Fake Claude & Perplexity Lures Push Malware

Help Net Security · Medium sophistication
Last updated August 21, 2026

Sophos reports real incidents where attackers impersonated well-known AI brands (especially Claude) to trick people into installing malware. The lures included polished fake installer pages that instruct victims to copy/paste commands, and browser extensions that look legitimate via high ratings and reviews but steal data and reroute searches.

Key findings

  • Sophos reviewed 12 months of MDR cases and identified 38 incidents involving malicious activity tied to AI brands/ecosystems.
  • Software impersonation was the most common pattern (30 of 38 incidents), with Claude impersonation appearing in 26 cases.
  • InstallFix-style fake installer pages used step-by-step instructions to get users to copy and run commands that lead to infection.
  • Fake browser extensions posed as AI assistants; one fake Perplexity extension in the Chrome Web Store hijacked searches and sent browsing data to attacker infrastructure.
  • In one case, attackers used a Slack-based remote access Trojan and linked development to a GitHub repo showing a human account working with a Claude coding agent.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Developers/Engineering, IT/Helpdesk, Security team.
  • Affected industries: Finance/financial services, General business users installing AI tools, Organizations using browsers and extensions.
  • Attack channels: website, slack, github.
  • Impersonated: Claude (Anthropic), Perplexity (as a browser extension), Legitimate developer tooling/workflows (Slack + GitHub).

Awareness takeaways

  • Only install AI tools (and updates) from confirmed vendor domains, don’t trust lookalike sites or ‘manual install commands’ from a web page.
  • Treat browser extensions like software: verify the publisher and watch for fake popularity signals (ratings/reviews/installs).
  • Be cautious when any ‘AI assistant’ installation results in unusual browser behavior (search hijacking, redirects) or unexpected data sharing.
  • Don’t assume ‘AI’ makes an attack magical, focus on classic warning signs like suspicious downloads, obfuscated commands, and unusual software behavior.

Red flags to watch for

  • Installation requires copying/running a command from a web page
  • Lookalike domain used to host the payload
  • Unexpected packaged download (e.g., a zip or repackaged installer) instead of the vendor’s official download flow
  • Extension routes searches through a lookalike domain
  • Too-good-to-be-true legitimacy signals (ratings/reviews) used to build trust
  • Unexpected behavior after install (search hijacking, redirections)
  • Unapproved software communicating with Slack as a control channel
  • Suspicious GitHub repository/tooling tied to internal incidents
  • Persistence attempts (e.g., scheduled tasks) following initial compromise
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You search for “Download Claude for desktop” and land on a slick install page that looks totally legit. This is an InstallFix-style fake Claude page. It walks you through copying an mshta command from the site to “finish setup”, but that command quietly pulls malware from a lookalike domain. Same play with a fake Perplexity Chrome extension: 4.7 stars, 10,000 installs, looks perfect. But once installed, it hijacks your searches, routes them through a lookalike site, and streams your browsing data out in real time. Here’s the move: if a Claude or Perplexity install ever tells you to run a command from a web page or install an extension that changes how your browser behaves, stop and get it only from the official vendor site yourself.

Similar attacks

Fake IT Helpdesk Tricks Users Into Remote Access

Fake IT Helpdesk Tricks Users Into Remote Access

This bulletin describes multiple real-world social engineering campaigns where attackers impersonate IT support or use trusted-looking sharing and “Allow” prompts to gain access. Several campaigns abuse Microsoft Teams and document-sharing lures to trick employees into installing remote tools or…

September 3, 2026
Brevo Hack Injects Fake Cloudflare “Verify” Prompts

Brevo Hack Injects Fake Cloudflare “Verify” Prompts

Attackers compromised Brevo’s Cloudflare setup using a long-lived API key found in source code, then altered website content at the CDN edge. Visitors were shown fake Cloudflare verification prompts to run Windows commands, and logged-in WordPress admins were targeted with a hidden backdoor plugin…

September 22, 2026
Trusted Channels Hijacked for Phishing and Malware

Trusted Channels Hijacked for Phishing and Malware

The article describes multiple real-world social engineering operations this week, including phishing sent from a legitimate Trezor newsletter channel and malware pushed through a verified HBO Max Reddit ad account. It also highlights a large-scale network of fake online stores impersonating real…

September 18, 2026
Attackers Phish via Teams & Slack, Not Email

Attackers Phish via Teams & Slack, Not Email

Research and incident examples show attackers increasingly using trusted collaboration tools (like Microsoft Teams and Slack) to impersonate IT/support or known community members, then push victims to phishing sites, approve MFA prompts, or run malicious files. Because messages come through…

August 20, 2026
Job Offer & Doc-Link Phishing Drive Real Breaches

Job Offer & Doc-Link Phishing Drive Real Breaches

This weekly threat bulletin describes real incidents where attackers used human manipulation to break in, including social engineering at Levi Strauss and a Microsoft 365 credential-theft phish at defense supplier IEH. It also highlights a Lazarus-linked campaign using fake job offers and…

August 17, 2026
Device-Code Phishing and “ClickFix” Lures Spread

Device-Code Phishing and “ClickFix” Lures Spread

This weekly recap highlights multiple real-world campaigns where attackers trick users into taking actions that grant access, without needing to steal passwords directly. Notable examples include “device code” phishing (victims are instructed to enter a short code to approve an attacker session)…

September 28, 2026