{"slug": "answer-engines-trojanised-installations-and-the-new-routes-attackers-are", "title": "Answer engines: trojanised installations and the new routes attackers are exploiting", "summary": "Attackers are exploiting AI answer engines to deliver malware through fake and trojanised software recommendations, according to Danny Jenkins, CEO of ThreatLocker. Recent cases include a Bing AI response directing a user to a fake GitHub repository for OpenClaw that installed information-stealing malware, and Microsoft investigating over 150 domains impersonating utilities like CrystalDiskInfo and HWMonitor that delivered genuine software alongside hidden remote-access tools and cryptocurrency miners. The shift from traditional web browsing to AI-generated answers is creating new attack vectors that security experts are still working to name and counter.", "body_md": "*Guest post by Danny Jenkins, CEO at **ThreatLocker*\n\nAI is changing the rules of web browsing. Instead of comparing multiple sources, users are asking AI answer engines for recommendations and acting on the responses they receive.\n\nHistory shows that criminals exploit every major shift in how people use technology, and the move from traditional web browsing to AI-generated answers is no exception.\n\nThe security industry has not yet settled on a specific name for these techniques. Terms such as AI search poisoning, answer-engine manipulation, AI/SEO poisoning, and malicious generative engine optimisation (GEO) are all used to describe attempts to influence AI-generated recommendations. Regardless of the label, the objective is to become the source an AI system recommends and that users inadvertently trust.\n\nAttack methods vary, but each one works by making a malicious source look trustworthy.\n\n##### The many shapes of a malicious software recommendation\n\nPeople routinely ask AI engines where to find software they need. If an attacker can shape that answer, malware lands directly in front of someone who is actively looking to install something, and the resulting download could be anything from a completely fake application to a legitimate one.\n\nA fake installer is the simplest case. A recent real-world example involved a user searching Bing for the AI assistant OpenClaw. They were then directed by Bing’s AI-generated response to a newly created GitHub repository posing as the official download. What it delivered in place of OpenClaw was information-stealing malware that turned the victim’s machine into a proxy for later attacks. Nothing about the underlying software was genuine.\n\nAnother case is a trojanised installer, which is much harder to catch because part of what a user receives is very much real. Microsoft investigated more than 150 domains impersonating utilities such as CrystalDiskInfo, HWMonitor, FurMark, and PDFgear, some of which surfaced through poisoned search results and others through AI chatbot answers. The downloaded packages contained the genuine utility, running normally, alongside a hidden file installing remote-access tools and cryptocurrency miners in the background. A user grows suspicious when a promised application never runs. A trojanised installer removes that signal. It hands over exactly what was requested, plus something never agreed to.\n\nLastly, the third type of case involves entirely original apps that provide a legitimate service while hiding a malicious payload. Free VPN apps marketed under names like MaskVPN and DewVPN, for instance, worked exactly as advertised. What they didn’t disclose was that installing one also enrolled the device in a residential proxy network that spanned more than 19 million IP addresses and was rented out for large-scale fraud. There was no fake wrapper or trojanised download. The VPN worked, and that was the point.\n\n##### When the recommendation becomes the attack\n\nSoftware attacks do not always arrive through a download button. Users now rely on AI-generated technical guidance to solve problems. Attackers are finding ways to place harmful instructions within seemingly helpful content.\n\nThis approach shares many characteristics with ClickFix attacks. A user searching for troubleshooting advice may be told to execute commands, modify system settings, or install additional tools. If those instructions have been manipulated by an attacker, the victim may effectively compromise their own system while believing they are fixing an issue.\n\nThe same risk extends to developers, who ask AI tools to recommend APIs and code samples, sometimes from a fraudulent source an attacker has spent months making look established. GitHub repositories, blog posts, forum answers, and developer profiles can all be used to give a malicious API or service an artificially positive track record. Developers who rely on AI-generated recommendations without validating the source could unknowingly introduce risk into their environments.\n\nFor a developer under pressure to solve a problem quickly, a confident answer backed by several matching sources can appear persuasive. In some cases, all those sources may trace back to the same attacker in the end.\n\n##### A website can also target the AI\n\nAn ill-intentioned webpage doesn’t need a human visitor to fall for anything. It can leave instructions for whatever AI system reads the page on that person’s behalf, a technique known as indirect prompt injection. Those instructions get buried in a page’s metadata, HTML comments, or other text no visitor would ever see.\n\nWhen an AI system reads and summarises the page, it may interpret those hidden phrases as instructions. Those commands might include prompts to agentic AI to install malware or exfiltrate data.\n\n##### Zero Trust is built to fight manipulation\n\nThis is exactly the situation Zero Trust is designed for. It assumes a user, developer, or AI agent will eventually follow an ill-meaning recommendation, so instead of depending on everyone to catch every new attack technique, controls are implemented that keep working after trust has already been misplaced.\n\nApplication allowlisting stops two different problems. Unapproved software doesn’t run just because it arrived through a source that looked trustworthy, including one an answer engine recommended. A modified version of an already-approved utility doesn’t run either, since altering the file changes what allowlisting is checking against.\n\nWhat happens after something does run matters just as much. A compromised system utility does not need unrestricted access to PowerShell, scripting tools, or a company’s sensitive files, and limiting what approved software is allowed to do keeps one infected application from becoming a route into everything else. The same logic applies to both people and AI agents to ensure tight access, narrow permissions, and separate approval for anything sensitive. Least privilege keeps an attacker who has gained a single foothold from moving freely through the rest of the environment.\n\n##### Trust has become the target\n\nThe underlying objectives of cybercriminals have not changed, but they are always developing new tactics.\n\nUsers cannot assume that a recommendation is safe simply because it was delivered confidently by an AI system.\n\nAs answer engines become a primary interface between users and information, trust itself is becoming a target. Zero Trust provides a practical response by enforcing security at the point where software executes and access is granted.\n\nSee more stories [here](https://irishtechnews.ie/).\n\n```\nMore about Irish Tech News\nIrish Tech News are Ireland’s No. 1 Online Tech Publication and often Ireland’s No.1 Tech Podcast too.\nYou can find hundreds of fantastic previous episodes and subscribe using whatever platform you like via our Anchor.fm page here: https://anchor.fm/irish-tech-news\nIf you’d like to be featured in an upcoming Podcast email us at [email protected] now to discuss.\nIrish Tech News have a range of services available to help promote your business. Why not drop us a line at [email protected] now to find out more about how we can help you reach our audience.\nYou can also find and follow us on Twitter, LinkedIn, Facebook, Instagram, TikTok and Snapchat.\n```\n\n", "url": "https://wpnews.pro/news/answer-engines-trojanised-installations-and-the-new-routes-attackers-are", "canonical_source": "https://irishtechnews.ie/answer-engines-trojanised-installations-and-the-new-routes-attackers-are-exploiting/", "published_at": "2026-07-28 12:00:07+00:00", "updated_at": "2026-07-28 12:04:37.478487+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-safety", "ai-products"], "entities": ["ThreatLocker", "Danny Jenkins", "Microsoft", "OpenClaw", "CrystalDiskInfo", "HWMonitor", "FurMark", "PDFgear"], "alternates": {"html": "https://wpnews.pro/news/answer-engines-trojanised-installations-and-the-new-routes-attackers-are", "markdown": "https://wpnews.pro/news/answer-engines-trojanised-installations-and-the-new-routes-attackers-are.md", "text": "https://wpnews.pro/news/answer-engines-trojanised-installations-and-the-new-routes-attackers-are.txt", "jsonld": "https://wpnews.pro/news/answer-engines-trojanised-installations-and-the-new-routes-attackers-are.jsonld"}}