Sophos X-Ops: Attackers Impersonate Claude, ChatGPT, Copilot and Perplexity to Distribute Infostealers, Backdoors and Malicious Browser Extensions

Sophos X-Ops (TL-2026-2120), also tracked as Fake AI, Real Malware, is a high-severity malware campaign, first published 2026-08-23. It has no confirmed attribution, affects Anthropic Claude (brand impersonated in fake installers/sites), maps to 19 MITRE ATT&CK techniques (T1027, T1053.005, T1055.012), and is covered by 9 detection rules and 30 indicators of compromise.

Key facts for TL-2026-2120

Threat ID
TL-2026-2120
Also known as
Fake AI, Real Malware, InstallFix Campaign, AI Brand Impersonation Wave
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-08-23
Last reviewed
2026-08-23
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
finance, technology, general opportunistic
Target regions
Global
Detection rules
9
Indicators of compromise
30

Malware and tooling in Sophos X-Ops

Malware and tooling: AdaptixC2, Lumma Stealer - S1213

Sophos X-Ops reviewed 12 months of MDR case data (July 2025-June 2026) and confirmed 38 incidents of malicious activity impersonating popular AI brands, 30 of them software impersonation and 26 abusing the Claude brand specifically. Attackers use a ClickFix variant dubbed 'InstallFix', trojanized installers/.msixbundle packages, and a malicious Chrome Web Store extension impersonating Perplexity to deliver infostealers (LummaStealer), a previously undocumented DLL-sideloaded backdoor ('Beagle'), and a Rust-based Slack-C2 RAT whose GitHub development history shows commits from a Claude coding-agent account.

How Sophos X-Ops works

Between 2 July 2025 and 29 June 2026, Sophos X-Ops reviewed 86 MDR cases tagged for AI involvement and confirmed 38 as genuinely adversarial. Of those, 35 targeted AI brands/ecosystem and 30 were direct software impersonation, with Claude the most abused lure (26 of 38 cases) ahead of ChatGPT, Microsoft Copilot, and Perplexity.

The dominant delivery technique is a ClickFix variant Sophos calls 'InstallFix': malvertising and SEO-poisoned search results steer victims to typosquatted sites that present a polished, fake step-by-step 'installation guide' ending in a copy-pasted obfuscated command. In one documented chain, a fake Claude site had victims run an mshta one-liner pulling a payload from download-version[.]1-9-18[.]com; the payload was a Windows app package named 'claude' or 'claude.msixbundle', followed by an `irm <url> | iex` one-liner that executed in memory and attempted process hollowing against the browser. Other InstallFix variants used trojanized 'Claude Setup.zip' archives staging a malicious libcef.dll, and a repackaged claude.exe acting as a loader; a related fake-CAPTCHA ClickFix flow distributed LummaStealer.

A separate, previously-undocumented backdoor named 'Beagle' was distributed from a cloned Claude site (claude-pro.com, live since ~March 2026, hosted on Alibaba Cloud behind Cloudflare) offering a fictitious 'Claude-Pro Relay' as a 505 MB ZIP. The archive's MSI installer drops a signed G DATA antivirus updater (renamed NOVupdate.exe), an encrypted data file, and a malicious avk.dll into the Windows startup folder; when the legitimate, signed updater runs it side-loads avk.dll in place of its real library, which reverses an XOR-encoded blob, runs shellcode, and launches an in-memory DonutLoader that ultimately deploys Beagle. Beagle supports eight commands (CMD/PowerShell execution, file upload/download, directory listing/creation/deletion, file rename, self-removal) and beacons to license[.]claude-pro[.]com over TCP/443 or UDP/8080 with a hardcoded AES key; a March 2026 variant instead deployed AdaptixC2. Sophos notes structural similarity to PlugX-style loader chains without formally attributing the cluster.

On the extension front, Sophos found a fake Perplexity browser extension published on the Chrome Web Store — with a 4.7-star rating across 67 reviews and 10,000+ installs — that hijacked searches, redirected traffic through perplexity-ai[.]online, displayed a Tilda-hosted landing page (extension.tilda.ws/perplexityai) post-install, and exfiltrated real-time browsing telemetry to attacker infrastructure. A second extension marketed as an 'AI Sidebar with DeepSeek, ChatGPT, Claude' functioned the same way, beaconing stolen data to its own C2.

The most novel finding is a custom Rust-based RAT discovered during a financial-services intrusion. Its source was recovered from a public GitHub repository with visible commit history showing two contributors: a human threat-actor account and a 'claude' AI coding-agent account (built on an agentic skills framework), with the config internally renamed from 'rat-agent' to 'svc' across the development history. The RAT polls a Slack channel for host-tagged operator commands and supports remote command execution, reverse shell, file download, DPAPI-encrypted configuration retrieval, and scheduled-task-based persistence; development spanned several days of iterative feature/encryption/hardening commits.

Sophos also flags — as a separate, lower-confidence finding from the same 38-incident review — a SonicWall SMA1000 ransomware intrusion (via the actively-exploited CVE-2026-15409/CVE-2026-15410 SSRF+code-injection chain) where PowerShell used for internal reconnaissance carried unusually verbose, templated, English-narrated comments and, in one script, Mandarin-language comments — a pattern consistent with, though not conclusive proof of, LLM-generated tooling; the leaked internal chats of the unrelated 'Gentlemen' ransomware group separately show the group promoting an uncensored Qwen3.5 build to affiliates in April 2026. Sophos' core recommendation across all clusters is unchanged: install AI tooling only from confirmed, official vendor domains, and treat 'paste this command to fix/install' prompts as a red flag.

MITRE ATT&CK techniques used in TL-2026-2120

Defense Evasion

T1027 Obfuscated Files or Information; T1055.012 Process Injection: Process Hollowing; T1140 Deobfuscate/Decode Files or Information; T1218.005 System Binary Proxy Execution: Mshta; T1574.001 DLL

Persistence

T1053.005 Scheduled Task/Job: Scheduled Task; T1176 Software Extensions; T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

Execution

T1059.001 Command and Scripting Interpreter: PowerShell; T1204.002 User Execution: Malicious File; T1204.004 User Execution: Malicious Copy and Paste

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1102.002 Web Service: Bidirectional Communication; T1572 Protocol Tunneling

defense-impairment

T1553.002 Subvert Trust Controls: Code Signing

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1583.001 Acquire Infrastructure: Domains; T1583.008 Acquire Infrastructure: Malvertising; T1608.006 Stage Capabilities: SEO Poisoning

Affected products and versions in Sophos X-Ops

  • Anthropic — Claude (brand impersonated in fake installers/sites)
    Vulnerable versions: N/A - trademark/brand abuse, not a software vulnerability
    Fixed in: N/A
  • OpenAI — ChatGPT (brand impersonated)
    Vulnerable versions: N/A
    Fixed in: N/A
  • Microsoft — Copilot (brand impersonated)
    Vulnerable versions: N/A
    Fixed in: N/A
  • Perplexity AI — Perplexity (brand impersonated via fake Chrome Web Store extension)
    Vulnerable versions: N/A
    Fixed in: N/A
  • Google — Chrome Web Store (distribution channel for the malicious extensions)
    Vulnerable versions: N/A
    Fixed in: N/A
  • G DATA — CyberDefense AV updater binary (NOVupdate.exe) abused for DLL side-loading
    Vulnerable versions: signed updater abused as-is, unmodified
    Fixed in: N/A - abuse of a trusted signed binary, not a G DATA vulnerability
  • Slack Technologies — Slack (abused as C2 channel by a custom Rust RAT)
    Vulnerable versions: N/A - platform abuse, not a Slack vulnerability
    Fixed in: N/A

Remediation for Sophos X-Ops

Patches

  • No vendor patch applies to the core impersonation/malvertising campaign — enforce software-restriction and extension-allowlisting controls instead
  • For the separately-noted SonicWall SMA1000 exploitation chain referenced in the same Sophos review: apply SonicWall firmware 12.4.3-03453+ or 12.5.0-02835+, which fixes CVE-2026-15409 and CVE-2026-15410

Immediate actions

  • Block/deny the published IOC domains and IPs at DNS, web proxy, and firewall layers (Sophos AI_2025-2026_IOCs.csv)
  • Instruct users to download AI-tool installers only from official vendor domains (claude.ai/anthropic.com, chatgpt.com/openai.com, copilot.microsoft.com, perplexity.ai)
  • Audit installed browser extensions org-wide for the fake Perplexity extension and any unrecognized 'AI Sidebar'-style extensions and remove them
  • Hunt for mshta.exe executions and `irm <url> | iex` PowerShell one-liners spawned from browser processes
  • Review Slack workspace app/bot integrations and outbound webhook/API polling activity for anomalous host-tagged command patterns

Workarounds

  • Disable browser extension installation from unmanaged/non-enterprise sources via browser policy
  • Block execution of mshta.exe and non-administrative PowerShell where operationally feasible

Longer-term hardening

  • Deploy EDR behavioral detection tuned for DLL side-loading via signed AV/security-vendor binaries, process hollowing, and signed-binary proxy execution
  • Enforce enterprise browser-extension allowlisting instead of trusting Chrome Web Store ratings/install counts
  • Train users to recognize ClickFix/InstallFix-style 'copy this command to fix or install' social engineering and fake CAPTCHA prompts
  • Restrict mshta.exe execution and msixbundle installation via application control policy for standard users
  • Add SOC triage heuristics for AI-coding-agent-assisted malware (unusually verbose, templated, narrated code comments in obfuscated scripts)

Weaknesses (CWE) in Sophos X-Ops

CWE-494, CWE-506

Timeline of Sophos X-Ops

  • Start of the 12-month Sophos X-Ops MDR case review window later found to contain 38 confirmed AI-brand-impersonation/malicious-AI-use incidents.
  • Earliest Beagle backdoor samples identified on VirusTotal, per Sophos' campaign timeline.
  • Malicious hosting infrastructure for the cloned claude-pro.com site established on Alibaba Cloud, fronted by Cloudflare.
  • A March 2026 Beagle campaign variant deploys the AdaptixC2 framework as an alternate payload.
  • Leaked internal chats show the unrelated 'Gentlemen' ransomware group promoting an uncensored Qwen3.5 build to affiliates (cited by Sophos as a separate 'malicious use of AI' data point from the same review).
  • Sophos publishes 'Donuts and Beagles', disclosing the previously undocumented Beagle backdoor and its claude-pro.com distribution chain.
  • End of the 12-month Sophos X-Ops MDR case review window.
  • Help Net Security, GBHackers, Cyber Security News and others report on the Sophos findings, amplifying the disclosure.
  • Sophos X-Ops publishes 'Fake AI, real malware', consolidating 38 confirmed incidents across ClickFix/InstallFix, the Beagle backdoor, the fake Perplexity extension, and the Slack-based Rust RAT.

Sources cited for Sophos X-Ops

Threats related to Sophos X-Ops

Detection coverage for TL-2026-2120

As of 2026-08-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2120 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-2120

1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats