Fake AI Apps Become a Growing Cybersecurity Threat
The global boom in artificial intelligence is creating a new opportunity for cybercriminals: impersonating the tools millions of people are actively searching for and installing.
Fake applications and download pages designed to resemble well-known AI products, including ChatGPT, Claude and Gemini, have been used as bait to distribute malware.
According to cybersecurity company Kaspersky, its systems detected more than 92,000 attacks involving malware and potentially unwanted applications disguised as popular AI agents and services worldwide from January through the beginning of May 2026.
The figures demonstrate how the extraordinary popularity of generative AI has created another powerful social-engineering opportunity for attackers.
Fake ChatGPT Apps Account for Nearly Half of Detected Attacks
Among the AI brands examined by Kaspersky, ChatGPT was the most frequently exploited lure.
Fake ChatGPT applications represented approximately 49% of the detected attacks, while fake Claude and Gemini software each accounted for about 18%.
The numbers do not mean the legitimate AI platforms themselves were infected or compromised. Instead, attackers are exploiting their names, branding and popularity to persuade people to download malicious files.
That distinction is important: the threat originates from impersonators rather than from the genuine ChatGPT, Claude or Gemini services.
More Than 15,000 Malware Samples Disguised as Agentic AI Software
The threat extends beyond conventional chatbot applications.
Kaspersky researchers said they had identified more than 15,000 malware samples masquerading as agentic AI software since the beginning of 2026.
The malicious software identified in the wider campaign included banking trojans, spyware, credential-stealing malware, exploits and downloaders capable of installing additional malicious payloads.
This is particularly significant as interest in AI agents continues to grow. Users searching for new tools may be less familiar with their legitimate websites and distribution channels, making convincing copies potentially harder to recognize.
Fake Websites Can Look Surprisingly Convincing
Cybercriminals do not necessarily rely on obviously suspicious websites.
In one separate investigation, Malwarebytes discovered a fake website impersonating OpenAI's ChatGPT download experience. The page used familiar branding and offered apparent Windows and macOS downloads.
According to the researchers, Windows visitors could receive credential-stealing malware, while the macOS download delivered Odyssey Stealer, malware designed to target information including browser data and cryptocurrency wallets.
The sophistication of these sites highlights a fundamental problem: a polished design and HTTPS padlock are no longer enough to establish that a software download is genuine.
Claude Has Also Been Impersonated
Claude users have faced similar threats.
Malwarebytes documented a fake Claude website offering what appeared to be a Windows "Pro" version. The downloaded package could launch a functioning Claude application while simultaneously deploying a malicious chain in the background.
Researchers said the campaign used DLL sideloading and ultimately deployed PlugX malware capable of providing attackers with remote access to an infected machine.
Allowing the expected application to function normally can make this type of attack particularly deceptive because users may have little reason to suspect that malicious activity is taking place behind the scenes.
Search Results and Malicious Advertising Can Increase the Risk
One reason AI impersonation campaigns can succeed is the way users discover new software.
People unfamiliar with the official download location may search for phrases such as "download ChatGPT," "Claude desktop" or an AI coding utility and follow advertisements or unfamiliar search results.
Security researchers have documented campaigns using search-engine optimization poisoning and malicious advertising to steer users toward fake AI-related websites. Fake Gemini and Claude Code pages, for example, have previously been used to distribute information-stealing malware.
Attackers have also abused shared AI-chat pages and trusted domains as intermediate steps in malware-delivery campaigns, making suspicious activity harder for ordinary users to identify immediately.
Why AI Brands Are Attractive to Cybercriminals
AI applications provide attackers with several advantages as impersonation targets.
The industry is moving quickly, new products and features appear frequently, and users may be installing AI software for the first time. Unlike established applications whose official download locations are widely recognized, people may not immediately know where a newly released AI tool should legitimately come from.
The combination of curiosity, rapid product launches and intense demand creates an environment in which fake "Pro," "desktop," "free" or newly released versions can appear believable.
The danger is therefore less about artificial intelligence creating an entirely new category of malware and more about criminals adapting established phishing, impersonation and malware-distribution techniques to one of technology's fastest-growing markets.
How Users Can Reduce the Risk
Users should verify the source before installing AI applications. Downloads should come from the provider's official website or a legitimate platform specifically identified by that provider.
OpenAI, for example, has explicitly advised users to obtain its applications through official webpages or trusted in-app update mechanisms rather than unexpected links in emails, messages, advertisements, file-sharing links or third-party download sites.
Unexpected installers, misspelled domains, unusual ZIP files, requests to disable security protections and instructions asking users to paste unfamiliar commands into a terminal or PowerShell window should all be treated cautiously.
Balanced Analysis: AI Is the Lure, Not Necessarily the Attack Technology
The growing number of AI-themed malware campaigns should not be interpreted as evidence that legitimate AI applications are inherently unsafe.
In many documented cases, criminals are simply borrowing the names and visual identities of trusted technology companies while relying on established cyberattack techniques.
The scale of the Kaspersky detections nevertheless shows why AI impersonation deserves attention. More than 92,000 detected attacks in just the first months of 2026 suggest that well-known AI brands have become valuable tools for social engineering.
As AI adoption expands, cybersecurity awareness will increasingly need to include not only how people use artificial intelligence, but also where they obtain the software in the first place.
This article is based on reporting published by Business Standard.






