TL;DR:
- Criminals are distributing infostealer malware disguised as free AI apps — fake ChatGPT desktop apps, AI image tools, and productivity assistants promoted heavily on social media and via Google Ads
- Once installed, these tools steal saved passwords, browser session cookies, cloud storage files, and cryptocurrency wallets — often without the victim noticing anything is wrong
- The defence is straightforward: only install software through official app stores or the verified vendor website, and use a password manager so stolen saved passwords aren’t your only line of defence
Demand for AI tools is high and supply from criminals is obliging. Over the past 18 months, cybersecurity teams have catalogued hundreds of campaigns distributing malware disguised as popular AI applications. The pattern is consistent: take a legitimate product (ChatGPT, Midjourney, DALL-E, or a lesser-known AI productivity tool), create a convincing-looking alternative, promote it heavily through social media ads and SEO, and distribute an installer that runs the promised function while silently harvesting everything valuable on the machine.
For small businesses, this is a significant threat. Staff routinely search for “free AI tools” to help with marketing, content creation, customer service scripts, and administrative tasks. The malicious versions look professional and often work — they just also steal everything in the background.
What These Tools Actually Do
The malware category is called infostealers, and they do exactly that. When installed, they silently collect:
- Saved browser passwords — Chrome, Edge, Firefox, Brave all store passwords locally. Infostealers extract them in seconds.
- Browser session cookies — These are the tokens that keep you logged into websites without entering your password again. A stolen session cookie for your business email, accounting software, or online banking bypasses your password and sometimes your MFA.
- Autofill data — Names, addresses, card numbers stored in browser autofill.
- Files matching certain patterns — Documents containing “password”, “invoice”, “bank”, “payroll” are commonly targeted.
- Cryptocurrency wallet files — High-value target in many campaigns.
- Screenshots and keystrokes — Some variants capture ongoing activity, not just what’s already stored.
The collected data is compressed and sent to the criminal’s server, often within minutes of installation. Most infostealers are undetected by standard antivirus for the first days or weeks of distribution — the criminals test their tools against detection software before releasing them.
How They’re Distributed
Social media advertising: Paid ads on Facebook, Instagram, and TikTok promoting “Free ChatGPT Desktop App”, “AI Image Generator — No Account Needed”, or similar. Meta’s ad review process is imperfect at catching these. The ads look professional and link to convincing landing pages.
Google Ads: Search for “chatgpt desktop app” or “free AI writing tool download” and you may find sponsored results leading to malicious sites. Google removes these when reported, but they reappear under new domains.
SEO-poisoned results: Some campaigns build convincing websites that rank genuinely in search results for AI tool terms, distributing malware through what appear to be legitimate software download pages.
Discord and Telegram: AI-focused communities on these platforms are frequently targeted with “beta access” links to new AI tools that turn out to be malware installers.
Cracked software sites: Sites offering cracked or free versions of paid software increasingly bundle infostealers with the downloaded files.
Real Examples
The Vidar and Lumma infostealers have appeared extensively in fake AI tool campaigns in 2025-2026. Lumma Stealer in particular has been distributed through fake ChatGPT and Midjourney Windows applications, targeting browser credentials and cloud storage access tokens.
FakeBat (a loader malware) has been distributed via Google Ads campaigns promoting fake AI productivity tools, dropping infostealers and remote access trojans on installation.
Campaigns targeting Canva AI, Notion AI, and various small-company AI productivity tools have been documented by ESET, Malwarebytes, and Sophos researchers throughout 2025 and 2026.
Warning Signs
A suspicious AI tool download typically has one or more of these characteristics:
- The download is a Windows
.exefile from a website you haven’t heard of before - The installer requests admin privileges immediately
- The “official” website has recently registered domain (check with whois lookup tools)
- Social media ads promoting it are from accounts created in the past few weeks
- The site doesn’t have clear company contact information or a real physical address
- It’s promoted as “free” for a paid tool that requires expensive compute to run (real tools charge because running AI is expensive)
What to Do
Check the real domain: ChatGPT is at chat.openai.com. Midjourney is at midjourney.com. Claude is at claude.ai. When looking for a tool you’ve seen advertised, search directly for the tool name plus the company name, not the ad link.
Use official app stores where possible: The Mac App Store and Windows Store have imperfect but real verification processes. Prefer these to direct downloads.
Don’t allow installs from unverified publishers: Windows shows a warning when running software from an unverified publisher (“Unknown publisher” in the UAC prompt). For software your IT support hasn’t approved, this is a stop sign.
Don’t save passwords in your browser: Use a dedicated password manager (Bitwarden, 1Password) instead. Stolen browser session cookies can still be used, but at least the criminal doesn’t also have all your saved passwords.
Enable MFA on critical accounts: Session cookie theft can bypass passwords, but phishing-resistant MFA (hardware security keys, passkeys) is much harder to bypass. Enable this on your business email, banking, and accounting platforms at minimum.
Report suspicious ads: If you see a social media ad promoting a suspicious AI tool download, report it using the platform’s ad reporting function. This removes it for other potential victims.
If you think a machine in your business may have run one of these installers, treat it as compromised: change passwords for all accounts accessible from that device, revoke active sessions in your email and key apps, and have a security professional assess the machine.
The NCSC’s Suspicious Email Reporting Service (SERS) at report@phishing.gov.uk is also relevant here — if you received the link by email, forward it there.