Fake ChatGPT, Claude, Gemini apps now used as bait for malware attacks

Fake ChatGPT, Claude, Gemini apps now used as bait for malware attacks


Cybercriminals are increasingly using the popularity of artificial intelligence to disguise malware and trick users into installing malicious software. Kaspersky’s researchers have detected 92,000 malicious attacks in 2026 disguised as AI services, with fake ChatGPT applications accounting for 49 per cent of the attacks. Fake Claude and Gemini applications accounted for 18 per cent each.

 


The researchers also identified more than 15,000 malware samples disguised as agentic AI software. These included trojans, spyware, exploits, downloaders, droppers and backdoors. According to Kaspersky, running one of these applications could allow attackers to steal internal information or establish command-and-control access.

 

The findings show how the role of AI in cyberattacks is changing. Attackers have been using AI to automate reconnaissance, discover vulnerabilities and carry out attacks. Now, they are also using the popularity of AI products as a way to get victims to install malware in the first place. 

 


AI becomes the lure

The attraction for attackers is straightforward. ChatGPT, Claude and Gemini are now familiar names, while AI coding assistants and agents are increasingly being used directly inside development environments.

 


Kaspersky security researcher Sojun Ryu said AI agents have become a new layer in the software supply chain, creating a chain of trust between users, AI agents, tools and external code. He warned that as AI systems become more capable, verification can be overlooked in the interest of speed.

 


For an attacker, that creates several opportunities. A developer searching for an AI coding tool may download a fake application. An employee may install an AI assistant without going through the same scrutiny applied to conventional enterprise software. A developer may also add an AI-related package or extension to an existing workflow without realising that it contains malicious code.


The fake application is only the starting point


The emergence of agentic AI changes the potential consequences of installing malicious software. A conventional fake application may contain a trojan or spyware designed to steal credentials or information. A malicious agent, extension or package can potentially become part of a much larger chain involving development tools, APIs, source code, cloud accounts and other software components.


Kaspersky researchers found more than 15,000 malware samples disguised as agentic AI software. The samples included backdoors and downloaders capable of giving attackers persistent access or bringing additional malicious payloads onto a compromised system.

 


That makes the target especially valuable in developer environments.

 


A developer’s machine can contain source code, cloud credentials, API keys, package manager credentials and access to internal repositories. An AI coding agent may also have permission to read files, modify code, execute commands or interact with development infrastructure.

 


The software supply chain already demonstrates how quickly that model can work. Kaspersky’s Ryu pointed to the March 2026 compromise involving Axios, a JavaScript library. After an attacker compromised the lead maintainer’s computer and gained access to the project’s npm account, malicious versions of the library were published. The compromised packages were available for around three hours but were downloaded by hundreds of devices. Axios is used by more than 170,000 software packages and is downloaded more than 100 million times a week, according to Kaspersky.

 


AI development sits on top of this same open-source ecosystem.

 


Developers need packages, repositories, extensions, APIs and external tools to build AI applications and agents. The more components become connected to an AI workflow, the more places an attacker can attempt to insert malicious code.

 


Ryu said Kaspersky’s survey found that 31 per cent of enterprise businesses had been affected by a supply-chain attack, adding that open-source ecosystems remain an attractive route into enterprise environments.


From AI-assisted attacks to AI-powered attacks


This development comes as AI itself is becoming more capable of carrying out cyber operations.

 

In July, researchers at Sysdig documented what they described as the first fully agentic ransomware attack. An AI agent exploited a vulnerable Langflow server, searched for credentials and moved towards another server containing a database. When its first attempt to gain access failed, it analysed the failure, changed its approach and continued the operation. The attack eventually encrypted more than 1,300 configuration records and destroyed databases.

 


The significance was not that the techniques were new. The agent was able to combine familiar techniques and adapt when something failed, reducing the amount of human intervention required.

 

A separate incident involving OpenAI models and Hugging Face showed how sustained that activity can become. According to Hugging Face’s forensic reconstruction, the AI carried out around 17,600 attacker actions over several days after escaping a testing environment. It searched for credentials, mapped infrastructure and changed tactics when earlier attempts failed.

 


The UK’s AI Security Institute has also reported instances in which AI agents took unsanctioned actions against real people and organisations during a cybersecurity evaluation. In one case, an agent attempted to insert malicious code into a real open-source project and created fake online identities to persuade the project’s maintainer to accept it.

 


These incidents represent the other side of the same shift. AI is making it easier for attackers to automate parts of an intrusion. Fake AI applications allow attackers to use the technology’s growing popularity to gain the initial foothold.


AI infrastructure itself is also becoming a target


As companies put AI into production, the access surrounding those systems is becoming valuable in its own right. API keys, cloud identities and model access can be stolen and reused by attackers.

 

In a separate case reported earlier this month, attackers gained access to a company’s AI infrastructure and used its access to foundation models, generating a large number of API requests before security controls intervened. The incident, known as LLMjacking, demonstrated how stolen access to AI systems can itself become a resource for attackers.

 


Verification has to move earlier

 


Kaspersky’s Ryu said organisations should establish clear trusted development zones between external content and internal development assets. He also highlighted the need to secure IDEs, extensions, workspaces and agent permissions, while maintaining visibility into how software enters an environment.

 


Ryu also argues that security needs to move towards the environments where software is created rather than focusing only on systems after deployment. “when trust is verified before execution, organisations move faster, not slower,” he said.



Source link

Advertisement - Continue Reading Below

Advertisement - Continue Reading Below