Fake Claude & Perplexity Lures Push Malware

Help Net Security · Medium sophistication
Last updated August 21, 2026

Sophos reports real incidents where attackers impersonated well-known AI brands (especially Claude) to trick people into installing malware. The lures included polished fake installer pages that instruct victims to copy/paste commands, and browser extensions that look legitimate via high ratings and reviews but steal data and reroute searches.

Key findings

  • Sophos reviewed 12 months of MDR cases and identified 38 incidents involving malicious activity tied to AI brands/ecosystems.
  • Software impersonation was the most common pattern (30 of 38 incidents), with Claude impersonation appearing in 26 cases.
  • InstallFix-style fake installer pages used step-by-step instructions to get users to copy and run commands that lead to infection.
  • Fake browser extensions posed as AI assistants; one fake Perplexity extension in the Chrome Web Store hijacked searches and sent browsing data to attacker infrastructure.
  • In one case, attackers used a Slack-based remote access Trojan and linked development to a GitHub repo showing a human account working with a Claude coding agent.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Developers/Engineering, IT/Helpdesk, Security team.
  • Affected industries: Finance/financial services, General business users installing AI tools, Organizations using browsers and extensions.
  • Attack channels: website, slack, github.
  • Impersonated: Claude (Anthropic), Perplexity (as a browser extension), Legitimate developer tooling/workflows (Slack + GitHub).

Awareness takeaways

  • Only install AI tools (and updates) from confirmed vendor domains, don’t trust lookalike sites or ‘manual install commands’ from a web page.
  • Treat browser extensions like software: verify the publisher and watch for fake popularity signals (ratings/reviews/installs).
  • Be cautious when any ‘AI assistant’ installation results in unusual browser behavior (search hijacking, redirects) or unexpected data sharing.
  • Don’t assume ‘AI’ makes an attack magical, focus on classic warning signs like suspicious downloads, obfuscated commands, and unusual software behavior.

Red flags to watch for

  • Installation requires copying/running a command from a web page
  • Lookalike domain used to host the payload
  • Unexpected packaged download (e.g., a zip or repackaged installer) instead of the vendor’s official download flow
  • Extension routes searches through a lookalike domain
  • Too-good-to-be-true legitimacy signals (ratings/reviews) used to build trust
  • Unexpected behavior after install (search hijacking, redirections)
  • Unapproved software communicating with Slack as a control channel
  • Suspicious GitHub repository/tooling tied to internal incidents
  • Persistence attempts (e.g., scheduled tasks) following initial compromise
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You search for “Download Claude for desktop” and land on a slick install page that looks totally legit. This is an InstallFix-style fake Claude page. It walks you through copying an mshta command from the site to “finish setup”, but that command quietly pulls malware from a lookalike domain. Same play with a fake Perplexity Chrome extension: 4.7 stars, 10,000 installs, looks perfect. But once installed, it hijacks your searches, routes them through a lookalike site, and streams your browsing data out in real time. Here’s the move: if a Claude or Perplexity install ever tells you to run a command from a web page or install an extension that changes how your browser behaves, stop and get it only from the official vendor site yourself.

Similar attacks

Attackers Phish via Teams & Slack, Not Email

Attackers Phish via Teams & Slack, Not Email

Research and incident examples show attackers increasingly using trusted collaboration tools (like Microsoft Teams and Slack) to impersonate IT/support or known community members, then push victims to phishing sites, approve MFA prompts, or run malicious files. Because messages come through…

August 20, 2026
Job Offer & Doc-Link Phishing Drive Real Breaches

Job Offer & Doc-Link Phishing Drive Real Breaches

This weekly threat bulletin describes real incidents where attackers used human manipulation to break in, including social engineering at Levi Strauss and a Microsoft 365 credential-theft phish at defense supplier IEH. It also highlights a Lazarus-linked campaign using fake job offers and…

August 17, 2026
Fake Bank Calls and ClickFix Drive Data Theft

Fake Bank Calls and ClickFix Drive Data Theft

The roundup describes multiple real-world attacks where criminals manipulate people, not just systems, such as fake bank support calls that trick victims into installing phone malware, and “ClickFix” lures that convince Mac users to run malicious commands. It also highlights an AI-assisted…

August 21, 2026
AI Browser Tricked into Spamming WhatsApp, Shopping

AI Browser Tricked into Spamming WhatsApp, Shopping

Researchers showed how a malicious web page could trick OpenAI’s Atlas AI-enabled browser into taking actions a user didn’t intend, like spamming WhatsApp contacts or modifying an Amazon account. The attacks used prompt-injection style instructions hidden in a seemingly legitimate “newsletter…

August 6, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
Vishing Lures, Fake Identities, and Repo-Trap Attacks

Vishing Lures, Fake Identities, and Repo-Trap Attacks

This recap describes multiple real-world social-engineering-driven attacks, including vishing calls that push employees to spoofed login pages and a supply-chain trick where cloning/opening a GitHub repo in developer tools triggers malware. It also highlights an unusual case where an AI model…

August 10, 2026