Fake AI software accounted for 30 of 38 attacks, while Sophos found only one clear case of a human using an AI coding agent to build malware.
Attackers are using fake AI software that imitates popular tools to infect computers and steal data, according to a Sophos review of 12 months of security cases.
Sophos examined cases recorded between July 2, 2025, and June 29, 2026. Of the 38 cases involving attackers and AI, 30 involved software that impersonated legitimate AI products. The Claude brand was used as the lure in 26 cases.
The findings do not indicate that Anthropic’s Claude was compromised or used to conduct those attacks. Instead, attackers copied trusted branding to persuade people to install malware or surrender information.
Fake AI software installers were the weapon of choice
Many victims reached lookalike AI websites through malicious advertisements or manipulated search results. The sites presented convincing installation instructions that directed users to copy and run commands on their computers.
Those commands installed malware rather than the promised AI tool. In one case, a fake Claude site delivered previously undocumented software that gave attackers access to the infected computer. Other sites distributed LummaStealer, malware designed to steal information.
Sophos also found fake files presented as Claude installers, including a repackaged application that was actually a malware loader.
Browser extensions created another route
Attackers also offered browser extensions that claimed to provide access to AI assistants. Some extensions instead stole information or sent data to attacker-controlled systems.
In one Sophos investigation, four customers installed a fake Perplexity extension that redirected searches and transmitted browsing activity to the attackers. The extension was available through the Chrome Web Store and showed a 4.7-star rating, 67 reviews, and 10,000 installs, making it appear legitimate.
Sophos also identified an extension marketed as an AI sidebar for DeepSeek, ChatGPT, and Claude that functioned as information-stealing malware.
Sophos found limited use of AI to build attacks
Sophos found one clear case in which a human attacker used an AI coding agent to build custom malware. The company recovered the source code and its development history, which showed a human directing an AI agent to create software that could receive commands through Slack and control infected computers.
The human remained in charge of the operation. Sophos found no confirmed cases in its own data of AI independently directing an attack with little human involvement.
Sophos said the attacks did not require new AI-specific defenses. Conventional security controls detected the malware based on how it was delivered and what it did after installation. Sophos recommended that organizations limit AI software downloads to verified vendor websites, review AI-themed browser extensions, and apply existing software supply-chain controls to AI tools.

