Security1 distinct publisher3 min readUpdated
A year of Sophos managed detection cases shows the AI threat that actually landed was a lookalike download page. Claude appeared in 26 of 38 incidents.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Sophos X-Ops reviewed twelve months of its managed detection and response cases, covering July 2, 2025 through June 29, 2026, and reported that software impersonation accounted for 30 of the 38 confirmed AI-linked incidents [1][2][3]. Claude was the brand attackers reached for most often, appearing in 26 of the cases reviewed [4]. That puts roughly 79 percent of the confirmed set in the fake-installer category and about 68 percent under one vendor's name [1][2], which makes the internal queue of "can I install this AI tool" requests a place to look for compromise, not just a procurement backlog.
The dataset is small and worth stating plainly: 86 cases were initially tagged for AI involvement, 34 were confirmed as malicious activity involving AI, and four more surfaced in separate investigations, giving 38 [2]. That is a confirmation rate of about 40 percent on the initial tags [3]. In 35 of the 38, criminals were targeting AI products, brands, or the ecosystem around them rather than using AI themselves [5].
The delivery mechanism Sophos describes is InstallFix, which it frames as a variation on ClickFix: rather than a fake CAPTCHA or error, the victim gets "a polished, step-by-step installation guide," and both roads end with a user pasting and running an obfuscated command [6]. In one case a fake Claude site walked the victim through an mshta command that pulled a payload from a lookalike domain, packaged as a Windows app named "claude" or "claude.msixbundle," which then fetched code that ran in memory and attempted to hollow out browser processes [7]. Other variants were a booby-trapped Claude Setup.zip and a repackaged claude.exe acting as a loader [8].
Sophos is blunt about what saved customers: in the impersonation cases, "the decisive protections were based on conventional delivery and payload behaviors, rather than AI-specific characteristics" [9]. Its recommendation is equally unglamorous, which is to install AI tooling only from confirmed vendor domains [10].
The browser extension cases are where the queue argument gets sharper. Sophos found extensions posing as AI assistants, including one marketed as "AI Sidebar with DeepSeek, ChatGPT, Claude" that worked as an infostealer and talked to command-and-control infrastructure [11]. In another, four customers installed a fake Perplexity extension distributed through the Chrome Web Store, which hijacked searches through a lookalike domain and streamed browsing data to attacker infrastructure [12]. The listing carried a 4.7-star rating from 67 reviews and a 10,000-user install count, which Sophos said could lend it the appearance of legitimacy [13]. That is one review per roughly 149 claimed installs [4]; the store's social proof is a signal an approver can be misled by.
On the other side of the ledger, attackers using AI as a capability stayed at the lightest-touch end. In a financial services intrusion that began with SQL injection against a custom PHP application, Sophos found a Rust remote access Trojan that polled a Slack channel for commands, with a public GitHub repository whose commit history showed a human account working alongside a Claude coding agent over several days [14][15][16]. Planned capabilities included command execution, file retrieval, configuration download, persistence via scheduled task, and at one point a reverse shell [17]. A separate ransomware case had unusually detailed comments and structured PowerShell, which Sophos called circumstantial rather than proof [18]. Sophos found nothing in its telemetry suggesting AI runs attacks on its own, and said the genuine uses it saw had a human in control [19][20].
What to watch: whether the impersonation share stays concentrated on one brand or spreads as installer traffic shifts, and whether extension marketplaces tighten review-to-install ratios. Operationally, treat every AI tool install request as a lookup against the vendor's confirmed domain [10], and check whether your allowlisting covers .msixbundle packages and mshta execution [7].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Sophos X-Ops reviewed 12 months of managed detection and response cases, covering July 2, 2025 through June 29, 2026.
Of 86 cases initially tagged for AI involvement, 34 were confirmed as malicious activity involving AI; researchers added four cases uncovered during separate investigations, bringing the dataset to 38 incidents.
Software impersonation accounted for 30 of the 38 incidents.
Claude was the brand attackers reached for most often, showing up in 26 of the cases reviewed.
In 35 cases, criminals targeted AI products, brands, or their surrounding ecosystem.
Sophos researchers wrote: "Whereas ClickFix attacks mimic an error or verification step, such as a fake CAPTCHA, an InstallFix page may present a polished, step-by-step installation guide. Both end with the user copying and running (often obfuscated) commands that ultimately result in a malware infection."
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Specific vendor case data, single source, no external corroboration
The cluster rests on one vendor's incident review with concrete counts (86 tagged, 34 confirmed, 38 total, 30 impersonation, 26 Claude), named techniques, and reproducible artefact details, and it flags its own weak inferences as circumstantial. Evidence quality is limited by there being exactly one publisher summarising exactly one vendor's telemetry, with no IOCs, no total caseload denominator, and no independent replication.
Attacker adoption of AI-brand lures is broad; AI-as-capability remains rare
Adoption here is attacker uptake. Impersonation of AI brands is clearly widespread within this telemetry (30 of 38 cases, 26 involving Claude, a malicious extension listing claiming 10,000 installs and four affected customers). Adoption of AI as an actual offensive capability is measured but small: one clear AI-assisted development case and one circumstantial ransomware signal, with no autonomous use observed. Scope is bounded to one vendor's customer base.
Claims run slightly conservative against the evidence presented
The coverage resists the prevailing AI-attacker narrative: it foregrounds that the AI angle is mostly brand impersonation, that conventional delivery and payload detections were decisive, and that observed AI capability use was lightest-touch with a human in control. The counts are reported without extrapolation and the weakest inference is labelled circumstantial. Slightly negative rather than zero because the framing understates the ordinary phishing-and-loader nature of most incidents relative to the AI framing in the headline claims.
Vendor-authored threat research relayed by a security trade outlet
The underlying research is published by Sophos, a commercial vendor whose managed detection and response and endpoint products are the implicit remedy for the described threat, and the dataset is drawn exclusively from its own customer cases. The reporting outlet is a security trade publication that reproduces the vendor's framing, structure and quotes without external comment. This is a standard, disclosed vendor-research incentive rather than a hidden conflict, and it is partly offset by the report declining to overclaim on AI.
Internally consistent but single-source and small-sample
Confidence is moderate: the numbers are consistent, the caveats are stated by the researchers themselves, and the technique descriptions are concrete. It is held down by one publisher, one vendor dataset, a 38-incident sample from an undisclosed total caseload, and no independent verification of the extension listing figures or the GitHub attribution.
security
A year of Sophos AI cases: 30 of 38 were fake installers, not autonomous attackers1 distinct publisher
security
Bring Your Own Runtime: Sophos MDR maps a repeatable Deno-based intrusion chain1 distinct publisher
product
Incogni ranks 13 AI assistants by privacy risk: bigger is worse, except ChatGPT1 distinct publisher
build
A Notion agent that dies after each request, and the debugging error that broke version two1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 21, 2026