This page was machine-translated and may differ from the original. View original
Over 15,000 Agentic AI-Disguised Malware Samples Confirmed This Year
As AI agent adoption rapidly expands in enterprise environments, supply chain security threats mediated through external frameworks, APIs, and plugins are emerging as a new challenge. In response, Kaspersky has disclosed a capability to inspect AI components themselves.
Kaspersky (Branch Manager Lee Hyo-eun) announced on the 18th that it will provide malware and backdoor inspection capabilities targeting AI agents, AI models, and "agent skills" that extend functionality to perform specific tasks. The company explained that this capability expands the existing software supply chain security domain into the AI stack, with the aim of enabling employees to proactively identify security risks before introducing AI components into the enterprise environment.
Pre-Inspection System Prior to AI Agent, Model, and Skill Deployment
The capability operates at the infrastructure and supply chain layer within endpoint and threat intelligence products. Inspections are performed both at the point of downloading OpenClaw skills and at the point of actual implementation. Inspection targets include △AI agents △AI models △downloadable agent skills. Kaspersky stated that it can detect malware, backdoors, and bias. Over 15,000 malware samples disguised as agentic AI software have been confirmed this year, and from January 2026 through early May, over 92,000 attacks of malware and unwanted applications impersonating AI agents and services were detected. Among these, fake ChatGPT applications accounted for 49%, while Claude and Gemini each comprised 18%.
Increase in AI-Exploited Attacks and Long-Term Dormancy Cases Confirmed
Kaspersky blocked an average of 500,000 unique malicious files per day last year, a 7% increase compared to the previous year. Attackers generating malware variants using AI was cited as one of the contributing factors to the increase. In 31% of analyzed incidents, malicious activity persisted for over three months, and 52% of high-risk breach cases were only discovered after 90 days. Kaspersky's Global Research & Analysis Team (GReAT) is tracking over 900 attack activities and groups. The Kimsuky APT group, which has been active targeting South Korean government agencies, was confirmed to have exploited Visual Studio Code tunneling, and Kaspersky reported that code traces presumed to be generated by large language models (LLMs) were also discovered in the group's malware.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.















