Kaspersky detects over 92,000 malware attacks disguised as AI agents

Source: PR Wednesday, 20.05.2026. 13:03
Comments
Podeli
(Photo: Shutterstock)
From January to early May 2026, Kaspersky solutions detected over 92,000 malware and potentially unwanted application attacks worldwide that were disguised as popular AI services and AI agents.

Cybercriminals exploited the trust in well-known brands to trick victims into downloading malicious files, with fake ChatGPT apps accounting for 49% of all detected attacks, while Claude and Gemini accounted for 18% each.

Kaspersky presented these insights at its annual Kaspersky HORIZONS European conference in Rome on May 19, highlighting the growing risks facing organizations and critical infrastructure.


Since the beginning of the year, Kaspersky researchers have identified over 15,000 malware samples masquerading as AI software, including fake versions of fast-growing tools like OpenClaw.

These samples included banking Trojans, spyware, banking credential stealers, exploits, and downloadable malware capable of installing additional malicious content.

In May 2026, Kaspersky’s Global Research and Analysis Team (GReAT) also uncovered a new campaign associated with the Silver Fox APT group.

In this operation, attackers distributed fake Claude AI applications for Windows, macOS, and Linux, targeting users seeking access to AI tools.

(Photo: ShutterPNPhotography/shutterstock.com)
Once launched, the malicious installers silently installed malware on victims’ devices, allowing long-term access to compromised systems and sensitive information.

Previous investigations by Kaspersky researchers have also identified infostealers disguised as Claude Code, OpenClaw, and other service-based AI tools, indicating a broader trend in which threats are increasingly exploiting trust in widely used AI platforms and services.

Supply chains becoming key targets in AI ecosystems

According to Kaspersky research, 99% of companies plan to use AI in their security processes.

At the same time, attackers are increasingly targeting supply chains, open-source AI tools, and trusted AI brands to gain access to corporate systems and sensitive data.

Supply chain compromise is becoming one of the most critical risks associated with the adoption of AI technologies.

As organizations become more reliant on interconnected AI ecosystems, a single compromised component can expose entire networks and disrupt the operations of multiple organizations.

One recent example involves the compromise of the LiteLLM library, a widely used Python library for accessing AI models, which reportedly has around 97 million monthly downloads worldwide.

Malicious code embedded in the tool was capable of stealing database credentials, crypto wallet files, and other sensitive information.


Cybercriminals also disguise malicious tools as legitimate AI solutions, add-ons, and services that appear trustworthy, encouraging users to voluntarily disclose sensitive data or install malware.

AI systems facing new security risks

In addition to traditional malware and supply chain threats, organizations also face risks inherent to AI systems themselves, including data leaks, biased or manipulated datasets, data poisoning attacks, prompt injection, as well as unpredictable model behavior or hallucinations.

(Photo: Jirsak/shutterstock.com)
Kaspersky experts also warn of the growing threat of so-called “malicious skills” - hidden, harmful capabilities built into AI workflows.

They may appear as legitimate add-ons, prompts or extensions, but are designed to covertly perform malicious actions such as data exfiltration, reconnaissance or output manipulation.

Automation expands capabilities, but also increases risks

Organizations increasingly expect AI to improve operational efficiency. According to Kaspersky research, 57% of companies expect better threat detection capabilities through AI, while 49% expect automated response capabilities.

However, automation can also bring new risks. Errors generated by AI systems can quickly scale, and automated decisions can be made without sufficient supervision.

Experts emphasize that the human factor remains one of the most significant security risks, including overreliance on AI technologies, system abuse, and lack of operational vigilance.

The lack of qualified cybersecurity personnel, coupled with evolving AI threats and data quality challenges, makes a structured AI implementation strategy necessary.

Building resilience through structured AI automation

Implementing AI-driven automation requires a systematic and carefully designed approach.

Kaspersky recommends that organizations adopt the following principles:

Standardization: uniform interfaces, data formats, and communication protocols for consistent control and security across systems

Minimal data exchange: each party should receive only the data necessary to perform its function

Managed trust: clearly defining who or what communicates with the system, including precisely defined permissions for AI applications and services

Human oversight: the ability to manually intervene in critical processes when necessary

Phase-based implementation: gradual introduction with predefined rollback scenarios to reduce operational risk

The introduction of AI agents into business environments changes the very nature of trust. Every automated action becomes part of a wider chain of systems and data exchange, which means that security is no longer just about protecting endpoints - but about controlling how intelligence, permissions, and decisions are propagated through interconnected AI processes – explained Dmitry Galov, Head of the Global Research and Analysis Team at Kaspersky for Russia and the CIS.

At the conference, Luana Lo Piccolo, Senior Advisor for Tech Law, AI Governance and Digital Policy, stated:

As AI systems evolve from assistants to autonomous actors, the challenge is no longer just technical resilience, but responsible autonomy.

She emphasized that organizations must establish governance frameworks that clearly define where human oversight is necessary, how accountability is allocated, and how control is maintained as AI systems operate at ever greater speeds, at greater scale, and with greater autonomy.

Security approach and solutions

On the technical side, Andrea Fumagalli, cybersecurity and AI advisor, stressed that organizations must adopt an “Assume Breach” approach and move from traditional resilience to cybersecurity resilience, especially as AI threats become faster, more autonomous, and increasingly coordinated.

In the near future, these threats could have an unprecedented impact, especially when combined with advances in quantum computing.

(Photo: TippaPatt/shutterstock.com)
For more than 20 years, AI and machine learning technologies have been applied in cybersecurity to detect and respond to threats on a large scale.

Kaspersky recommends the following solutions:

• Managed Detection and Response (MDR)

Kaspersky MDR enables expert-led security operations. Its AI automation layer now processes around 25% of incoming security events, while human analysts continue to review cases to ensure quality and reduce false positives.

• Security Information and Event Management (SIEM)

Kaspersky SIEM enables proactive detection of unknown and emerging threats. The solution aggregates, analyzes, and stores log data across the entire IT infrastructure, providing contextually enriched and actionable threat insights.

It has recently been enhanced with advanced AI features, such as recognizing signs of DLL hijacking and detecting potential account compromises.

• AI assistant for analysts

AI assistants help analysts in the Security Operations Center (SOC) analyze incidents faster and more accurately by processing, prioritizing, and contextualizing large amounts of security data.

For example, Kaspersky Investigation and Response Assistant (KIRA AI) is designed to reduce the cognitive load of analysts by de-obfuscating command lines, generating incident summaries, and translating threat hunting queries from natural language into structured telemetry queries. KIRA AI is available as an additional license within Kaspersky SIEM or Kaspersky Next.

The combination of AI automation and human expertise enables organizations to manage rapidly growing amounts of data while maintaining control, accuracy, and resilience in an increasingly AI-targeted threat environment.

Companies:
Kaspersky Kaspersky
Comments
Your comment
Full information is available only to commercial users-subscribers and it is necessary to log in.

Forgot your password? Click here HERE

For free test use, click HERE

Pratite na našem portalu vesti, tendere, investicione projekte, grantove i pravnu regulativu.
Registracija na eKapiji vam omogućava pristup potpunim informacijama i dnevnom biltenu
Naš dnevni ekonomski bilten će stizati na vašu mejl adresu krajem svakog radnog dana. Bilteni su personalizovani prema interesovanjima svakog korisnika zasebno, uz konsultacije sa našim ekspertima.