A new report reveals that cybersecurity threats are rising, as malware attacks on SMBs disguised as popular artificial intelligence services surged by five times in the first four months of 2026. Kaspersky security solutions detected more than 33,300 of these attacks between January and April 2026, representing a massive increase compared to the same period in 2025.

Cybercriminals are increasingly targeting small and medium-sized businesses by exploiting the growing adoption of digital tools. According to the data, the most common lures used in these malware attacks on SMBs involved malicious files posing as ChatGPT at 42 percent, Claude at 24 percent, and DeepSeek at 20 percent. Meanwhile, a newer tool called OpenClaw also emerged as a frequent disguise for malicious software.

Understanding the Nature of Malware Attacks on SMBs

The majority of the unique malicious files detected in this sector were classified as Trojware, which includes Trojans and Trojan-like malware. These programs disguise themselves as harmless files to trick users into installing them, allowing attackers to download other malware onto compromised devices. Once installed, their capabilities include stealing, deleting, blocking, modifying, or copying sensitive corporate data.

Consequently, this type of software represents a highly dangerous threat to entrepreneurs and growing businesses. Security analysts noted that the rapid adoption of digital tools has outpaced the security measures of many smaller organizations, making them prime targets for financial and data theft.

Communication Apps Remain a Major Threat

Beyond artificial intelligence tools, communication and video conferencing apps remain a primary vector for cyberthreats. Kaspersky telemetry blocked nearly 415,000 attacks disguised as Telegram, WhatsApp, Zoom, and Microsoft Teams during the same four-month period. This figure changed only marginally compared to the previous year, indicating that fake communication software remains a widespread threat.

Specifically, the persistence of these attacks highlights how cybercriminals rely on familiar software to exploit human error. Employees frequently download these applications for daily collaboration, often failing to verify the authenticity of the download sources.

Expert Recommendations for Business Protection

Security experts emphasize the need for vigilance as employees integrate external services into their daily workflows. Furthermore, they suggest that businesses must adapt their defense strategies to match these evolving tactics.

“Corporate employees are increasingly using various AI services and other tools in their workflows, including those that are publicly available. Thus, to be on the safe side, SMB employees should exercise caution when looking for software on the internet.”

Vasily Kolesnikov, Security Expert at Kaspersky

To mitigate these risks, organizations should establish clear guidelines for using external services and define access rules for corporate resources. Implementing regular data backups and utilizing scalable security solutions can help prevent significant operational downtime caused by malware attacks on SMBs.

Future Outlook and Security Training

Providing accessible security education is crucial for smaller organizations that may lack dedicated IT security personnel. Many micro-organizations struggle to allocate time and budget to regularly update their staff on the latest threats. However, tailored security solutions can deliver core protection while offering accessible education to help employees recognize suspicious links and files.

In addition, utilizing managed detection and response services can offer round-the-clock monitoring to identify and remediate threats before they impact business operations. As cyber threats continue to evolve, proactive defense remains the most effective way to safeguard corporate assets.