top of page

Over 92,000 malware detections impersonated ChatGPT and other AI services in early 2026

From January to early May 2026, Kaspersky recorded more than 92,000 detections of malware and potentially unwanted applications disguised as popular AI services or AI agents. ChatGPT accounted for 49% of detections, while Claude and Gemini each represented 18%. Kaspersky also identified more than 15,000 malicious samples impersonating AI agent software. No specific CVE is associated with the campaign.

The growing adoption of generative AI is creating a new security risk that does not necessarily originate from ChatGPT, Claude, or Gemini themselves. Instead, cybercriminals are exploiting the names, logos, and popularity of these services to make malicious software appear legitimate.

For enterprises, the impact can extend beyond a single compromised personal device. Employee workstations may already have access to corporate email, SaaS applications, VPN credentials, internal documents, and customer data, meaning a fake AI application can become an initial access point into a wider business environment.

fake-chatgpt-malware-attacks-2026
Warning: fake ChatGPT malware attacks

What happened in the more than 92,000 AI impersonation detections?

Kaspersky reported that its security systems detected more than 92,000 attacks involving malware and potentially unwanted applications, or PUAs, worldwide between January and early May 2026. The malicious files were disguised as AI services or AI-related software.

The figure should not be interpreted as 92,000 individual organizations or users being successfully compromised. It represents security detections recorded by Kaspersky systems.

Among the impersonated brands, ChatGPT appeared most frequently, accounting for 49% of detected activity. Claude and Gemini each represented 18%. VnExpress also reported the findings on August 23, 2026, highlighting the use of fake AI applications as a malware delivery technique.

Metric

Kaspersky data

Security significance

Reporting period

January to early May 2026

Covers the first months of 2026

Total detections

More than 92,000

Includes malware and PUAs disguised as AI tools

ChatGPT impersonation

49%

Most frequently abused AI brand

Claude impersonation

18%

One of the main impersonation lures

Gemini impersonation

18%

One of the main impersonation lures

Fake AI agent samples

More than 15,000

Included multiple malware categories

How do attackers abuse ChatGPT, Claude, and Gemini brands?

The main technique is brand impersonation. Attackers use names, logos, interface elements, or installation packages that resemble legitimate AI services, making malicious files appear trustworthy.

Kaspersky said it had identified more than 15,000 malware samples disguised as AI agent software since the beginning of 2026. The samples included banking trojans, spyware, credential stealers, exploits, and malware downloaders capable of retrieving additional payloads.

In May 2026, Kaspersky Global Research and Analysis Team, or GReAT, linked one campaign to the Silver Fox threat group. According to Kaspersky, fake Claude applications were distributed for Windows, macOS, and Linux. Once executed, the installers could silently deploy malware and enable longer-term access to compromised devices and sensitive information.

👉 Enterprises can review IPSIP Vietnam's analysis of the campaign impersonating ChatGPT to distribute malware through Facebook to understand how trusted brands can be incorporated into social engineering campaigns.

Why are enterprises particularly exposed to fake AI applications?

Risk increases when employees are allowed to download AI tools without an approved software catalog or verification process. The desire to test a new AI agent, plugin, desktop application, or productivity tool can shorten the normal security review process.

OpenAI similarly advises users to install its applications only through official channels or trusted in-app update mechanisms. In 2026 security guidance, OpenAI warned users not to install software carrying the OpenAI, ChatGPT, or Codex name when the installer is delivered through email, messaging services, advertisements, file-sharing platforms, or third-party software download websites.

For enterprises adopting AI at scale, the issue therefore extends beyond the question of whether an AI model itself is secure. Organizations must also determine which AI tools are authorized, where they may be obtained, what data they can access, and what permissions they receive.

👉 IPSIP's analysis of security risks created by the growing use of AI in enterprise environments provides additional context for organizations developing AI usage policies rather than managing each application in isolation.

What should enterprises do now to reduce the risk of fake AI software?

The priority should not be to ban all AI applications. Organizations should instead control how software enters the environment and limit the privileges that an untrusted installer could obtain.

For endpoints that access internal documents, privileged accounts, or critical business applications, unrestricted software installation should be treated as a security control issue.

  • Maintain an approved list of AI services, desktop applications, and AI agents.

  • Allow software downloads only from verified vendor websites, trusted app stores, or approved internal repositories.

  • Remove unnecessary Local Administrator privileges and apply least privilege to standard users.

  • Use application allowlisting or centralized software management on devices handling sensitive data.

  • Deploy EDR/XDR to detect suspicious processes, persistence mechanisms, unusual network activity, and post-installation behavior.

  • Require MFA, preferably phishing-resistant MFA, for email, VPN, administrative accounts, and sensitive SaaS services.

  • Train employees to identify fake AI websites, advertisements, installers, and impersonated brands.

  • If a suspicious installer has already been executed, isolate the endpoint, collect logs, and investigate potentially exposed credentials before reconnecting the device to the network.

What does IPSIP Vietnam's cybersecurity perspective suggest?

Users may be directed toward fake installers or applications through websites, advertisements, social media, messaging platforms, or other distribution channels. Once a user executes the file, malware may establish persistence, steal information, or download additional payloads. Kaspersky observed this model in the fake Claude campaign linked to Silver Fox.

AI Governance should include software governance and distribution controls. A policy that only defines whether employees may use ChatGPT or Gemini is not sufficient. Enterprises should also specify approved versions, official installation channels, permitted data types, access permissions, and monitoring requirements.

For Vietnamese enterprises, the immediate priorities are to standardize approved AI tools, control installation sources, reduce endpoint privileges, and monitor suspicious behavior continuously. AI Governance should therefore be treated as part of cybersecurity governance rather than only as a technology usage policy.

References

Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
Logo-Zalo-Arc.webp
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page