Threat actors are increasingly exploiting prominent artificial intelligence brands including Perplexity, Claude, ChatGPT, and Copilot to distribute information stealers, backdoors, and malicious browser extensions.
According to managed detection and response research published by Sophos X-Ops covering incidents between July 2, 2025, and June 29, 2026, threat actors frequently target AI products and user ecosystems through deceptive software impersonation. Out of 38 confirmed AI-involved security incidents analyzed in the dataset, 30 focused on brand and software impersonation, with Anthropic’s Claude appearing in 26 of the reviewed cases.
Many campaigns leverage InstallFix tactics, an evolution of the ClickFix methodology. While traditional ClickFix tricks users with fake errors or CAPTCHAs, InstallFix utilizes step-by-step installation guides that prompt victims to copy and execute obfuscated commands. Investigators observed fake Claude sites distributing malicious Windows MSIX bundles and ZIP archives designed to inject payloads directly into memory and hollow out legitimate browser processes.
Cybercriminals have also weaponized official distribution channels by publishing fraudulent browser extensions on marketplaces like the Chrome Web Store. One malicious listing masquerading as an AI assistant for Perplexity accumulated a 4.7-star rating and roughly 10,000 installs, actively hijacking search queries and exfiltrating browsing data in real time.
In addition to brand spoofing, security researchers identified instances where attackers utilized AI-generated code to construct attack tooling. One financial sector incident revealed a Rust-based remote access Trojan controlled via Slack, whose GitHub commit history demonstrated active collaboration between a human operator and a Claude coding agent.
“From a defensive perspective, in the impersonation cases we reviewed, the decisive protections were based on conventional delivery and payload behaviors, rather than AI-specific characteristics,” Sophos researchers stated. “The earliest and best defense remains unchanged: install AI tooling only from confirmed vendor domains.”