Kaspersky: Malware Disguised as AI Services Targeting SMBs Surges Fivefold in 2026

Cybercriminals are increasingly exploiting the popularity of artificial intelligence (AI) tools to target small and medium-sized businesses (SMBs), according to a new report from Kaspersky. The cybersecurity firm says malware attacks disguised as AI services increased nearly fivefold during the first four months of 2026.

From January to April 2026, Kaspersky detected more than 33,300 attacks on SMBs involving malicious or unwanted software masquerading as legitimate AI applications. The figure represents almost a fivefold increase compared to the same period in 2025.

ChatGPT, Claude, and DeepSeek become top AI lures

According to Kaspersky, cybercriminals are increasingly impersonating well-known AI platforms to trick users into downloading malware.

The company’s analysis of AI-themed malware attacks during the first four months of 2026 found that fake versions of ChatGPT accounted for 42% of detected attacks, followed by Claude at 24% and DeepSeek at 20%.

Researchers also observed campaigns disguised as OpenClaw, an AI tool that has gained popularity in 2026.

Kaspersky said the growing enterprise adoption of AI tools has created new opportunities for attackers to exploit employees searching online for productivity software.

Trojans remain the primary malware delivered through fake AI apps

Kaspersky reported that most of the malicious files detected were Trojans, which disguise themselves as legitimate software before infecting a user’s computer.

Once installed, Trojan malware can perform a range of malicious activities, including downloading additional malware, stealing sensitive data, modifying or deleting files, blocking access to systems, and copying corporate information.

Because of their versatility and ability to evade unsuspecting users, Trojans remain one of the most significant cybersecurity threats facing businesses.

Messaging apps continue to be major attack vectors

While AI-themed malware has grown rapidly, communication platforms remain the most common disguise used by cybercriminals.

Between January and April 2026, Kaspersky blocked nearly 415,000 attacks involving malware disguised as messaging and collaboration software, including Telegram, WhatsApp., Zoom, amd Microsoft Teams.

Unlike AI-related attacks, the volume of fake communication app attacks remained relatively stable compared to 2025.

AI adoption creates new cybersecurity challenges

Kaspersky says the rapid adoption of AI tools in workplaces is expanding the attack surface for businesses, particularly SMBs that may lack dedicated cybersecurity teams.

As employees increasingly rely on publicly available AI platforms for productivity, attackers are taking advantage by creating convincing fake websites and software installers.

The cybersecurity company recommends verifying website URLs before downloading applications and avoiding software from unofficial sources.

Kaspersky recommends layered protection for SMBs

To reduce the risk of malware infections, Kaspersky advises businesses to strengthen both their technical defenses and employee awareness.

The company recommends that small and medium-sized businesses deploy endpoint security solutions designed for business environments, provide regular cybersecurity awareness training for employees, establish clear policies for using third-party AI services, restrict access to sensitive corporate resources, regularly back up critical business data, and consider managed detection and response (MDR) services if in-house security resources are limited.

As AI becomes increasingly integrated into day-to-day business operations, Kaspersky warns that organizations must remain vigilant against cybercriminals using trusted AI brands as bait to compromise corporate systems.

Leave a Reply