Cybercriminals are increasingly disguising malware as artificial intelligence services and exploiting open-source software used in AI development, according to cybersecurity firm Kaspersky.
At its recent Asia Pacific Cyber Security Weekend in China, Kaspersky said its Global Research and Analysis Team (GReAT) recorded 92,000 malicious attacks disguised as AI services in 2026. Nearly half involved applications impersonating ChatGPT.
Attackers typically distribute fake versions of popular AI applications to trick users into downloading malicious software.
Kaspersky said it also identified more than 15,000 unique malware samples posing as AI tools, including trojans and spyware capable of stealing internal information or giving attackers unauthorized access to systems.
The company identified open-source software as another major point of exposure. AI developers rely heavily on publicly available packages, making repositories such as the Node Package Manager (npm) and Python Package Index (PyPI) attractive targets for supply chain attacks.
In these attacks, cybercriminals compromise software packages or development tools that are later incorporated into legitimate applications, allowing malicious code to spread across multiple organizations and users.
A Kaspersky survey found that 31% of enterprises had been affected by supply chain attacks, reflecting the widespread use of open-source components in corporate development environments.
The company advised organizations to impose stricter controls over software entering development systems and clearly separate trusted sources from unverified ones.
Kaspersky GReAT security researcher Sojun Ryu said Southeast Asia’s expanding digital environment has increased the number of potential entry points for attackers, while the region’s ability to detect and respond to threats remains uneven.
Historical underinvestment in cybersecurity has contributed to gaps in visibility and preparedness, although organizations are beginning to allocate more resources toward structured security systems, according to Ryu.
Advanced threat groups are also using AI to assist in malware development and carry out more sophisticated supply chain attacks.
The trend is increasing pressure on companies to weigh the productivity benefits of AI tools against the security risks introduced by their rapid adoption.
Kaspersky said it is incorporating AI into its Endpoint Detection and Response and Extended Detection and Response products to improve threat detection and response.
The company added that organizations need to combine global threat intelligence with localized research, as attack methods and active threat groups can differ across countries and regions.


