Back

Kaspersky detected more than 33,300 malware attacks on small and midsize businesses between January and April 2026. The twist? The attackers did not break through firewalls or exploit zero-days. They simply offered employees something they already wanted: free AI tools.

The attacks, disguised as downloads for ChatGPT, Claude, DeepSeek, and other popular AI services, surged roughly fivefold compared to the same period in 2025. That makes fake AI tools the fastest-growing malware lure for SMBs, one of the easiest to overlook.

The 33,000 Attacks You Didn’t See Coming#

Kaspersky’s telemetry, drawn from its endpoint protection network, is not a projection or a survey. It is a count of actual infections blocked on business systems. The 33,300 figure represents verified attacks, not theoretical risk.

For context, the same period saw about 24,000 attacks disguised as office and collaboration tools. The fake AI lure outpaced that category by 39%, despite being a relatively new tactic. The old standby, fake messenger and video conferencing apps, still led overall at about 415,000 attacks, but that number held steady year over year. AI-themed malware is the growth story.

India saw more than 600 attacks, a sixfold increase over 2025. Southeast Asia recorded over 1,800, a roughly sevenfold jump. The regional spikes suggest threat actors are following local AI adoption curves, not just casting a wide net globally.

How Fake ChatGPT and Claude Downloads Are Spreading Malware#

The attack is straightforward. A user searches for “free ChatGPT desktop app” or follows a link in a forum or social post. The download page looks legitimate. The installer runs without issue. The user now has AI software. At least, that’s what they think.

In reality, they have installed a Trojan Horse. According to Kaspersky’s Securelist team, these payloads typically perform one or more of the following:

  • Steal data from the infected system
  • Delete or modify files
  • Download additional malware after the initial infection
  • Maintain persistent access for future exploitation

The malware types vary, but the delivery mechanism is consistent: the user intentionally installs the software because they believe it is a legitimate AI tool. Traditional antivirus, which excels at blocking known threats, is less effective here because the initial action (a user downloading and running an installer) looks like normal behavior.

The lure brands break down as follows for the first four months of 2026:

  • ChatGPT: 42%
  • Claude: 24%
  • DeepSeek: 20%
  • OpenClaw (previously ClawdBot / MoltBot): emerging, with hundreds of detected attacks

The pattern is clear. The more publicity and industry discussion a tool receives, the more likely a fake version appears online within weeks.

Why SMBs Are the Perfect Target#

Large enterprises have security operations centers, vendor vetting procedures, and locked-down software policies. SMBs usually do not. In India, SMBs represent 99% of all enterprises. Threat actors know the math: fewer defenses, more endpoints, and employees who are genuinely excited about AI productivity gains.

That enthusiasm is the vulnerability. The attack does not exploit a software flaw. It exploits trust in innovation itself. An employee who reads about a new AI feature and wants to try it is not being careless. They are being curious. Threat actors count on that curiosity.

The Three Red Flags of a Malicious AI Tool Download#

Most SMBs cannot afford a dedicated security team. What they can afford is a simple verification checklist for any employee who wants to install AI software.

Flag 1: The source is not the vendor’s official domain. ChatGPT downloads come from OpenAI. Claude downloads come from Anthropic. DeepSeek downloads come from deepseek.com. If the URL contains extra words, hyphens, or unfamiliar domains, stop.

Flag 2: The tool is “free” when the official version is paid or requires an account. Some AI tools offer free tiers, but they still require registration. A download page that promises full functionality with no signup is suspicious.

Flag 3: The installer requests broad system permissions. A chatbot application should not need administrator access, system-level file modification rights, or network proxy settings. If the installer asks for more access than the task requires, cancel the installation and verify with IT or the vendor directly.

What the Kaspersky Report Actually Reveals#

Kaspersky’s report is not a warning about AI itself. It is a warning about the gap between AI enthusiasm and security practice. The 5x surge correlates with the mainstreaming of AI tools in business workflows. As more employees search for AI software, more fake versions appear in search results, forum posts, and social links.

The report also reveals that AI lures have not replaced older tactics. Fake communication apps still dominate. SMBs now face a dual threat: the traditional lure pool plus a rapidly growing AI-themed addition. The attack surface is expanding faster than awareness.

How to Verify an AI Tool Before Your Team Installs It#

For SMBs without a formal software approval process, a three-step verification is usually enough:

  1. Check the vendor’s official download page. Search for the tool name plus “official download” and verify the domain against the vendor’s known website. When in doubt, start from the vendor’s homepage and navigate to downloads from there.

  2. Cross-check on the vendor’s verified social media or support channels. Most vendors post download links on their official accounts. If a download URL does not appear there, treat it as unverified.

  3. Run the installer through your antivirus or endpoint protection first. Even if the tool is legitimate, this builds a habit. If your security software flags it, do not override the warning without confirming with the vendor.

If your business has more than five employees, consider creating a simple approved-software list. The list does not need to be exhaustive. It just needs to establish that new tools require a quick check before installation.

The Bigger Picture: AI Hype Creates AI Vulnerability#

The malware threat follows the hype cycle. As soon as a new AI tool gains traction in business conversations, threat actors begin impersonating it. The lag time is often measured in weeks, not months.

This means the risk is not static. As new models and platforms launch, the lure pool expands. SMBs that stay current on AI trends, which most should for competitive reasons, are also more likely to encounter fake versions of those trends.

The defense is not to slow AI adoption. It is to match adoption speed with verification discipline. A business that moves fast on AI but slow on security policy is exactly the profile threat actors are optimizing for.

Samsung learned this in 2023, when staff uploaded source code and meeting notes to ChatGPT, prompting a company-wide ban on external AI tools. That incident involved a legitimate tool used carelessly. The Kaspersky data shows the opposite problem — fake tools designed to exploit the same eagerness.


Ready to put these ideas into action? Browse our collection of AI implementation tools, templates, and guides at Rozelle.ai — built specifically for operators who want results, not theory.


Sources#

AI Malware Targeting SMBs: Fake ChatGPT & Claude Tools Surge 5x
https://answerbot.cloud/articles/ai-malware-smb-defense
Author Rozelle
Published at August 3, 2026
Copyright © 2026 Rozelle.ai. All rights reserved.