Fake AI apps malware is now one of the fastest-growing cybersecurity threats globally, with Kaspersky flagging a surge in attacks that weaponise the brand names of ChatGPT, Claude, and Gemini to trick users into downloading malicious software. Cybercriminals are distributing counterfeit versions of these AI tools across unofficial app stores and social media channels. The attacks are accelerating in 2026 as AI app adoption hits record levels worldwide.
What You Need To Know
- Kaspersky identified fake versions of ChatGPT, Claude, and Gemini being used as malware delivery vehicles in 2026
- Attackers are distributing infected APK files through Telegram channels, phishing sites, and third-party app stores
- India ranks among the top five countries globally for exposure to trojanised AI app downloads
- Stolen data includes banking credentials, OTPs, and personal identification files stored on infected devices
How Fake AI Apps Malware Is Hitting Users Right Now
Kaspersky’s threat intelligence team confirmed in 2026 that fake AI apps malware campaigns are exploiting the explosive popularity of generative AI platforms. Attackers clone the interfaces of ChatGPT by OpenAI, Anthropic’s Claude, and Google’s Gemini with alarming accuracy. Users download what looks like a legitimate app, grant permissions, and within minutes hand over full device access to remote hackers. The malware payloads include spyware, banking trojans, and credential-harvesting tools designed to operate invisibly in the background.

Why Should Indian Smartphone Users Be on High Alert?
India’s 750 million-plus smartphone users make it a prime target. Jio, Airtel, and Vi subscribers frequently sideload apps from outside the Google Play Store, a habit that cybercriminals are now aggressively exploiting. Fake AI apps malware spreads rapidly through WhatsApp forwards and Telegram groups, which have hundreds of millions of active users in India. The country’s Digital India push has accelerated AI app adoption at every income level, widening the attack surface considerably in 2026.
Banking trojans embedded in these fake apps specifically target UPI-linked applications like PhonePe, Google Pay, and Paytm. Once installed, the malware silently captures OTPs, scans stored images for Aadhaar and PAN card details, and exfiltrates the data to overseas command-and-control servers. Indian cybersecurity agency CERT-In has not yet issued a specific advisory on this wave of attacks, but security researchers expect one imminently given the scale of infections now being documented across South Asian networks.
“Generative AI is the most powerful social engineering lure we have seen since banking app clones in 2019. Users implicitly trust the ChatGPT name, and attackers are ruthlessly exploiting that trust to deploy some of the most sophisticated mobile trojans in circulation right now.” — Senior Threat Analyst, Cybersecurity Sector
What Happens Next and How Users Can Protect Themselves
Kaspersky urges all users to download AI applications exclusively from verified sources such as the Google Play Store or Apple App Store. Fake AI apps malware campaigns are expected to intensify through mid-2026 as AI tool adoption grows. Users should revoke unnecessary app permissions immediately, enable Google Play Protect, and install a reputable mobile antivirus solution. Telecom operators including Jio and Airtel are being asked by security researchers to activate network-level blocking of known malicious domains linked to these campaigns.
Sources: DOT ↗ | TRAI ↗ | COAI ↗ TelecomTalk — Kaspersky Warns of Fake AI Apps Spreading Malware Attacks
People Also Ask
- What is fake AI apps malware and how does it work? Fake AI apps malware refers to counterfeit versions of popular AI tools like ChatGPT and Gemini that secretly install spyware or banking trojans on a user’s device after they grant standard app permissions during installation.
- How can I tell if I have downloaded a fake AI app? Check the developer name on the app store listing, compare the app size against the official version, and monitor your device for unusual battery drain, unexpected data usage, or unexplained permission requests after installation.
- Which AI apps are cybercriminals faking most often in 2026? Kaspersky reports that ChatGPT by OpenAI, Anthropic’s Claude, and Google’s Gemini are the three most impersonated AI platforms. Their household-name status makes them the highest-value targets for social engineering attacks.





