When trust in AI becomes a weakness
An application named ChatGPT, Claude or Gemini appears online, with an interface similar to a real product, advertised as having additional features or being allowed to use it for free. For someone who wants to quickly try a new artificial intelligence (AI) tool, downloading and installing can only take a few minutes.
But behind that familiar symbol may not be artificial intelligence. Experts from the Kaspersky GReAT research group have detected about 92,000 counterfeit AI services attacks in 2026. Of which, 49% counterfeit ChatGPT, equivalent to more than 45,000 cases; 18% counterfeit Claude and 18% counterfeit Gemini.
This figure shows a worrying trend: The more people trust and use AI, the more famous AI brands become attractive "bait" for cybercriminals.
Unlike many previous forms of attack that required bad actors to exploit a technical vulnerability, AI impersonation can directly hit user psychology. When seeing the name of a familiar service, users easily assume that the software is safe, thereby skipping the necessary checks.
Security experts have discovered more than 15,000 samples of malware disguised as AI agent software. These include Trojans, spyware, exploitation codes, malware download codes, malware installation codes and backdoor malware. Although wearing the shell of an AI tool, their real function is still to perform harmful acts. Just downloading and running a fake application once, users can unintentionally open the device to the attacker.
The first danger is data.
Computers and phones now not only contain photos or contacts. For office workers, the device can store work documents, customer information, email accounts, internal business data. For individual users, it can be passwords, exchange history, private files and many other sensitive information.
When malware is installed on the device, those data are at risk of being stolen. More dangerously, some malware can set up remote access, meaning that the attacker is likely to continue to intrude and control the device after the user thinks they have just installed an AI application.
The risk does not stop at an individual. If a computer infected with malware is a device used in a business, a careless operation by an employee can become the starting point for a larger intrusion.
According to reports, the case of the SilverFox attack group using the fake Claude application to infiltrate organizations. SilverFox is identified as one of the most active APT groups, using the form of spreading malware through many stages and building its own infrastructure for each step of the attack to reduce the likelihood of detection.
This group's recent campaign targets businesses in the fields of industry, consulting, commerce and transportation in many countries. One method used is fraudulent emails forging tax check notifications, requiring recipients to download a file believed to contain a "list of tax violations". In just the first 2 months of 2026, Kaspersky recorded more than 1,600 malicious emails related to this campaign.
It is noteworthy that attackers know how to combine two factors that are very easy to create trust: seemingly official documents and AI tools being widely used.
The recipient may not suspect when an application named Claude appears during document processing, but "Claude" itself may be malware.
According to security experts cited in the document, the Asia-Pacific region is where SilverFox is operating strongly, with the number of attacks far exceeding the total recorded in the remaining regions. This further shows that users and businesses in the region need to be particularly cautious about AI products of unknown origin.
At another level, AI is not only used as a "cover" for malware but also begins to participate deeper into the attack process itself.
This poses a new challenge: Users not only have to face increasingly real-like scams but also attacks that can become more flexible, automated and difficult to detect.
The more popular, the more easily exploited AI brands become
There is a paradox that is emerging. That is, the more famous AI platforms are, the more people they use, the greater their brand value. But also because of that, they are more easily exploited by cybercriminals.
When a person sees a strange application with a name unknown, the natural reflex may be to be wary. But if that application is named ChatGPT, Gemini or Claude, the alert level is easily reduced.
The attack on Axios mentioned in the document shows that cybercriminals may target software components that many people and businesses trust. Axios is a popular JavaScript library, with more than 100 million downloads per week and integrated in more than 170,000 software packages. The attacker is believed to have infiltrated the project manager's computer, accessed the account on the source code and released a version containing malware.
In an environment where AI agents are increasingly integrated into the software development process and given more access, this risk is even more noteworthy. A fake tool or a component infected with malware can become a path to access internal resources.
Do not skip the verification step for convenience
The greatest attraction of AI is convenience. But the psychology of wanting a faster, freeer tool or more features can make users easily fall into the trap.
First of all, users need to be careful with AI software that is spread through strange links, emails, advertisements of unknown origin or installation files shared outside of official channels. The fact that an application uses the correct name and logo of a famous service does not mean it is a real product.
For businesses, the requirements are even higher. Kaspersky experts recommend setting clear security boundaries between external content and internal resources used in software development; and controlling not only the integrated development environment but also extensions, workspaces and rights granted to AI agents. Businesses also need to control how software is put into the development environment and monitor activities taking place in the system.
Experts also propose an "AI-to-AI" approach, using AI technology itself to proactively detect threats, combined with a Zero Trust architecture and a comprehensive defense system for devices, networks, applications and data.
AI is helping people work faster and opening up many new opportunities. But the more trusted a technology is, the more likely it will be exploited to create more sophisticated traps.
For users, the big risk sometimes does not lie in not knowing how to use AI, but in being too trusting in something just named AI. A click to install fake software can only take a few seconds. The consequences of it can be data loss, loss of device control and even opening the door for bad guys to infiltrate the entire business system.
In the AI era, knowing how to use technology is necessary. But knowing how to verify whether the technology you are using is really what it claims to be, is becoming an equally important safety skill.
