Over 92,000 malware detections impersonated ChatGPT and other AI services in early 2026
- Evelyn Carter

- 1 day ago
- 4 min read
From January to early May 2026, Kaspersky recorded more than 92,000 detections of malware and potentially unwanted applications disguised as popular AI services or AI agents. ChatGPT accounted for 49% of detections, while Claude and Gemini each represented 18%. Kaspersky also identified more than 15,000 malicious samples impersonating AI agent software. No specific CVE is associated with the campaign.
The growing adoption of generative AI is creating a new security risk that does not necessarily originate from ChatGPT, Claude, or Gemini themselves. Instead, cybercriminals are exploiting the names, logos, and popularity of these services to make malicious software appear legitimate.
For enterprises, the impact can extend beyond a single compromised personal device. Employee workstations may already have access to corporate email, SaaS applications, VPN credentials, internal documents, and customer data, meaning a fake AI application can become an initial access point into a wider business environment.

What happened in the more than 92,000 AI impersonation detections?
Kaspersky reported that its security systems detected more than 92,000 attacks involving malware and potentially unwanted applications, or PUAs, worldwide between January and early May 2026. The malicious files were disguised as AI services or AI-related software.
The figure should not be interpreted as 92,000 individual organizations or users being successfully compromised. It represents security detections recorded by Kaspersky systems.
Among the impersonated brands, ChatGPT appeared most frequently, accounting for 49% of detected activity. Claude and Gemini each represented 18%. VnExpress also reported the findings on August 23, 2026, highlighting the use of fake AI applications as a malware delivery technique.
Metric | Kaspersky data | Security significance |
Reporting period | January to early May 2026 | Covers the first months of 2026 |
Total detections | More than 92,000 | Includes malware and PUAs disguised as AI tools |
ChatGPT impersonation | 49% | Most frequently abused AI brand |
Claude impersonation | 18% | One of the main impersonation lures |
Gemini impersonation | 18% | One of the main impersonation lures |
Fake AI agent samples | More than 15,000 | Included multiple malware categories |
How do attackers abuse ChatGPT, Claude, and Gemini brands?
The main technique is brand impersonation. Attackers use names, logos, interface elements, or installation packages that resemble legitimate AI services, making malicious files appear trustworthy.
Kaspersky said it had identified more than 15,000 malware samples disguised as AI agent software since the beginning of 2026. The samples included banking trojans, spyware, credential stealers, exploits, and malware downloaders capable of retrieving additional payloads.
In May 2026, Kaspersky Global Research and Analysis Team, or GReAT, linked one campaign to the Silver Fox threat group. According to Kaspersky, fake Claude applications were distributed for Windows, macOS, and Linux. Once executed, the installers could silently deploy malware and enable longer-term access to compromised devices and sensitive information.
👉 Enterprises can review IPSIP Vietnam's analysis of the campaign impersonating ChatGPT to distribute malware through Facebook to understand how trusted brands can be incorporated into social engineering campaigns.
Why are enterprises particularly exposed to fake AI applications?
Risk increases when employees are allowed to download AI tools without an approved software catalog or verification process. The desire to test a new AI agent, plugin, desktop application, or productivity tool can shorten the normal security review process.
OpenAI similarly advises users to install its applications only through official channels or trusted in-app update mechanisms. In 2026 security guidance, OpenAI warned users not to install software carrying the OpenAI, ChatGPT, or Codex name when the installer is delivered through email, messaging services, advertisements, file-sharing platforms, or third-party software download websites.
For enterprises adopting AI at scale, the issue therefore extends beyond the question of whether an AI model itself is secure. Organizations must also determine which AI tools are authorized, where they may be obtained, what data they can access, and what permissions they receive.
👉 IPSIP's analysis of security risks created by the growing use of AI in enterprise environments provides additional context for organizations developing AI usage policies rather than managing each application in isolation.
What should enterprises do now to reduce the risk of fake AI software?
The priority should not be to ban all AI applications. Organizations should instead control how software enters the environment and limit the privileges that an untrusted installer could obtain.
For endpoints that access internal documents, privileged accounts, or critical business applications, unrestricted software installation should be treated as a security control issue.
Maintain an approved list of AI services, desktop applications, and AI agents.
Allow software downloads only from verified vendor websites, trusted app stores, or approved internal repositories.
Remove unnecessary Local Administrator privileges and apply least privilege to standard users.
Use application allowlisting or centralized software management on devices handling sensitive data.
Deploy EDR/XDR to detect suspicious processes, persistence mechanisms, unusual network activity, and post-installation behavior.
Require MFA, preferably phishing-resistant MFA, for email, VPN, administrative accounts, and sensitive SaaS services.
Train employees to identify fake AI websites, advertisements, installers, and impersonated brands.
If a suspicious installer has already been executed, isolate the endpoint, collect logs, and investigate potentially exposed credentials before reconnecting the device to the network.
What does IPSIP Vietnam's cybersecurity perspective suggest?
Users may be directed toward fake installers or applications through websites, advertisements, social media, messaging platforms, or other distribution channels. Once a user executes the file, malware may establish persistence, steal information, or download additional payloads. Kaspersky observed this model in the fake Claude campaign linked to Silver Fox.
AI Governance should include software governance and distribution controls. A policy that only defines whether employees may use ChatGPT or Gemini is not sufficient. Enterprises should also specify approved versions, official installation channels, permitted data types, access permissions, and monitoring requirements.
For Vietnamese enterprises, the immediate priorities are to standardize approved AI tools, control installation sources, reduce endpoint privileges, and monitor suspicious behavior continuously. AI Governance should therefore be treated as part of cybersecurity governance rather than only as a technology usage policy.
References









Comments