AI Chatbots Claude, ChatGPT, Copilot Used in Malware Attacks
Key Takeaways Cybercriminals are leveraging the popularity of AI chatbots like Claude, ChatGPT, and Microsoft Copilot to distribute malware. Attackers create fake download pages, malicious browser...
Key Takeaways
- Cybercriminals are leveraging the popularity of AI chatbots like Claude, ChatGPT, and Microsoft Copilot to distribute malware.
- Attackers create fake download pages, malicious browser extensions, and poisoned search results, primarily impersonating AI brands rather than using AI for the attacks themselves.
- The primary goal is to trick users into installing backdoors, password stealers, or browser hijackers, impacting both individuals and organizations through data theft.
- Sophos identified 30 cases of software impersonation out of 38 hostile AI-related incidents reviewed over a year.
- Users should strictly download AI tools from official vendor websites and organizations should audit AI-related browser extensions and monitor for unusual system activity.
AI Brand Impersonation Fuels Malware Distribution
Cybercriminals are increasingly exploiting the widespread adoption and trust in prominent artificial intelligence platforms to propagate malware. Rather than employing AI in their attack methodologies, threat actors are masquerading as popular AI brands to trick users into downloading malicious software. This tactic leverages the perceived legitimacy of names like Claude, ChatGPT, and Microsoft Copilot as a direct route to compromise systems.
Table Of Content
Sophos researchers, after analyzing a year’s worth of managed detection and response (MDR) investigations, uncovered a significant trend: attackers are predominantly using brand impersonation. Out of 38 confirmed cases involving hostile AI activity, 30 specifically involved fraudulent software, indicating a clear preference for abusing established AI brands to facilitate attacks. These campaigns target individuals seeking AI tools, coding assistants, and productivity features. Victims often encounter these malicious lures through fake download portals, deceptive browser extensions, sponsored search advertisements, or even shared AI conversations, leading them to inadvertently install various forms of malware, including backdoors, password-stealing tools, or browser hijackers.
The ramifications extend beyond individual users, posing a substantial threat to organizations. Compromised browser sessions, stolen credentials, private files, and cryptocurrency wallet data can provide attackers with a critical foothold, enabling further infiltration into broader business networks. Sophos said in a report that a key factor contributing to the success of these campaigns is the inherent trust users place in installation prompts featuring familiar AI branding.
Claude, ChatGPT, and Copilot as Malware Bait
Sophos’s analysis revealed that Claude was the most frequently exploited AI brand, appearing as a lure in 26 distinct incidents. Threat actors crafted counterfeit pages for Claude, ChatGPT, and Microsoft Copilot to disseminate malware. This was achieved through malicious advertisements, manipulated search engine results, and domains meticulously designed to mimic legitimate vendor websites.
A common technique observed in many of these incidents was “InstallFix,” a variation of the ClickFix social engineering method. Unlike traditional fake error pages, InstallFix presents victims with a seemingly professional installation guide that instructs them to copy and execute a specific command. This command then initiates the download or execution of the actual malware payload.
In one notable instance, a deceptive Claude website directed users to run an mshta command. This command was designed to retrieve a Windows application package, either named claude or claude.msixbundle. A subsequent command then executed code directly in memory, attempting to conceal its operations within a browser process. This method mirrors broader malware operations where users are tricked into executing commands themselves, transforming legitimate user actions into the initial stages of a compromise.
Sophos also documented the delivery of LummaStealer via AI-branded infrastructure. Additionally, a fraudulent “Claude Setup.zip” archive was found to deploy a malicious libcef.dll file. Another repackaged claude.exe functioned as a malware loader, while a more sophisticated fake site employed DLL sideloading to install the previously undocumented Beagle backdoor. The most effective initial defense against these threats remains straightforward: always obtain AI tools exclusively from their official, confirmed vendor domains, as fake pages can be highly convincing in their replication of official branding and download processes.
Browser Extensions and Trusted Platforms Exploited
The malicious activities are not confined to fake installers. Researchers also discovered AI-themed browser extensions that, while appearing to offer useful assistance, were secretly collecting browser data and communicating with attacker-controlled command-and-control servers. Given that extensions often possess extensive access to user sessions and stored credentials, they represent a particularly attractive target for data exfiltration.
In one investigation, four distinct customers inadvertently installed a fake Perplexity extension. This extension hijacked search queries and transmitted browsing telemetry in real-time. It redirected searches through perplexity-ai[.]online and presented a landing page post-installation, thereby simulating a genuine AI service.
The threat extends even to seemingly legitimate sources. Sophos found one fraudulent extension listed in the Chrome Web Store that boasted a 4.7-star rating, 67 reviews, and over 10,000 installations. This manufactured credibility can significantly lower user suspicion, reminiscent of other malicious AI extensions that targeted enterprises by harvesting conversations and browsing data.
Furthermore, attackers are increasingly placing their lures on trusted services. Several macOS campaigns shifted from using fake brand pages to distributing malware through shared conversations hosted on legitimate ChatGPT infrastructure. Victims were then instructed to paste specific Terminal commands, a technique also observed in abused Claude shared chats used to propagate information-stealing malware.
What You Should Do
- Verify Sources: Always download AI tools and software exclusively from the official websites of the respective vendors. Double-check URLs for any subtle misspellings or anomalies.
- Audit Browser Extensions: Regularly review and audit all installed browser extensions, especially those related to AI. Verify the publisher’s legitimacy before installation and remove any extensions that are not essential or appear suspicious.
- Monitor System Activity: Security teams should actively monitor for unusual command execution, suspicious PowerShell activity, and browser processes attempting to launch system utilities. These behaviors are often detectable even when the initial infection vector uses a trusted AI brand.
- Implement Supply Chain Controls: Treat AI dependencies with the same rigorous supply-chain controls applied to other software packages. Be wary of poisoned packages and malicious plugins that fetch remote code, as automated development tools can accelerate the time from publication to execution of malicious code.
- Educate Users: Conduct awareness training for employees on the risks of social engineering, phishing, and the importance of verifying software sources, particularly concerning popular AI technologies.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.