Neoxis IT
Home Blog About Us Contact
RO EN FR
Contact Us
33,000 attacks disguised as AI tools: how to stop them

Nobody in your company installs malware on purpose. The employee who downloaded the “free desktop version” of a popular AI tool just wanted to finish a report faster. They searched the internet, found a site that looked convincing, clicked “Download” — and installed, along with the familiar icon, exactly what the attacker hoped they would install.

The phenomenon now has a measure too: in the first four months of 2026, Kaspersky detected over 33,300 attacks on SMEs disguised as popular AI tools — almost five times more than in 2025. It is not a statistical curiosity; it is the sign that attackers have found a lure that works at scale, exactly where the defence is thinnest: on the computers of small and medium-sized companies.

This article is for companies where employees install software on their own — that is, for most. It explains why the AI lure catches on so well, what a typical attack looks like and, above all, how you regain control over what runs on the company's computers without turning into the office policeman.

Why AI tools in particular are the perfect lure

Because the demand is real and the pressure is high. Everyone has heard that AI raises productivity; many employees genuinely want to use it; few companies have provided official tools. The gap between “I want” and “I was given” gets filled with downloads on people's own initiative.

Add three ingredients and the recipe is complete: AI tools are new, so nobody knows exactly what the “right” site or installer should look like; many promote themselves aggressively as free, so a “free download” raises no suspicion; and the “unlocked premium” versions exploit the same old weakness as software piracy — the wish not to pay. A “Pro unlocked for free” is, in practice, a nicely written invitation to run unknown code with your own hand.

What a typical attack looks like

The disguise takes a few recurring forms:

  • The fake installer: a clone site or a search engine advert offers the “desktop app” of a well-known AI service. The installer may even put a working interface on screen — while installing something else in the background.
  • The browser extension: it promises to bring AI into your email or documents; by its very nature it receives access to everything you see and type in the browser — including sessions and passwords.
  • The “cracked” version: the archive with the “free Pro licence”, distributed through forums and torrents, for which the antivirus must be “switched off for a moment, it's a false alarm”. The alarm was not false.
  • The fake login page: an email or an advert leads to a copy of the login page of a popular AI service; the password entered goes straight to the attacker.

The typical result is not spectacular, and that is exactly why it is dangerous: a program that steals saved passwords and active sessions, or remote access installed quietly. For days or weeks nothing shows — until the access is used or sold on.

Application control: who installs, what and how

The good news: this problem is solved first of all administratively, with tools you already have.

No administrator rights for everyday work

The most effective measure is also the oldest: work accounts have no local administrator rights. Installing a program requires an approval — from IT or from the designated person. A fake installer without installation rights is an inert file. The measure costs zero lei and stops most of the scenarios above from the start.

A list of approved applications, not a hunt for bad ones

The “we ban what is dangerous” approach loses from the start — new lures appear daily. The approach that works is the reverse: a list of approved applications, installable on request, and one simple rule for everything else: it is requested, it is assessed, it is answered quickly. The key is the last part — if approval takes two weeks, people go back to downloading on their own.

The inventory: do you know what is running right now?

Before any new rule, learn the actual state: which programs and which browser extensions exist on the company's computers at this moment. A software inventory — done with administration tools, not from memory — almost always produces surprises. Browser extensions deserve a separate pass: they are the most ignored channel of access to data.

Centralised updates

Some of the “side” installs happen because the official software is old and clunky, and the employee looks for an alternative. Programs kept up to date, centrally, cut off both the motive and the pretext.

All of these are classic system administration tasks. If the company has no one of its own in this role, they fit naturally into an IT support contract, as part of the day-to-day administration of the computers, not as a special project.

Ban or channel?

The managerial temptation is a total ban: “nobody uses anything with AI until we figure it out”. On paper it sounds prudent; in practice it produces exactly the opposite — employees do not give up tools that help them, they just move them into the invisible zone: onto the personal phone, the laptop at home, private accounts through which company data starts to circulate. The ban does not remove the risk; it takes it outside any control.

The mature alternative: pick a few official AI tools, paid from the company budget, with company accounts; publish the list and the route for requesting additions; explain briefly why only these — including the story of the 33,300 attacks, which is more convincing than any regulation. And the “free unlocked” versions deserve a separate paragraph in the internal policy: beyond the security risk, unlicensed software is a legal problem in its own right — the frequently asked questions about software licences explain what the company risks and how to put things in order.

It is also worth saying that fake installs are only one face of the same offensive: the same AI wave has changed the trap emails too — we have written separately about AI-generated phishing and the training that still works.

The minimal plan, in four steps

  1. Take the inventory of the software and browser extensions on all the company's computers.
  2. Withdraw local administrator rights from work accounts — with a quick, clear route for requesting installs.
  3. Publish the short list of approved AI tools and the channel for proposing new ones.
  4. Tell people why: a single open conversation about what a fake installer looks like is worth more than a policy nobody reads.

The next step comes down to a single decision: who approves, from today onward, what gets installed on the company's computers? Name the person or the partner, and the steps above fall into place by themselves. Neoxis, an IT services company founded in 2015 in Pitești, administers exactly this kind of environment for SMEs across Romania.

Share this article:

Facebook LinkedIn