< Back to all clusters
[TECHNOLOGY] · 23 sources

started · updated

AI agents and brand impersonation drive new wave of cyberattacks

Cybersecurity researchers are warning of a rise in sophisticated attacks leveraging artificial intelligence. In the ClawHavoc campaign, attackers targeted the OpenClaw platform by flooding its ClawHub skill registry with over 350 malicious packages. These packages were disguised as legitimate developer, crypto, and automation tools to trick users into installing malware capable of stealing cryptocurrency wallets, passwords, and browser data.

Separately, Sophos researchers identified a trend where criminals use the names of trusted AI brands like Claude, ChatGPT, and Microsoft Copilot to lure victims. By creating fake download pages, malicious browser extensions, and sponsored search ads, attackers trick users into running harmful commands or downloading malware. Sophos noted that Claude was the most frequently abused brand, appearing in 26 of the 38 confirmed cases of hostile AI activity involving software impersonation.

Furthermore, industry experts warn that the development of autonomous AI agents could significantly amplify the scale and speed of cryptocurrency hacks. While current exploits often target single protocols, AI agents could potentially automate and run numerous attacks in parallel, making existing billion-dollar breaches appear minor by comparison.

Entities

ASIC · Anthony Albanese · Apate · Australian Securities and Investments Commission · ChatGPT · Claude · Fidelity Digital Assets · National Anti-Scam Centre · OpenClaw · Sarah Court · Sophos · Trellix

Claims

What the coverage asserts, and how many sources carry each claim.

  • [○ 1 SOURCE] Sophos researchers found that 30 out of 38 confirmed cases of hostile AI activity involved software impersonation. cybersecuritynews.com
  • [○ 1 SOURCE] Attackers flooded the ClawHub registry with over 350 malicious skills. cybersecuritynews.com
  • [○ 1 SOURCE] Trellix identified a campaign targeting the OpenClaw platform using malicious packages. cybersecuritynews.com
  • [○ 1 SOURCE] The ClawHavoc campaign targeted the OpenClaw ClawHub registry with malicious packages disguised as developer, crypto, and automation tools. cybersecuritynews.com
  • [○ 1 SOURCE] Claude was the most frequently abused lure in Sophos’ review, appearing in 26 cases. cybersecuritynews.com

Sources

7 days ago