Fake AI Apps and Signed Installers Spread Malware

Unit 42 · Medium sophistication
Last updated August 25, 2026

A large review of “AI-enabled malware” found most samples were proof-of-concepts, but a small set were real threats seen in production environments. The real-world activity included trojanized installers that pretended to be legitimate apps (like a recipe app or a Dropbox installer) and relied on brand trust and code signing to get users to run them.

Key findings

  • The report analyzed 405 “AI-enabled malware” samples, but only 12 were seen on real endpoints; ~97% were limited to sandboxes/repositories.
  • A trojanized installer masqueraded as a recipe-finding app (“Recipe Lister”) and was seen across “more than 50 organizations,” generating large alert volume, but was blocked on protected endpoints.
  • A separate sample “masquerades as a Dropbox installer” and used a signature that appears to read “Dropbox, Inc.” to look legitimate while installing the Oyster/CleanBoost backdoor.
  • The report highlights “AI-themed brand abuse” where AI popularity is used as a lure: “The AI branding is a social engineering tactic, not a technical capability.”

Who’s being targeted

  • Commonly targeted roles: All employees, IT, Security operations, Procurement / Software request approvers.
  • Affected industries: Multiple industries (no clear concentration reported).
  • Attack channels: website.
  • Impersonated: Recipe Lister (legitimate-looking app) / signed software publisher, Dropbox, Inc..

Awareness takeaways

  • Treat “AI-branded” downloads as a common lure; verify the source before installing software.
  • Don’t trust an installer just because it is code-signed; confirm the publisher is expected for your organization and the download came from an official channel.
  • Watch for “installer runs scripts from temp folders” as a strong warning sign and report it immediately.
  • Assume broad, opportunistic distribution: these lures can hit many organizations, not just a specific industry.

Red flags to watch for

  • Software is presented as an AI app, but comes as an unexpected installer download
  • Installer is signed, but by an unfamiliar publisher for your organization
  • Unusual installer behavior such as extracting and running scripts from a temporary directory
  • Installer appears “verified/signed,” but the file may not be genuine Dropbox software
  • Installer drops additional unexpected components (loader/backdoor behavior)
  • Brand-name installers sourced from unofficial download locations
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You see a shiny new AI app called “Recipe Lister” and a big button: “Install Recipe Lister to quickly find recipes.” Looks harmless, right? Here’s the trick: the installer is trojanized. It’s an NSIS installer that pretends to be Recipe Lister, but when you run it, it quietly extracts and runs a JavaScript backdoor from a temp folder. It was seen across more than 50 organizations. And it’s not just fake recipe apps. One sample masqueraded as a Dropbox installer with a signature that reads “Dropbox, Inc.” The signed file was not Dropbox software at all; it dropped a loader that installed the Oyster, also called CleanBoost, backdoor. That’s the aha: a code signature can lie to you. If any “AI” or brand-name installer pops up from the web, and you weren’t expecting it, especially if it runs scripts from a temp folder, stop and report it to IT. Don’t install it yourself.

Similar attacks

Fake AI App Installers Spread Backdoors and Ransomware

Fake AI App Installers Spread Backdoors and Ransomware

Palo Alto Networks’ Unit 42 reviewed 405 “AI-linked” malware samples and found most never reached real victims, but a small set did spread in the wild. Several successful samples relied on deception, posing as legitimate installers (e.g., a recipe app, Dropbox, and security software components), to…

August 26, 2026
Teams Helpdesk Vishing Pushes Remote Control Tools

Teams Helpdesk Vishing Pushes Remote Control Tools

Researchers observed a coordinated social-engineering operation (“Spring Ring”) where attackers used external Microsoft Teams accounts to pose as internal IT help desk staff and start voice calls. Victims were pressured to install remote-control tools (like Quick Assist or other RMM software) or…

August 31, 2026
Fake Mac Crash Reporter Steals Passwords

Fake Mac Crash Reporter Steals Passwords

Researchers warn about a new macOS infostealer called “CrashStealer” that pretends to be Apple’s Crash Reporter. It uses a legitimate-looking installer and a fake macOS-style password prompt to trick users into unlocking Keychain, then steals credentials and crypto wallet data.

July 15, 2026
Resume Phish Hit Brazil Banks; AI Aided Ops

Resume Phish Hit Brazil Banks; AI Aided Ops

Two real, ongoing intrusion campaigns targeted organizations in Latin America, including a Mexican transportation organization and Brazil’s financial sector. In the Brazil campaign, attackers reportedly got in via a resume-themed phishing attachment, then attempted to download and run tunneling…

September 3, 2026
Attackers Phish via Teams & Slack, Not Email

Attackers Phish via Teams & Slack, Not Email

Research and incident examples show attackers increasingly using trusted collaboration tools (like Microsoft Teams and Slack) to impersonate IT/support or known community members, then push victims to phishing sites, approve MFA prompts, or run malicious files. Because messages come through…

August 20, 2026
Invoice Phish Drops ValleyRAT via BYOVD Drivers

Invoice Phish Drops ValleyRAT via BYOVD Drivers

Researchers reported a real campaign by the China-based Silver Fox group against a Japanese industrial manufacturer. The attack starts with an invoice-themed phishing message that leads victims to open a ZIP file, triggering a DLL sideloading chain and installing ValleyRAT for persistent remote…

July 30, 2026