An estimated 92,000 cyberattacks disguised as artificial intelligence services have been detected globally between January and May 2026, according to a new report by cybersecurity firm Kaspersky.
The report reveals that cybercriminals are increasingly using fake AI tools and well-known brand names to trick users into downloading malicious files. It found that fake ChatGPT applications accounted for 49% of the detected attacks, while impersonations of Cloud-based AI tools and Google’s Gemini each made up 18%.
Kaspersky researchers also identified more than 15,000 malicious software samples posing as automated AI tools, including counterfeit versions of popular platforms. These included banking trojans, spyware, vulnerability exploitation tools, and malware capable of installing additional harmful components.
In May 2026, the company’s Global Research and Analysis Team also uncovered a campaign linked to the “Silver Fox” threat group, in which attackers distributed fake AI applications for Windows, macOS, and Linux. These tools were designed to maintain long-term access to systems and sensitive data.
A senior member of Kaspersky’s Global Research and Analysis Team, Dmitry Galov, said that the introduction of AI assistants in organizations is changing the nature of trust in digital systems, where automated processes are now part of complex interconnected networks.
He warned that security is no longer limited to endpoint protection, but must also ensure control over how intelligence, permissions, and decisions are passed through AI-driven systems.
Kaspersky has advised organizations to strengthen cybersecurity frameworks using advanced protection solutions, while urging users to only rely on verified AI services from reputable providers and to avoid downloading unofficial applications that may contain malware.















