Over 92,000 cyberattacks hidden behind fake AI tools detected
From January to early May 2026, the solutions of Kaspersky More than 92,000 cyberattacks disguised as popular artificial intelligence (AI) agents and services have been detected. Cybercriminals exploited trusted brands to lure victims into downloading malicious files. Fake ChatGPT applications accounted for 49% of all detected attacks, while Claude and Gemini each accounted for 18%. Kaspersky presented these findings during Kaspersky HORIZONS, its flagship annual conference in Europe, held on May 19 in Rome, where the company highlighted the emerging risks facing organizations and critical infrastructure.
Since the beginning of the year, Kaspersky analysts have identified more than 15.000 malware samples that masqueraded as agentic AI software, including fake versions of rapidly growing tools like OpenClaw. Among the samples were banking trojans, spyware, credential-stealing stealers, exploits, and malware downloaders capable of deploying additional malicious payloads.
In May 2026, Kaspersky's Global Research and Analysis Team (GReAT) also discovered a new campaign linked to the Silver Fox advanced persistent threat (APT) group. In this operation, cybercriminals distributed fake Claude AI applications for Windows, macOS, and Linux targeting users interested in AI tools. Once executed, the malicious installers silently deployed malware on the victims' devices, allowing them to maintain persistent access to compromised systems and sensitive information.
Previous Kaspersky investigations also identified infostealers disguised as Claude Code, OpenClaw, and other agentic AI tools, which highlights a broader trend: malicious actors are increasingly exploiting the trust placed in widely used AI platforms and services.
Supply chain, key objective in AI ecosystems
According to a Kaspersky research, the 98% of companies in Spain plan to use AI in their security processes. However, cybercriminals are increasingly directing their efforts toward supply chains, open-source AI tools, and trusted brands to gain access to corporate systems and sensitive data. In fact, supply chain compromise is becoming one of the most critical risks associated with AI adoption. As organizations rely on interconnected AI ecosystems, a single compromised component can expose entire networks and affect multiple organizations.
A recent example was the compromise of LiteLLM, a popular Python library used to access AI models that recorded approximately 97 million monthly downloads worldwide. The malicious code embedded in the tool was capable of stealing database credentials, cryptocurrency wallet files, and other sensitive information.
Cybercriminals are also camouflaging malicious tools as legitimate AI solutions, plugins, and services, designed to look trustworthy, in order to encourage users to voluntarily provide sensitive data or install malware.
Artificial intelligence systems are facing new security risks
Beyond traditional malware and supply chain cyber threats, organizations must also address risks inherent to AI systems themselves, such as data leaks, biased or manipulated datasets, data poisoning attacks, prompt injection, or unpredictable model behaviors and hallucinations. Kaspersky experts also warn of the growth of so-called “malicious skills”: hidden capabilities integrated into AI workflows that may appear as legitimate plugins, prompts, or extensions, but are designed to covertly execute malicious actions.
Automation expands capabilities, but it also increases risks
Organizations expect AI to improve operational efficiency: according to Kaspersky research, the 59% from Spanish companies plans to enhance its threat detection capabilities using AI, while the 37% hopes to automate its response capabilities.
However, automation can also introduce new risks. Errors generated by AI systems can escalate rapidly, and certain automated decisions can occur without sufficient supervision. Experts emphasize that the human factor remains one of the main security risks, including over-reliance on AI technologies, misuse of systems, and a lack of operational oversight.
The shortage of qualified cybersecurity professionals, coupled with the evolution of AI-driven threats and challenges related to data quality, makes having a structured AI implementation strategy essential.
Implementing AI-based automation requires a systematic and well-planned approach. Kaspersky analysts recommend that organizations adopt the following principles:
Standardization: unified interfaces, data formats, and communication protocols to ensure consistent control and security across systems.
Minimum necessary data exchange: each party must receive only the data strictly necessary to perform its function.
Managed trust: clear identification of who or what is interacting with the system, including defined permissions for AI agents and services.
Human supervision: ability to manually intervene in critical processes when necessary.
Gradual deployment: progressive implementation with pre-defined rollback scenarios to reduce operational risks.
“The introduction of AI agents in corporate environments changes the very nature of trust. Every automated action becomes part of a broader chain of systems and data exchanges, meaning that security is no longer just about protecting endpoints, but about controlling how intelligence, permissions, and decisions propagate through interconnected AI-driven processes, Explain Dmitry Galov, Head of Kaspersky's Global Research & Analysis Team for Russia and the CIS.
During his speech at the conference, Luana Lo Piccolo, Senior Advisor in Technology Law, AI Governance, and Global Digital Affairs, stated that “as AI systems evolve from simple assistants into autonomous actors, the challenge is no longer just technical resilience, but responsible autonomy”. He emphasized that organizations must adopt governance frameworks that clearly define in which areas human oversight remains essential, how responsibility is distributed, and how to maintain control as AI systems operate with greater speed, scale, and autonomy.
From a technical perspective, Andrea Fumagalli, Cybersecurity and AI Advisor, he stressed that “Organizations must adopt an “assume breach” mindset and move beyond traditional resilience toward cybersecurity resistance, especially as AI-driven threats become faster, more autonomous, and increasingly coordinated. In the near future, these threats could have an unprecedented impact, particularly if combined with advances in quantum computing.