From January to April 2026, Kaspersky security solutions detected more than 33 300 attacks on small and medium-sized businesses (SMBs), in which malicious or unwanted software for PCs was disguised as popular artificial intelligence (AI) services. This number has surged to nearly five times the same period in 2025.
A new Kaspersky report presents threat analysis and mitigation strategies to help SMBs protect themselves in an evolving threat landscape.
Kaspersky experts explored the extent to which threat actors target small and medium-sized businesses with malware disguised as legitimate AI services, given the growing popularity of such tools in business workflows. At the beginning of 2026, the most common lures in cyberattacks involved malware posing as ChatGPT (42%), Claude (24%), and DeepSeek (20%).
Among the unique malicious files detected in the SMB sector and masqueraded as AI services, Kaspersky experts observed mainly various Trojanware (Trojans and Trojan-like malware), including those capable of downloading and executing other malware on compromised devices. Trojanware disguises itself as harmless files to trick users into installing them. Their functionality may vary depending on the type of malware. It may include stealing, deleting, blocking, modifying or copying users’ data, as well as other malicious capabilities.
However, in 2026, Kaspersky telemetry detected even more attacks on SMBs, in which malicious or unwanted software for PCs was disguised as messenger apps and video conferencing software, including Telegram, WhatsApp, Zoom, and Teams. From January to April, Kaspersky solutions blocked almost 415 000 such attacks. The number of attacks changed marginally compared to the previous year’s figures. Thus, Kaspersky experts note that the lure of fake communication apps remains a widespread cyberthreat.
“The threat landscape is evolving with new lures constantly appearing. For example, for the first four months of this year, our solutions for small and medium-sized businesses detected hundreds of attacks, in which malicious or unwanted software was disguised as OpenClaw – an AI tool that rapidly gained popularity in 2026. Corporate employees are increasingly using various AI services and other tools in their workflows, including publicly available ones. Thus, to be on the safe side, SMB employees – as well as all users – should exercise caution when looking for software on the Internet,” says Vasily Kolesnikov, security expert at Kaspersky.
“As adversaries constantly refine their methods to exploit human error, the need for up-to-date security awareness training for businesses of all kinds and sizes is undeniable. However, the reality is that micro-organisations often struggle to allocate time and budget to regularly update their staff on the latest threats and malicious trends. We believe this issue can be largely addressed through solutions tailored for small businesses which deliver robust core protection, while also providing accessible security education,” adds Rodion Pyanov, product manager, Kaspersky Small Office Security.
Read the full report on the SMB threat landscape at Securelist.com.
© Technews Publishing (Pty) Ltd. | All Rights Reserved.