Kaspersky Reports Surge in AI-Themed Malware Attacks Targeting SMBs

Cybersecurity firm Kaspersky detected more than 33,300 malware attacks targeting small and medium-sized businesses (SMBs) from January to April 2026. These attacks, which Kaspersky compared to the same period in 2025, primarily used popular artificial intelligence services as lures.

The shift in tactics is stark. While traditional lures like fake communication apps remain a threat, attackers are now weaponizing the corporate rush to adopt AI. By mimicking trusted tools, threat actors are successfully tricking SMB employees into installing malicious software that can steal, block, or modify sensitive corporate data.

ChatGPT, Claude, and DeepSeek as Malware Lures

The most frequent targets of impersonation are the industry’s heavy hitters. According to data from Kaspersky, the most common lures at the start of 2026 were malware posing as ChatGPT (42%), Claude (24%), and DeepSeek (20%).

It isn’t just the established giants. Analysts also identified hundreds of incidents involving malware disguised as OpenClaw, an AI application that gained rapid popularity among business users in 2026. In total, researchers identified approximately 1,100 unique malicious samples tied to these AI lures, a 21% increase over the previous year.

These campaigns rely heavily on Trojware. These programs trick users into believing they are installing a harmless AI tool, but once inside the system, they can download additional harmful software or perform other damaging actions on the infected device.

Stable Threats: Telegram, Zoom, and Microsoft Teams

Despite the AI-driven spike, the volume of attacks disguised as communication tools remains high, though the growth is far less aggressive. From January to April 2026, Kaspersky solutions blocked nearly 415,000 attacks posing as Telegram, WhatsApp, Zoom, and Microsoft Teams.

Unlike the AI lures, the number of these communication-based attacks changed only marginally compared to 2025 figures. This suggests that while the “fake app” strategy is still a widespread threat, the AI-themed approach is the primary driver of new growth in the SMB sector.

Regional Surges in Southeast Asia and Manila

The trend is particularly acute in specific geographic corridors. In the Philippines, malware attacks targeting SMEs grew by more than four times in the first half of the year, rising from 434 hits in the previous year to 1,847. This mirrors a broader regional trend where Kaspersky blocked 44,022 cyberthreats against SMEs across Southeast Asia, a 364-percent increase from the 9,482 hits recorded in the prior year.

Anatomy of a Cyber World | 2026 Kaspersky Security Services Global Report

These attacks often enter the network via phishing emails or fake text messages. Additionally, the company warned of social engineering and drive-by downloads, where users accidentally download malicious code simply by visiting a compromised website.

The Resource Gap for Micro-Businesses

The vulnerability of SMBs often stems from a fundamental misconception about their own risk profile. Many business owners believe they are too small to be targeted, but any device connected to the internet is a potential entry point.

Love seekers beware: Valentine's Day scams abound
Photo: business.inquirer.net

It’s always easy—and popular— to think that your business is too small to be a target.

Yeo Siang Tiong, general manager of Kaspersky at Southeast Asia

Beyond mindset, there is a practical struggle with budget and time. Rodion Pyanov, a product manager at Kaspersky Small Office Security, noted that micro-organizations often lack the resources to regularly update staff on the latest malicious trends. To counter this, the company suggests that security platforms specifically designed for small businesses can provide the necessary core protection and accessible education to bridge this gap.

Mitigation and Defense Strategies

To reduce exposure, security experts emphasize a combination of technical tools and strict internal policies. For those without dedicated security personnel, managed detection and response (MDR) services can provide the 24/7 monitoring required for the full incident management cycle.

Malware
Photo: crowdfundinsider.com
  • Access Control: Define strict rules for corporate resources, including shared folders and email accounts, and revoke permissions promptly when they are no longer needed.
  • Verification: Carefully check the spelling of websites and links in suspicious emails before downloading software.
  • Data Preservation: Maintain regular backups of critical corporate information to limit damage from successful attacks.
  • Scalable Tools: Use security solutions matched to the company’s size, such as EDR (Endpoint Detection and Response) and XDR (Extended Detection and Response) for organizations with more mature IT expertise.

As AI tools continue to integrate into daily business operations, the risk remains that employees will rely on publicly available platforms without verifying the source of the software they download. The ongoing challenge for SMBs will be balancing the speed of digitalization with the necessity of security awareness training.

Anatomy of a Cyber World | Kaspersky Security Services Global Report 2026

More on this


Discover more from Archyworldys

Subscribe to get the latest posts sent to your email.