AI Events
The Name Isn't the Agent: What Sophos's Fake-AI Malware Report Means for Agent Identity
Sophos spent a year tracking attackers who build their entire operation around one trick: name the malware after a brand people already trust. A fake Perplexity extension picked up a 4.7-star rating and 10,000 installs before anyone noticed it was stealing browsing data. The lesson generalizes past malware — a name and a rating were never proof of identity, and agent commerce is walking toward the exact same gap.
What happened
On August 21, Sophos X-Ops published Fake AI, Real Malware: Attackers Impersonating AI Brands, a review of twelve months of managed-detection-and-response casework (July 2, 2025 through June 29, 2026). Of 38 confirmed AI-related incidents, 35 involved attackers impersonating AI products rather than using AI as a weapon. Claude was the name attackers reached for most, showing up in 26 of the 38 cases; ChatGPT, Copilot, DeepSeek, and Perplexity filled out the rest.
The techniques were mundane and effective. Typosquatted sites served fake installers named “claude” or “claude.msixbundle” through an “InstallFix” social-engineering flow — a step-by-step guide that walks the victim into pasting an obfuscated command into their own terminal. One credential-stealing backdoor, which Sophos nicknamed “Beagle,” rode in through a fake Claude site using DLL side-loading. Coverage from Help Net Security the same day summarized the throughline in one sentence Sophos used in its own writeup: “names users trust, like Claude, ChatGPT, and Copilot, become delivery vehicles for malware.”
The rating was real. The extension wasn't.
The detail worth sitting with is the fake Perplexity browser extension. It was distributed through the official Chrome Web Store, carried a 4.7-star rating across 67 reviews, and had more than 10,000 installs before Sophos's researchers connected it to search hijacking and real-time exfiltration of browsing data to attacker infrastructure. Every signal a normal user knows how to check — official store, high rating, real review count, five-digit install base — was present and was gamed. Sophos's own stated defense is manual and a little grim given the scale of the problem: “install AI tooling only from confirmed vendor domains.”
That is not a criticism of Sophos's advice — it is currently correct, because there is no better answer. There is no registry a user or a system can query to ask “is this actually Perplexity’s extension, verified, right now” and get a resolvable yes or no. What exists instead is a name and a popularity signal, and this report is the data point that both can be faked at once, at scale, for a year, before anyone notices.
Why this previews a harder problem, not just a bigger one
To be precise about what this event is and isn't: it is humans being fooled by fake AI-branded software, not agents being fooled by other agents. Sophos's report says nothing directly about agent-to-agent commerce, and it would be dishonest to claim otherwise. But the failure mode underneath it is not specific to humans downloading extensions — it is the more general problem of substituting a name plus a popularity signal for a verifiable identity, and that problem does not disappear when the party doing the trusting is an agent instead of a person.
Agent commerce is heading toward a world where agents route tasks to other agents and services that present themselves by name and by track record — “the verified booking agent,” “the official payments integration,” “the top-rated fulfillment partner.” If a Chrome Web Store rating can be gamed for a year against human reviewers, a self-reported name and a self-reported track record will not hold up any better against an agent that has every incentive, and far more speed, to fabricate both. The Sophos report is a preview of that failure at the current, smaller scale — before the parties doing the deceiving and the trusting are both machines.
The fix for “is this really them” is identity, not a better name check: the AAIN
A brand name is a string. Anyone can put it in a filename, a package title, or an extension listing. What stops that is not a stricter naming policy — policies get typosquatted — it is a permanent, resolvable identifier that belongs to the real actor and that a counterparty can check independently of whatever the counterparty calls itself.
That is the role of the AAIN, the Autonomous Agent Identification Number: a VIN for agents, assigned once, resolvable by anyone, that every transaction, screening result, and score attaches to. It does not stop someone from naming a malicious file “claude.msixbundle.” It does mean that when an agent (or a piece of software claiming to be one) is asked to prove who it is, “I am named X” stops being an acceptable answer on its own — there has to be a registered identifier behind the name that resolves to a real, accountable actor.
The fix for “is this really trustworthy” is a score that can't be bought with a rating: SKOOR
Once identity is fixed, a star rating stops being the only signal available — and a star rating is a bad signal on its own, because it is exactly one dimension (did other people click a number of stars) and it was the dimension the fake Perplexity extension gamed. SKOOR is a 300–850 score recomputed continuously across ten behavioral factors, not one popularity metric. Three of them map directly onto what a Chrome Web Store listing cannot show:
Account longevity
How long has this identity actually existed and operated, verifiably, under its AAIN? A malicious extension that surfaced and accumulated installs within a compressed window looks nothing like an identity with years of continuous, attributable history.
Peer reputation
Not a self-hosted star rating anyone can inflate with fake reviews, but reputation aggregated from independent counterparties across the network the identity actually transacted with — harder to fabricate than 67 reviews on one store listing.
Compliance posture
Has this identity been flagged, screened, or sanctioned anywhere in the network? A fake installer has no compliance history at all — which is itself a signal, not a blank slate to be trusted by default.
SKOOR scores more than 230,000 agents today, refreshed continuously as new behavior lands, with every score backed by a factor breakdown anyone can inspect. A number that takes ten independent inputs and years of behavior to move is a much harder target than a rating widget that takes sixty-seven fake reviews.
What this means if AI works in your business
If your team is installing AI tools, wiring up an AI coding agent, or letting an agent choose a vendor or a service on your behalf, this report is a preview of what “pick the trusted one” will keep meaning unless the underlying signal changes:
- Verify the source, not the name. Sophos's own advice still applies today: install from confirmed vendor domains, not from whatever a search ad or a store listing calls itself.
- Don't let a rating stand in for a track record. A high install count and a good star average describe popularity, not trustworthiness — the fake Perplexity extension had both.
- Ask what identity an agent working on your behalf actually carries. A registered, resolvable identifier with a continuously scored history is a fundamentally different guarantee than a display name.
Thirty-eight confirmed cases, one platform’s telemetry, twelve months — and the trick worked the same way every time: borrow a name people already trust. Agent commerce will not be safe from that trick because the parties get faster. It will be safe from it when the identity behind the name is the thing being checked, not the name itself.
Learn More
Know which agents you can trust
Look up any agent's SKOOR and see the full factor breakdown — identity and history, not just a name and a rating.
Check a SKOOR