Fake AI Tool Attacks on SMBs: 33,300 Cyberattacks Masquerading as ChatGPT, Copilot, Claude in Early 2026
Fake AI Tool Attacks on SMBs (TL-2026-0993), also tracked as AI Impersonation Trojware Campaign, is a critical-severity malware campaign, first published 2026-06-28. It has no confirmed attribution, affects Microsoft Windows, maps to 42 MITRE ATT&CK techniques (T1001, T1003, T1008), and is covered by 9 detection rules and 20 indicators of compromise.
Key facts for TL-2026-0993
- Threat ID
- TL-2026-0993
- Also known as
- AI Impersonation Trojware Campaign, Fake AI Tools Wave, ChatGPT Fake Installer Trojan Campaign
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-06-28
- Last reviewed
- 2026-06-28
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- health, finance, legal, accounting, manufacturing, retail, government administration, education, technology, professional-services
- Target regions
- North America, Europe, Asia-Pacific, 005 - South America, Middle East
- Detection rules
- 9
- Indicators of compromise
- 20
Malware and tooling in Fake AI Tool Attacks on SMBs
Malware and tooling: AsyncRAT, Remcos, RemotePC
Kaspersky detected over 33,300 cyberattacks targeting small-to-medium businesses in the first four months of 2026, with attackers masquerading as popular AI tools (ChatGPT, Microsoft Copilot, Claude, Gemini). This represents a five-fold increase from 2025 attack volumes. Over 1,100 unique Trojware samples were identified, capable of downloading and executing additional malware, with confirmed data exfiltration and credential theft functionality.
How Fake AI Tool Attacks on SMBs works
A coordinated wave of trojware campaigns targeting SMBs worldwide has exploited the explosive adoption of AI tools by creating convincing fake installers and promotional materials for ChatGPT, Microsoft Copilot, Claude, Google Gemini, and other AI platforms. The attack chain begins with phishing emails containing malicious links to fake download pages or direct trojan attachments disguised as AI tool installers. Victims are tricked into executing trojware binaries, which establish persistence through registry modifications and scheduled tasks. Once deployed, the trojware samples download and execute secondary malware including information stealers, credential dumpers, backdoors (AsyncRAT, RemotePC, Remcos variants), and potentially ransomware payloads. Analysis of the 1,100+ unique samples revealed polymorphic packing, obfuscation, and anti-analysis techniques designed to evade antivirus detection. The trojware families primarily target Windows SMB endpoints to harvest credentials, steal sensitive files (financial documents, intellectual property, customer data), monitor user activity via keylogging and screen capture, and establish persistent remote access. C2 infrastructure analysis shows fallback mechanisms with hardcoded domains rotating through compromised hosting providers and free DNS services. The campaign demonstrates sophisticated social engineering, leveraging AI tool popularity at a time when many SMBs are experimenting with these platforms. Kaspersky telemetry indicates active targeting of industries including healthcare, financial services, legal, accounting, manufacturing, and retail sectors.
MITRE ATT&CK techniques used in TL-2026-0993
Command and Control
T1001 Data Obfuscation; T1008 Fallback Channels; T1071 Application Layer Protocol; T1568 Dynamic Resolution; T1573 Encrypted Channel
Credential Access
T1003 OS Credential Dumping; T1056 Input Capture; T1110 Brute Force; T1555 Credentials from Password Stores
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution; T1564 Hide Artifacts
Exfiltration
T1041 Exfiltration Over C2 Channel; T1048 Exfiltration Over Alternative Protocol
Persistence
T1053 Scheduled Task/Job; T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution
Execution
T1059 Command and Scripting Interpreter; T1106 Native API; T1204 User Execution; T1559 Inter-Process Communication
Discovery
T1082 System Information Discovery; T1083 File and Directory Discovery; T1087 Account Discovery; T1217 Browser Information Discovery
Collection
T1113 Screen Capture; T1114 Email Collection; T1115 Clipboard Data; T1123 Audio Capture; T1125 Video Capture; T1560 Archive Collected Data
Privilege Escalation
T1134 Access Token Manipulation; T1548 Abuse Elevation Control Mechanism
Initial Access
T1189 Drive-by Compromise; T1190 Exploit Public-Facing Application; T1566 Phishing
Impact
Lateral Movement
defense-impairment
Affected products and versions in Fake AI Tool Attacks on SMBs
- Microsoft — Windows
Vulnerable versions: Windows 7 SP1+; Windows 8.1; Windows 10; Windows 11 - OpenAI — ChatGPT
Vulnerable versions: Legitimate clients spoofed by trojware - Microsoft — Copilot
Vulnerable versions: Legitimate clients spoofed by trojware - Anthropic — Claude
Vulnerable versions: Legitimate clients spoofed by trojware - Google — Gemini
Vulnerable versions: Legitimate clients spoofed by trojware
Remediation for Fake AI Tool Attacks on SMBs
Immediate actions
- Block known trojware C2 domains and IP ranges at firewall/DNS egress
- Quarantine and analyze any suspicious executables with 'AI tool' branding
- Reset credentials for all users who may have interacted with phishing emails
- Enable endpoint detection and response (EDR) with behavioral monitoring
- Block execution of files downloaded from untrusted sources via AppLocker/WDAC
Workarounds
- Download AI tools only from official websites (openai.com, microsoft.com, anthropic.com, google.com)
- Disable macro execution in Office documents by default
- Require code signing verification for executable downloads
- Block suspicious file types (.exe, .msi, .scr) from email attachments
- Use application sandboxing to limit trojware capabilities
Longer-term hardening
- Implement multi-factor authentication (MFA) on all critical systems
- Deploy email gateway security with advanced phishing detection and URL sandboxing
- Conduct security awareness training emphasizing AI tool impersonation risks
- Establish incident response procedures for trojware infections
- Implement network segmentation to contain lateral movement
- Deploy behavioral analysis tools to detect keylogging, credential access, and exfiltration
- Monitor for IOCs: known trojware hashes, C2 domains, attacker infrastructure
Weaknesses (CWE) in Fake AI Tool Attacks on SMBs
CWE-94, CWE-434, CWE-798, CWE-912
Timeline of Fake AI Tool Attacks on SMBs
- Baseline period: SMB trojware attacks from 2025 establish comparison point for 2026 five-fold increase
- Attackers shift focus to AI tool impersonation as ChatGPT adoption surges among SMBs; early fake installer campaigns detected
- Large-scale phishing campaigns begin targeting SMB employees with fake AI tool download links and malicious email attachments
- Attack volume rapidly escalates; polymorphic trojware variants emerge with anti-analysis capabilities and secondary malware downloaders
- End of research period: 33,300 cumulative attacks detected across first four months of 2026; 1,100+ unique malware samples identified
- Secondary malware deployment intensifies with AsyncRAT, Remcos, RemotePC variants establishing persistent backdoor access to compromised systems
- Evidence of large-scale credential harvesting, document theft, and financial data exfiltration from compromised SMBs
- Kaspersky and other security vendors issue critical alerts about fake AI tool trojware campaign; SMBs urged to enhance defenses
- Kaspersky publishes comprehensive SMB threat landscape report documenting fake AI tools campaign, attack techniques, IOCs, and threat actor patterns
- Campaign remains active with continued phishing, malware distribution, and secondary malware deployment; attackers adapting evasion techniques
Sources cited for Fake AI Tool Attacks on SMBs
- Threat landscape for SMBs in 2026: fake AI tools, phishing and more
- Kaspersky SMB Threat Landscape 2026 - Full Report
- Trojware Campaign Targeting SMBs with Fake AI Tool Installers
- Analysis of 1,100+ Malware Samples in AI Tool Impersonation Campaign
- Fake ChatGPT, Copilot, and Claude Installers Spread Trojware
- How Attackers Are Impersonating AI Tools to Target SMBs in 2026
- Phishing Email Campaign Analysis: Fake AI Tool Download Links
- Trojware C2 Infrastructure Mapping: AI Tool Campaign
Threats related to Fake AI Tool Attacks on SMBs
- Black Basta Ransomware Operation - Organizational Breakdown & 2025 Shutdown
- TONResolver Remote Access Trojan - Active Campaign Targeting Japanese Hospitality Sector
- JadeSnow: Hijacked npm/Go Supply Chain Attack with VSCode Exploitation and Blockchain Dead Drops
- Nimbus RAT (BackupBOX) — Microsoft Teams Vishing + Quick Assist Delivery of a Self-Contained Java RAT Using Google Drive/Sheets for C2 (BlackSuit Affiliate)
- Unit 42 — 18 High-Risk GenAI Chrome Extensions Deliver RATs, AitB, Infostealers, and Search Hijackers Targeting AI Users
- FakeGit Campaign: 7,600 Malicious GitHub Repos Push SmartLoader and StealC Malware via AI Tool Poisoning (Water Kurita)
Detection coverage for TL-2026-0993
As of 2026-06-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0993 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.