Cyber Secure India Latest News Technology

AI-themed malware attacks on Indian SMBs surge over sixfold in 2026, warns Kaspersky

Cybercriminals are increasingly disguising malware as popular AI tools such as ChatGPT, DeepSeek and Claude to target small and medium-sized businesses in India, with attacks rising more than sixfold in

AI-themed malware attacks on Indian SMBs surge over sixfold in 2026, warns Kaspersky
Digital India Times Site Icon
  • PublishedAugust 3, 2026

Between January and April 2026, Kaspersky blocked nearly 415,000 attacks globally in which malicious software was disguised as messaging and video conferencing applications such as Telegram, WhatsApp, Zoom and Microsoft Teams.
Between January and April 2026, Kaspersky blocked nearly 415,000 attacks globally in which malicious software was disguised as messaging and video conferencing applications such as Telegram, WhatsApp, Zoom and Microsoft Teams.

NEW DELHI: The rapid adoption of artificial intelligence (AI) tools by businesses is creating a new avenue for cybercriminals, with malware attacks targeting Indian small and medium-sized businesses (SMBs) disguised as popular AI services increasing more than sixfold during the first four months of 2026, according to a new report by cybersecurity company Kaspersky.

The report reveals that Kaspersky security solutions detected more than 33,300 attacks globally between January and April 2026 in which malicious or unwanted software masqueraded as legitimate AI applications. This represents nearly a fivefold increase over the same period in 2025. India alone accounted for more than 600 of these attacks, recording one of the sharpest increases globally.

According to the analysis, cybercriminals are exploiting the growing popularity of AI-powered productivity tools by tricking users into downloading fake software disguised as well-known AI platforms. In India, malware impersonating ChatGPT accounted for 41% of detected AI-themed attacks, followed closely by DeepSeek at 40%, while Claude represented 15% of the cases.

The report notes that the majority of these malicious files were Trojans capable of downloading and executing additional malware after infecting a device. Depending on their design, such malware can steal confidential information, copy or modify files, delete data, block access to systems or perform a range of other malicious activities, making them particularly dangerous for businesses.

While AI-themed attacks are rising rapidly, cybercriminals continue to rely heavily on fake communication and collaboration platforms as infection vectors. Between January and April 2026, Kaspersky blocked nearly 415,000 attacks globally in which malicious software was disguised as messaging and video conferencing applications such as Telegram, WhatsApp, Zoom and Microsoft Teams. The company noted that these lures remain among the most persistent cyber threats facing small businesses.

Kaspersky researchers also observed emerging attacks involving malware disguised as OpenClaw, an AI tool that has gained popularity in 2026. The findings suggest that cybercriminals are quickly adapting their tactics to exploit whichever AI applications are attracting widespread business adoption.

Commenting on the findings, Vasily Kolesnikov, Security Expert at Kaspersky, said businesses should remain vigilant when downloading software or accessing online services. He advised employees to verify website addresses carefully, avoid suspicious email links and use robust cybersecurity solutions to reduce the risk of infection.

Rodion Pyanov, Product Manager for Kaspersky Small Office Security, said cybercriminals continue to refine their methods by exploiting human error, making regular security awareness training essential even for small organisations that often have limited cybersecurity resources.

Highlighting the Indian threat landscape, Jaydeep Singh, General Manager, India at Kaspersky, said cybercriminals increasingly view Indian SMBs as attractive targets because of their rapid adoption of AI tools in everyday business operations.

He noted that India has more than 99% of its enterprises classified as SMBs, making the scale of the threat particularly significant. Kaspersky said it blocked more than 10.6 million internet-borne threats on Indian systems during the first quarter of 2026 alone, underscoring the growing intensity of cyberattacks targeting businesses.

“The more than six-fold surge in malware disguised as popular AI services is a clear signal that threat actors are keeping pace with technology trends and exploiting the tools businesses rely on most,” Singh said, adding that cybersecurity should now be treated as a core business priority rather than an afterthought.

To strengthen cyber resilience, Kaspersky recommends that businesses adopt security solutions suited to their size and operational requirements, establish clear policies governing the use of external software and AI services, restrict access to corporate resources based on business needs, and maintain regular backups of critical data. The company also advises organisations lacking dedicated cybersecurity teams to consider managed detection and response services that provide continuous monitoring and rapid incident response.

The report underscores how the growing integration of AI into everyday business operations is creating new opportunities for cybercriminals, making employee awareness and proactive cybersecurity measures increasingly critical for India’s SMB sector.

Author

Leave a Reply

Your email address will not be published. Required fields are marked *