Security

March 16, 2026

Malware deployed using fake software installers

Denison Security

While today’s world is increasingly connected, it is also a common mechanism for threat actors to deliver malicious payloads via social engineering. Maliciously crafted advertisements can be used by threat actors to deliver their malware to unsuspecting victims. In a recent set of cyberattacks affecting multiple sectors, threat actors deployed their malware as a part of a fake AI tool installer, intending to install spyware and viruses on victim computers.

A common attack that targets a corporate environment might play out like this:

  1. The threat actor or threat actor group purchases advertising space pertinent to AI tools. The advertisements generally show as a part of web searches. They link the advertisement to their own, malicious website, which purports to have an AI tool available for download.
  2. The victim downloads the fake AI tool and attempts to install it on their computer.
  3. The installer “fails” to complete the installation, but suggests that the victim paste a command into the Terminal (on macOS) or the PowerShell (on Windows), also stating that the victim may have to enter their password.
  4. The command that the victim copies/pastes into the Terminal or PowerShell is maliciously crafted to sideload a piece of malware, spyware, or virus and alter important system settings. The command the victim runs also gives the threat actor access to the victim’s computer at a low level.

In another attack mechanism, attackers disguised their malware as cheat software for popular video games, like Fortnite or Counter-Strike. These attacks are more effective especially on younger players, who typically don’t have money for paid subscriptions, often ignore warnings, and are often ashamed to report a hack. Victims are often convinced to disable their antivirus, since cheats often behave like viruses. Once the malware is installed, the threat actor has access to the victim’s computer at a low level.

Using their access to the victim’s computer, the threat actor can make the victim’s computer a part of a botnet, infect other computers on the network, steal the victim’s information, or otherwise carry out cyberattacks on both the victim and any computers also on the victim’s network.

There are some simple steps you can use to protect yourself from attacks like these:

  • Don’t run commands in a shell or terminal unless you know what they do and trust their source.
  • When searching on the web in a search engine, make sure the result you are clicking on is legitimate. Advertisements are generally marked at the beginning of the link by a small symbol.
  • Be careful when downloading things from the Internet. Make sure you are downloading your things from a trusted source.
  • If you suspect your computer may be infected, have it examined by a trusted professional.

The Service Desk can provide guidance, but they are not a computer repair shop.


Denison aims to promote the use of inclusive language. While we value the use of inclusive language, terms that are outside of Denison's direct influence are sometimes required for the sake of maintaining user understanding. As other join Denison in embracing the use of inclusive language, Denison will continue to update the documentation to reflect those changes.

Denison Service Desk

Contact the Service Desk by email, phone, or on the Self-Service Portal. You can also find them in Fellows Hall.