Fake AI, Real Malware: Attackers Impersonating AI Brands
Sophos, Wednesday, August 19th, 2026
Sophos X-Ops reviewed a year of MDR cases and found attackers overwhelmingly faking AI sites and installers to spread malware.
Sophos X-Ops reviewed 12 months of Managed Detection and Response casework tagged as AI activity, from July 2025 to June 2026. Of 86 flagged cases, 34 were confirmed as genuine adversarial AI activity, plus four more identified by analysts, for a total of 38.
Nearly all involved attackers creating fake versions of legitimate AI sites and software, with AI software impersonation accounting for 30 of the 38 cases and the Claude brand abused in 26.
Many used InstallFix, a ClickFix variant in which a typosquatted site reached via malicious ads presents a polished installation guide ending in obfuscated commands. Sophos concludes conventional delivery and payload detections remain the decisive protection.