Key takeaways
Attacks disguised as popular AI tools have exploded. Kaspersky counted more than 33,000 in the first four months of 2026, roughly five times the year before.
The lures impersonate the biggest names: ChatGPT, Claude, Gemini, Grok, DeepSeek, Perplexity, Cursor, and more.
On a fake ChatGPT site, Windows visitors got a password-stealing loader and Mac visitors got crypto-stealing malware that even swaps your real wallet apps for fake ones.
Attackers buy search ads and abuse trusted hosts (even a real AI platform's own share links) so the fake page looks legitimate, padlock and all.
The reliable defense is at the page and the download. Haven helps in two ways: it flags the fake site for you, and on unverified sites it pauses downloads so you can see what is about to land on your device.
You want to try a new AI tool, so you search "download ChatGPT" or "install Claude," click a result near the top, and run the installer. It looks right: the branding, the layout, the padlock in the address bar. But the app you just installed is not the AI tool. It is malware built to empty your saved passwords, your browser sessions, and your cryptocurrency wallet.
This is now one of the fastest-growing scams online, because nobody knows the official download page for a brand-new AI tool yet. Three separate security teams have documented it from different angles. Here is how the fake AI tool download scam works, why it spreads so fast, and how to get the real app instead.
Why AI tools are the perfect bait
Most software has trusted download habits built around it. If you want Chrome, you go to Google. If you want Photoshop, you go to Adobe. You already know where the real download lives.
AI tools are different. Most people are installing them for the very first time, so they rely on a search, an ad, a YouTube link, or a post to find the download. And these products launch and change constantly, ChatGPT, Claude, Gemini, Sora, DeepSeek, and others, so every new release sends a fresh wave of people searching "download [name]" without knowing the official web address. That search traffic is exactly where attackers set up shop.
The fakes do not even need to be sophisticated, because real AI product pages are minimal by design: a logo, some copy, and a big download button. A copied page matches what you expect to see, with no broken English and no aggressive pop-ups, just familiar branding and the reassuring padlock.
The scale is not hypothetical. Kaspersky, in its 2026 report on threats to small and medium businesses, found more than 33,000 attacks in the first four months of 2026 that were disguised as five popular AI tools (ChatGPT, DeepSeek, Grok, Claude, and Gemini). That is nearly five times the same period a year earlier.
What actually happens: a fake ChatGPT site, two payloads
Malwarebytes documented a clear example: a site at a lookalike domain that closely mimicked OpenAI's real ChatGPT download page, complete with dark theme, familiar branding, and download buttons for both Windows and Mac. Like real software, it served a different installer for each platform. That is what made it convincing.
On Windows, clicking download delivered a fake installer that quietly opened a channel to an attacker's server and began stealing credentials and browser data.
On Mac, it delivered something more expensive and more targeted: a strain of crypto-stealing malware (a fork of the well-known AMOS family). It copied the Mac keychain, harvested saved logins and cookies from more than a dozen browsers, grabbed Telegram sessions, and scanned for cryptocurrency wallets like Ledger Live, Trezor Suite, Exodus, and Electrum. Then came the nastiest part: it tried to delete your real wallet apps and replace them with trojanized copies, so the next time you opened "Ledger Live," you were opening the attacker's version.
The tell that would have stopped all of it was the same in every case: the download did not come from the AI vendor's real, official website.
The new twist: ads and trusted domains
Getting you to the fake page is the attacker's main job, and they have gotten good at it.
Trend Micro tracked a campaign that bought Google search ads impersonating at least six AI developer tools, including Claude, ChatGPT Codex, Perplexity, Cursor, and JetBrains, funneling more than 2,000 victims toward malicious pages over about seven weeks. At first those pages were hosted on free, trusted infrastructure (subdomains of a well-known code-hosting service) so they slipped past filters. Then the campaign escalated in a way worth understanding: it started abusing a real AI platform's own "shared chat" links to host the lure. Victims landed on a genuine, trusted domain, which made the trap far harder to spot, and the security company that runs the platform later banned the accounts and tightened its rules once notified.
In that version, the page did not offer a download at all. It showed a fake "support" conversation telling the user to open Terminal and paste a command to "finish installing." That command quietly downloaded and ran the malware.
We will be honest about that last variant below, because it is a different kind of trap than a fake download button, and it is worth being clear about what a browser tool can and cannot do.
How Haven helps
For the core of this scam, the fake AI download page, Haven helps in the two moments that matter.
First, Haven flags the fake site for you. It analyzes the actual page in front of you, not just how it looks or how you got there, so when a page imitates ChatGPT, Claude, or another AI brand on a lookalike or unverified domain, Haven warns you before you click download, even when the page has a valid padlock and perfect branding.
Second, on unverified sites, Haven pauses downloads so you know what is about to land on your device. Instead of "ChatGPT.exe" quietly saving and running, you get a moment to see what it actually is and decide, rather than finding out later that it was a stealer. That pause is the difference between catching this and cleaning up after it.
Those two steps cover the exact gap here: the pages look legitimate and the files are freshly built, so the real protection is not trusting a fake AI page and not letting an unexpected download run unchecked. If you want to check a link from an ad or a post before you visit, you can also paste it into Haven's free link checker.
To be clear about scope, including where Haven does not help: Haven works in your browser, at the page and the download. It flags fake and unverified sites and pauses downloads there. It is not antivirus, so it does not scan a file's contents or remove malware already installed. And in the newer "paste this command into Terminal" version of the attack, there is no download for Haven to pause and the page may sit on a trusted domain, so the essential defense there is simple and human: never paste a command from a web page to "finish installing" software. Haven's strongest coverage is the fake download page, which is still how most of these attacks work.
How to download AI tools safely
A few habits keep you on the real thing:
Go to the official source. Type the vendor's real address yourself (for example, openai.com or anthropic.com) or use an official app store, rather than clicking a search result or ad.
Do not trust the padlock. A padlock only means the connection is encrypted, not that the site is genuine. Scam sites have padlocks too.
Be extra careful with brand-new AI tools. If you do not know the official URL, look it up from the company's verified site or social account before downloading.
Never paste a command into Terminal or PowerShell to "finish installing" an app. Real installers do not work that way, and this is a common trap.
Prefer official package managers (like the App Store, Microsoft Store, or brew/pip/npm for developers) over web-based install instructions.
If you already installed a fake AI app, treat the device as compromised: from a separate clean device, change passwords starting with your email, sign out everywhere, and if you hold cryptocurrency, move it immediately and do not reopen wallet apps on the affected machine.
The brand on the fake page will keep changing, ChatGPT today, the next hot AI tool tomorrow. The move underneath stays the same: impersonate a tool you want, get you to a fake page, and get you to install. Slow down at the page and the download, and it falls apart.
About Haven
Haven is a browser extension that helps you make safer trust decisions online, before a scam can cost you anything. It works at the moment you are about to click a link, enter your password, or download a file, flagging fake and impersonated login pages, suspicious links, and lookalike sites, and pausing downloads on unverified sites so you can see what is about to land on your device. Rather than only checking a page against a list of known-bad sites, Haven analyzes the actual page in front of you, so it can catch brand-new and convincing fakes that other tools miss.
Haven is free for individual use. For teams, Haven for Business extends this browser-level protection across every employee. Haven is operated by MirrorTab, Inc.

