Security1 publisher3 min readPublished
A year of Sophos AI cases: 30 of 38 were fake installers, not autonomous attackers
Sophos X-Ops confirmed 38 AI-related MDR cases across twelve months. Impersonation of AI software accounted for 30 of them, and conventional payload controls were what stopped them.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- Sophos X-Ops analysis draws on 12 months of Sophos MDR casework, from July 2, 2025 to June 29, 2026, alongside Counter Threat Unit intelligence and SophosLabs research.
- During the period, 86 MDR cases were tagged for AI involvement; each was reviewed individually against Sophos's AI threat taxonomy and 34 were confirmed as genuine adversarial AI activity.
- Sophos identified a further four cases through analysts' investigations - a Cursor-assisted detection-evasion case, a SonicWall SMA ransomware intrusion, a custom Slack-controlled RAT built with an AI coding agent, and a fake Claude site delivering a previously undocumented backdoor - bringing the total dataset to 38.
- Of the remaining tagged cases, 25 were benign AI developer tooling tripping behavioral detections and 27 included an AI keyword only incidentally.
- 52 of the 86 AI-tagged MDR cases did not hold up as genuine adversarial AI activity.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Sophos X-Ops has published its review of twelve months of Managed Detection and Response casework tagged for AI involvement, covering July 2, 2025 to June 29, 2026 [1]. The headline number for anyone budgeting against an "AI threat" line item: of 38 confirmed cases, 30 were attackers impersonating AI software rather than using AI as an attack capability [11].
The triage is as instructive as the findings. Sophos says 86 cases were tagged for AI involvement in the period, and that individual review against its AI threat taxonomy confirmed 34 [2]. Analysts added four more from their own investigations: a Cursor-assisted detection-evasion case, a SonicWall SMA ransomware intrusion, a custom Slack-controlled RAT built with an AI coding agent, and a fake Claude site delivering a previously undocumented backdoor, taking the dataset to 38 [3]. The 52 tagged cases that did not survive review [5] break down into 25 instances of benign AI developer tooling tripping behavioural detections and 27 where an AI keyword appeared only incidentally [4]. Roughly two in five tagged cases held up [6]. If your SOC has an AI tag, expect most of what lands in it to be your own engineers.
Sophos splits its taxonomy into malicious use of AI, where the attacker wields AI as a capability, and malicious targeting of AI, where AI products, brands and ecosystems are abused [7]. Thirty-five of the cases sit in the second bucket [8], leaving three on the capability side [9]. Where genuine attacker use of AI did appear, Sophos describes it as an assistant with a human in control, most notably the Cursor detection-evasion case [10].
The delivery mechanics are familiar. The Claude brand was the most frequently abused lure, appearing in 26 of the cases reviewed [12], and the largest cluster was fake installer campaigns using InstallFix, a ClickFix variant in which the pretext is software installation and the victim reaches a typosquatted site through a malicious ad or poisoned search results [11][13]. Where ClickFix mimics an error or verification step such as a fake CAPTCHA, an InstallFix page offers a polished step-by-step installation guide, and both end with the user copying and running obfuscated commands [14]. In one case a fake Claude site had the victim run an mshta one-liner pulling a payload from download-version[.]1-9-18[.]com, packaged as claude.msixbundle, followed by an irm | iex one-liner that ran code in memory and attempted process hollowing against the browser [15]. LummaStealer arrived over the same AI-branded infrastructure using the fake CAPTCHA route [16]. Other variants included a Claude Setup.zip staging a malicious libcef.dll and a repackaged claude.exe that was a loader [17]. Outside the MDR set, Sophos describes a fake Claude site delivering a DLL-sideloading chain ending in a previously undocumented backdoor it calls Beagle [18].
Sophos's own defensive read is the part worth carrying into a planning meeting: in the impersonation cases, the decisive protections were conventional delivery and payload behaviours, not AI-specific characteristics [19], and the earliest control remains restricting AI tooling installs to confirmed vendor domains [20]. The company frames the trend as at least not all bad, on the grounds that malware is what existing controls were built for [21].
What to watch: whether that three-case malicious-use slice grows as a share of the next twelve months, and whether the noise ratio in AI-tagged alerts pushes teams to loosen behavioural detections on developer tooling. Also watch acquisition paths. Malicious ads and poisoned search results put the compromise upstream of anything running on the endpoint [13].