Fake AI Apps and Signed Installers Spread Malware

Unit 42 · Medium sophistication
Last updated August 25, 2026

A large review of “AI-enabled malware” found most samples were proof-of-concepts, but a small set were real threats seen in production environments. The real-world activity included trojanized installers that pretended to be legitimate apps (like a recipe app or a Dropbox installer) and relied on brand trust and code signing to get users to run them.

Key findings

  • The report analyzed 405 “AI-enabled malware” samples, but only 12 were seen on real endpoints; ~97% were limited to sandboxes/repositories.
  • A trojanized installer masqueraded as a recipe-finding app (“Recipe Lister”) and was seen across “more than 50 organizations,” generating large alert volume, but was blocked on protected endpoints.
  • A separate sample “masquerades as a Dropbox installer” and used a signature that appears to read “Dropbox, Inc.” to look legitimate while installing the Oyster/CleanBoost backdoor.
  • The report highlights “AI-themed brand abuse” where AI popularity is used as a lure: “The AI branding is a social engineering tactic, not a technical capability.”

Who’s being targeted

  • Commonly targeted roles: All employees, IT, Security operations, Procurement / Software request approvers.
  • Affected industries: Multiple industries (no clear concentration reported).
  • Attack channels: website.
  • Impersonated: Recipe Lister (legitimate-looking app) / signed software publisher, Dropbox, Inc..

Awareness takeaways

  • Treat “AI-branded” downloads as a common lure; verify the source before installing software.
  • Don’t trust an installer just because it is code-signed; confirm the publisher is expected for your organization and the download came from an official channel.
  • Watch for “installer runs scripts from temp folders” as a strong warning sign and report it immediately.
  • Assume broad, opportunistic distribution: these lures can hit many organizations, not just a specific industry.

Red flags to watch for

  • Software is presented as an AI app, but comes as an unexpected installer download
  • Installer is signed, but by an unfamiliar publisher for your organization
  • Unusual installer behavior such as extracting and running scripts from a temporary directory
  • Installer appears “verified/signed,” but the file may not be genuine Dropbox software
  • Installer drops additional unexpected components (loader/backdoor behavior)
  • Brand-name installers sourced from unofficial download locations
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You see a shiny new AI app called “Recipe Lister” and a big button: “Install Recipe Lister to quickly find recipes.” Looks harmless, right? Here’s the trick: the installer is trojanized. It’s an NSIS installer that pretends to be Recipe Lister, but when you run it, it quietly extracts and runs a JavaScript backdoor from a temp folder. It was seen across more than 50 organizations. And it’s not just fake recipe apps. One sample masqueraded as a Dropbox installer with a signature that reads “Dropbox, Inc.” The signed file was not Dropbox software at all; it dropped a loader that installed the Oyster, also called CleanBoost, backdoor. That’s the aha: a code signature can lie to you. If any “AI” or brand-name installer pops up from the web, and you weren’t expecting it, especially if it runs scripts from a temp folder, stop and report it to IT. Don’t install it yourself.

Similar attacks

Fake Mac Crash Reporter Steals Passwords

Fake Mac Crash Reporter Steals Passwords

Researchers warn about a new macOS infostealer called “CrashStealer” that pretends to be Apple’s Crash Reporter. It uses a legitimate-looking installer and a fake macOS-style password prompt to trick users into unlocking Keychain, then steals credentials and crypto wallet data.

July 15, 2026
Attackers Phish via Teams & Slack, Not Email

Attackers Phish via Teams & Slack, Not Email

Research and incident examples show attackers increasingly using trusted collaboration tools (like Microsoft Teams and Slack) to impersonate IT/support or known community members, then push victims to phishing sites, approve MFA prompts, or run malicious files. Because messages come through…

August 20, 2026
Invoice Phish Drops ValleyRAT via BYOVD Drivers

Invoice Phish Drops ValleyRAT via BYOVD Drivers

Researchers reported a real campaign by the China-based Silver Fox group against a Japanese industrial manufacturer. The attack starts with an invoice-themed phishing message that leads victims to open a ZIP file, triggering a DLL sideloading chain and installing ValleyRAT for persistent remote…

July 30, 2026
Zero-Click Zimbra Webmail Phish Hits NATO Sectors

Zero-Click Zimbra Webmail Phish Hits NATO Sectors

Researchers at Unit 42 reported a real espionage campaign targeting organizations using Zimbra webmail, including government, defense, transportation and financial sectors. The attackers sent “zero-click” phishing emails disguised as news headlines, where opening/viewing the message could trigger a…

July 23, 2026
Typosquat RubyGems Stealer Hits Dev Machines

Typosquat RubyGems Stealer Hits Dev Machines

Researchers found 16 look‑alike (typosquatted) RubyGems packages that trick developers into installing a Windows information stealer. The malicious gems run code automatically during installation, pull down additional malware, and then steal browser logins and crypto wallet data before uploading it…

August 18, 2026
Fake Zoom Updates Install ScreenConnect Backdoor

Fake Zoom Updates Install ScreenConnect Backdoor

Researchers describe an active campaign ("SMOKE#SCREEN") where attackers trick users with realistic software update and document-themed lures to install a legitimate remote-control tool (ScreenConnect). Once installed, the attacker gains persistent remote access that can look like normal IT…

August 5, 2026