Security1 publisherNot yet confirmed elsewhere3 min readPublished
Sophos: Fake AI Installers Drove 30 of 38 AI-Linked MDR Cases, With Claude the Favourite Costume
A year of Sophos managed detection cases shows the AI threat that actually landed was a lookalike download page. Claude appeared in 26 of 38 incidents.
The Watch · Security desk
What happened
- Sophos X-Ops reviewed 12 months of managed detection and response cases, covering July 2, 2025 through June 29, 2026.
- Of 86 cases initially tagged for AI involvement, 34 were confirmed as malicious activity involving AI; researchers added four cases uncovered during separate investigations, bringing the dataset to 38 incidents.
- Software impersonation accounted for 30 of the 38 incidents.
- Claude was the brand attackers reached for most often, showing up in 26 of the cases reviewed.
- In 35 cases, criminals targeted AI products, brands, or their surrounding ecosystem.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Sophos X-Ops reviewed twelve months of its managed detection and response cases, covering July 2, 2025 through June 29, 2026, and reported that software impersonation accounted for 30 of the 38 confirmed AI-linked incidents [1][2][3]. Claude was the brand attackers reached for most often, appearing in 26 of the cases reviewed [4]. That puts roughly 79 percent of the confirmed set in the fake-installer category and about 68 percent under one vendor's name [21][22], which makes the internal queue of "can I install this AI tool" requests a place to look for compromise, not just a procurement backlog.
The dataset is small and worth stating plainly: 86 cases were initially tagged for AI involvement, 34 were confirmed as malicious activity involving AI, and four more surfaced in separate investigations, giving 38 [2]. That is a confirmation rate of about 40 percent on the initial tags [23]. In 35 of the 38, criminals were targeting AI products, brands, or the ecosystem around them rather than using AI themselves [5].
The delivery mechanism Sophos describes is InstallFix, which it frames as a variation on ClickFix: rather than a fake CAPTCHA or error, the victim gets "a polished, step-by-step installation guide," and both roads end with a user pasting and running an obfuscated command [6]. In one case a fake Claude site walked the victim through an mshta command that pulled a payload from a lookalike domain, packaged as a Windows app named "claude" or "claude.msixbundle," which then fetched code that ran in memory and attempted to hollow out browser processes [7]. Other variants were a booby-trapped Claude Setup.zip and a repackaged claude.exe acting as a loader [8].
Sophos is blunt about what saved customers: in the impersonation cases, "the decisive protections were based on conventional delivery and payload behaviors, rather than AI-specific characteristics" [9]. Its recommendation is equally unglamorous, which is to install AI tooling only from confirmed vendor domains [10].
The browser extension cases are where the queue argument gets sharper. Sophos found extensions posing as AI assistants, including one marketed as "AI Sidebar with DeepSeek, ChatGPT, Claude" that worked as an infostealer and talked to command-and-control infrastructure [11]. In another, four customers installed a fake Perplexity extension distributed through the Chrome Web Store, which hijacked searches through a lookalike domain and streamed browsing data to attacker infrastructure [12]. The listing carried a 4.7-star rating from 67 reviews and a 10,000-user install count, which Sophos said could lend it the appearance of legitimacy [13]. That is one review per roughly 149 claimed installs [24]; the store's social proof is a signal an approver can be misled by.
On the other side of the ledger, attackers using AI as a capability stayed at the lightest-touch end. In a financial services intrusion that began with SQL injection against a custom PHP application, Sophos found a Rust remote access Trojan that polled a Slack channel for commands, with a public GitHub repository whose commit history showed a human account working alongside a Claude coding agent over several days [14][15][16]. Planned capabilities included command execution, file retrieval, configuration download, persistence via scheduled task, and at one point a reverse shell [17]. A separate ransomware case had unusually detailed comments and structured PowerShell, which Sophos called circumstantial rather than proof [18]. Sophos found nothing in its telemetry suggesting AI runs attacks on its own, and said the genuine uses it saw had a human in control [19][20].
What to watch: whether the impersonation share stays concentrated on one brand or spreads as installer traffic shifts, and whether extension marketplaces tighten review-to-install ratios. Operationally, treat every AI tool install request as a lookup against the vendor's confirmed domain [10], and check whether your allowlisting covers .msixbundle packages and mshta execution [7].