic to dtm[.]kijangturbo88[.]top and Telegram-based infrastructure, and quarantined the infected device.
In the Gemini-themed campaign, attackers used a Google Colab-hosted lure that redirected victims to a fake "Windows Software Hub" page hosting Download_Google_Gemini_For_Windows.exe, with a ZIP archive and README instructing users to run the file as administrator and add AV exclusions.
Darktrace investigated an incident on a company network in the EMEA region where a malicious executable posing as a Google Gemini installer delivered a newer Go-compiled Vidar infostealer.
Sophos confirmed execution of a poisoned LiteLLM PyPI package and a claude-mem npm plugin installed through NPX that fetched code from a remote GitHub repository, though it could not determine whether a human or AI agent initiated the installs.
Sophos documented AI-branded social-engineering activity including fake Microsoft Copilot document shares redirecting victims to an EvilProxy adversary-in-the-middle kit, OpenAI-themed credential harvesting, and ClickFix-style prompts that tricked users into running commands.
Sophos investigated a case in which four customers installed a fake Perplexity browser extension distributed through the Chrome Web Store; the extension hijacked searches, redirected traffic through perplexity-ai[.]online, and exfiltrated browsing telemetry.
From its 12-month review, Sophos confirmed 38 AI-related adversarial cases, with 35 involving malicious targeting of AI and 30 specifically involving AI software impersonation such as fake installers and malicious browser extensions.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcecybersecuritynews.com
Open sourcehelpnetsecurity.com
Open sourcesophos.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.