Hackers Rebrand Claude, ChatGPT & Copilot to Deploy Real Malware

Cybercriminals increasingly lean on familiar AI names—Claude, ChatGPT, Copilot—as bait for malware campaigns. They leverage fake download pages, counterfeit browser extensions, poisoned search ads, and hijacked AI-themed shared conversations to trick people into installing backdoors, password stealers, browser hijackers, and worse. ([cybersecuritynews.com](https://cybersecuritynews.com/hackers-are-turning-claude-chatgpt/))

Sophos, in a recent year-long investigation of managed detection and response cases, found 38 definitive instances of AI-themed malware campaigns. In 30 of these, the attackers impersonated tools rather than writing code that leveraged AI. The result: individuals and organizations suffered data loss, session hijacking, credential theft, and exposure of private files and cryptocurrency wallets. ([cybersecuritynews.com](https://cybersecuritynews.com/hackers-are-turning-claude-chatgpt/))

Main Tactics: What to Watch Out For

The most exploited name out of the gate has been Claude—it appeared in 26 of the documented schemes. Typical methods include imitation download portals, domains mimicking official sites, malicious advertisements, and forged site designs. One particularly insidious method, dubbed “InstallFix” (a variant of “ClickFix” social engineering), uses polished installation guides to get victims to run commands that fetch malware. ([cybersecuritynews.com](https://cybersecuritynews.com/hackers-are-turning-claude-chatgpt/))

In some campaigns, victims were tricked into executing an mshta command that loaded a Windows App package named “claude” or “claude.msixbundle”. Another command would execute code directly in memory, masking its activity within a legitimate browser process. Other examples include fake archives like “Claude Setup.zip” that installed malicious DLLs, or disguised executables acting as loaders for previously unknown backdoors such as Beagle. ([cybersecuritynews.com](https://cybersecuritynews.com/hackers-are-turning-claude-chatgpt/))

Extensions & Trusted Services Aren’t Safe Either

Attackers are embedding malicious behavior in browser extensions too. Some extensions posing as AI assistants secretly harvest browser data and communicate with attacker-run servers. For instance, a fake Perplexity extension captured real-time browsing telemetry, hijacked searches, and used a domain like “perplexity-ai[.]online” to redirect traffic, while maintaining a facade of legitimacy. ([cybersecuritynews.com](https://cybersecuritynews.com/hackers-are-turning-claude-chatgpt/))

Even major platforms like the Chrome Web Store aren’t immune. One malicious Claude-themed extension had tens of thousands of installs, a 4.7-star rating, and dozens of reviews—clear indicators exploited for credibility. On macOS, shared AI chats hosted on official infrastructure were abused, guiding users to paste terminal commands that led to credential or data-stealing malware. ([cybersecuritynews.com](https://cybersecuritynews.com/hackers-are-turning-claude-chatgpt/))

How Organizations and Users Can Stay Safe

Experts recommend getting AI tools explicitly from vendor-verified domains. Double-check publishers on browser extensions; delete any that aren’t essential. In enterprise settings, monitor for unusual command-line execution, suspicious PowerShell activity, or browser processes launching system level tools. ([cybersecuritynews.com](https://cybersecuritynews.com/hackers-are-turning-claude-chatgpt/))

It’s also essential to treat AI dependencies with the same scrutiny as any other part of the software supply chain. Poisoned packages and malicious plugins that fetch remote code can turn up unnoticed—but integrating them hastily without checks makes them especially dangerous. ([cybersecuritynews.com](https://cybersecuritynews.com/hackers-are-turning-claude-chatgpt/))

Indicators of compromise (IoCs) shared by the investigation include fake domains like download-version[.]1-9-183[.]com, “perplexity-ai[.]online”, file names such as “claude.exe”, “claude.msixbundle”, “libcef.dll”, and archive names like “Claude Setup.zip”. These tools have been used in campaigns to stage backdoors and data exfiltration. ([cybersecuritynews.com](https://cybersecuritynews.com/hackers-are-turning-claude-chatgpt/))

Attackers are weaponizing trust. Using big AI names like Claude, ChatGPT, and Copilot, they build campaigns that bypass users’ vigilance. These attacks are rooted in familiar branding, polished user interfaces, and trusted platforms. That makes detecting them harder—but not impossible.

What this signals is a pivotal shift: acolytes of trusted AI brands are now fronts for real threat infrastructure. Going forward, vigilance over where tools come from—and auditing everything from install commands to extension permissions—will be core security hygiene. Users and organizations should expect these threats to only grow sharper and more sophisticated.