TL;DR: AI is being used as bait and a delivery vehicle rather than as novel malware, with ChatGPT Stealer, InstallFix, and ClickFix-style social engineering driving measurable shifts in browser, endpoint, and credential risk, according to Expel’s Q1 2026 SOC data. The pattern reinforces that identity and access controls, not AI hype, remain the decisive control layer when attackers exploit trusted workflows.
At a glance
What this is: Expel’s Q1 2026 threat report shows AI being used to lure users and deliver malware through browser extensions, fake install pages, and social engineering rather than new attack code.
Why it matters: For IAM, NHI, and identity teams, the finding matters because trusted tools, credentials, and collaboration workflows are being abused as delivery paths, making access governance and user behavior controls part of the same defence problem.
By the numbers:
- Identity-related incidents remained dominant at 58.7% of Expel’s Q1 2026 attack surface mix.
- Teams-based phishing drove 74% of targeted endpoint attacks in the quarter.
- Browser extensions accounted for 12.7% of incidents in Q1, driven largely by ChatGPT Stealer activity.
- ClickFix-based delivery reached 43.7% of malware delivery in Q1 2026 and overtook binary file execution.
👉 Read Expel's Q1 2026 quarterly threat report on AI-driven delivery and credential risk
Context
AI is now part of the threat environment because attackers can use it to increase trust, scale delivery, and hide in familiar workflows. In this case, the primary issue is not AI-generated malware but the misuse of AI branding, browser extensions, and copy-paste installation flows to reach users and harvest data. For identity security teams, the relevance is direct because the same trust assumptions that govern credentials, browser sessions, and collaboration tools are being exploited alongside conventional malware.
Expel’s Q1 2026 data suggests the operational boundary between identity security and malware delivery is getting thinner. Browser-based attacks, collaboration-platform phishing, and credential exposure now reinforce each other, which means governance over accounts, sessions, and user-facing tooling cannot sit apart from endpoint and application controls. That pattern is becoming typical, not exceptional, across modern enterprise environments.
Key questions
Q: How should security teams handle AI-branded malware that targets browser workflows?
A: Treat it as a trust and access problem, not only a malware problem. Restrict unmanaged browser extensions, review AI-tool permissions, and watch for sessions that expose chat content, tokens, or copied commands. The goal is to reduce the attacker’s ability to collect useful identity artefacts from ordinary user workflows.
Q: Why do browser-enabled AI agents increase credential exposure risk?
A: Because they often sit close to secrets, session data, and tool connectors while also being able to act on what they read. If a malicious page can influence the agent, the agent may disclose or use data it should not export. Least privilege and strict data boundaries matter because prompt injection becomes a credential problem, not only a content problem.
Q: What breaks when install instructions can be cloned by attackers?
A: Traditional user awareness and documentation trust break down. If a malicious page looks like official setup guidance, the user may execute attacker-controlled commands without noticing. That makes software installation, developer onboarding, and command execution part of the phishing surface rather than a clean technical process.
Q: What should teams do after access is obtained through social engineering?
A: Focus on limiting what the attacker can do next. Review mailbox rules, token use, cloud API activity, and collaboration-platform lateral movement, then revoke active sessions and rotate exposed credentials. The important question is not only how entry happened, but whether the attacker can turn it into meaningful action.
Technical breakdown
How AI branding becomes a malware lure
Attackers do not need AI-native malware to benefit from AI. They use trusted AI brands, interface familiarity, and productivity expectations to make malicious pages, extensions, or prompts feel routine. In this report, ChatGPT Stealer shows how browser extensions can intercept tabs, scrape content from the DOM, or capture API traffic to exfiltrate conversations. The mechanism works because users treat AI tools as normal work infrastructure, which lowers suspicion and raises click-through rates.
Practical implication: control browser extensions and AI tool access as an identity and session-risk problem, not only as an endpoint hygiene issue.
Why ClickFix-style delivery scales so quickly
ClickFix relies on a simple trust chain. The attacker presents a fake installation flow, usually a clone of legitimate documentation, and convinces the user to copy and run a command that completes the infection. That reduces malware complexity while shifting the burden onto human judgment. Expel’s data shows this model overtaking binary execution in Q1, which signals that social engineering now scales more efficiently than file-based delivery in many environments.
Practical implication: tighten controls around command execution prompts, installation documentation, and developer tooling workflows that can be impersonated.
Where credential weaponisation intersects with AI-enabled delivery
Credential weaponisation means access incidents are less about simple entry and more about what the attacker can do after access is obtained. When AI-assisted social engineering improves delivery, stolen credentials, tokens, and session cookies become more valuable because they support immediate abuse across email, cloud, and collaboration platforms. That turns identity assurance, MFA resistance, and session governance into the main containment layer rather than a back-office control.
Practical implication: prioritize phishing-resistant authentication and session monitoring where browser-driven theft and collaboration-platform abuse overlap.
Threat narrative
Attacker objective: The attacker aims to turn trusted AI workflows into a scalable channel for stealing data, harvesting credentials, and expanding access across enterprise systems.
- Entry occurs through malicious browser extensions or fake installation pages that impersonate legitimate AI tools and developer documentation.
- Credential access follows when the payload captures AI chat content, tokens, browser sessions, or user-entered commands that expose sensitive information.
- Escalation occurs as the attacker reuses the harvested access to move from a single compromised workflow into email, cloud, or collaboration systems.
- Impact is broader credential weaponization, data theft, and operational exposure across identity, endpoint, and cloud environments.
NHI Mgmt Group analysis
AI has become a trust amplifier for traditional malware, not a new malware class. The report shows attackers are using AI branding to increase click rates, lower user suspicion, and widen delivery reach. That means the security problem is less about model innovation and more about how identity trust gets abused in browser, collaboration, and developer workflows. Practitioners should treat AI-adjacent lures as a control-plane issue for access and behaviour.
Prompt poaching is a named concept worth tracking because it extends data loss beyond documents into live AI conversations. AI chat sessions can contain credentials, customer information, and work product that users would never paste into a static file. Once browser extensions can intercept those sessions, the boundary between endpoint protection and identity governance becomes much narrower. Teams should assume AI sessions can carry sensitive identity-bearing data and govern them accordingly.
ClickFix now looks like a durable delivery pattern, not an edge case. The tactic exploits documentation trust, developer routines, and copy-paste habits, which makes it more efficient than binary distribution in many environments. This is where identity security intersects with software supply chains and cloud access, because the same developer who copies an install command often has the permissions an attacker wants next. Practitioners should re-evaluate trust in install flows and command execution.
Credential weaponisation is the real downstream risk, because AI helps attackers convert access into action faster. Fewer access incidents can still mean more harm if each successful intrusion produces better usable credentials, tokens, or sessions. That changes the governance question from “did access occur?” to “what can the attacker do immediately after access?” Security teams should focus on reducing the usable lifetime of stolen identity artefacts.
The market signal is clear: identity, endpoint, and collaboration security are converging around the same attack path. AI is not replacing existing techniques, but it is improving their efficiency and success rate. That means identity governance, browser control, and phishing resistance need to be planned as a connected programme, not separate projects. Practitioners should expect more blended attacks that start with trust and end with access.
What this signals
AI-enabled delivery attacks are likely to keep collapsing the gap between user behaviour and identity compromise. The practical response is to treat browser sessions, extension governance, and collaboration platforms as part of the identity control surface, not as separate hygiene issues.
Prompt poaching: AI conversations now behave like sensitive data stores because users paste operational detail into them. If those sessions are exposed through browser tooling, the organisation has a data loss and identity assurance problem at the same time.
The next control gap is likely to be around proving which AI tools are sanctioned, which browser sessions are trusted, and which copied commands are safe. That is where identity governance, endpoint policy, and cloud access monitoring need to converge.
For practitioners
- Lock down browser extensions tied to AI workflows Create allowlists for browser extensions, block unmanaged AI productivity add-ons, and review extension permissions where users access chat tools or internal data. Tie the review to browser session risk and data access, not only to endpoint policy.
- Harden install and command-copy workflows Treat cloned installation pages and copy-paste terminal prompts as a phishing surface. Add internal guidance for developers, require signed install sources, and inspect outbound commands when users pull tooling from AI-related documentation.
- Prioritise phishing-resistant authentication for browser-heavy users Move high-risk users away from reusable MFA methods toward phishing-resistant controls, then monitor for token theft and session replay where collaboration platforms and browser sessions intersect.
- Monitor for credential weaponization after initial access Use detections that flag rapid follow-on activity after login, especially mailbox rules, cloud API use, and collaboration-platform lateral movement. The objective is to catch the harmful use of access, not just the initial compromise.
Key takeaways
- AI is being used mainly as bait and delivery infrastructure, while the underlying attacks remain familiar social-engineering and infostealer patterns.
- The quarter’s data shows that browser workflows, collaboration platforms, and credentials now form a single attack path rather than separate risk categories.
- Teams should respond by tightening browser, authentication, and command-execution controls around the places where AI tools intersect with identity.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5, CIS Controls v8 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | TA0001 , Initial Access; TA0006 , Credential Access; TA0008 , Lateral Movement | The article centers on phishing, browser-based delivery, and post-compromise abuse. |
| NIST CSF 2.0 | PR.AC-1 | Identity and access controls are central to limiting the impact of stolen sessions and credentials. |
| NIST SP 800-53 Rev 5 | IA-2 | Authentication strength matters when attackers exploit AI-branded lures and session theft. |
| CIS Controls v8 | CIS-6 , Access Control Management | The report points to access and session misuse after social engineering succeeds. |
| NIST AI RMF | GOVERN | The article frames AI as a governance problem around trust, use, and exposure. |
Map browser and collaboration abuse to ATT&CK and prioritize detections for initial access through lateral movement.
Key terms
- Prompt Poaching: Prompt poaching is the covert capture and forwarding of user prompts, conversations, or related context to an unapproved external system. In browser and AI tooling, it often hides behind a legitimate-looking interface, turning user trust into an unwitting data transfer path.
- ClickFix: A browser-delivered social engineering technique that persuades a user to paste and execute a malicious command, usually through clipboard manipulation and a fake instruction sequence. The key risk is that the endpoint may see a normal user action even though the payload originated from a hostile webpage.
- Runtime Weaponization: Runtime weaponization is the shift from a clean-looking extension to one that performs malicious actions only after it is installed and trusted. It often relies on delayed activation, remote payloads, or conditional execution, which makes static review a weak predictor of live behavior.
- Browser Extension Abuse: Browser extension abuse occurs when a trusted add-on is used to capture data, alter browser behaviour, or reuse authenticated sessions. In enterprise environments, the risk is not just malware delivery but silent access to cookies, tokens, and page content inside the user’s trusted browser session.
What's in the full report
Expel's full quarterly threat report covers the operational detail this post intentionally leaves for the source:
- Month-by-month incident breakdowns for Q1 2026 across malware, identity, endpoint, and cloud categories
- The specific telemetry behind ChatGPT Stealer, InstallFix, and ClickFix activity in Expel Workbench
- The full list of malicious browser-extension and cloned-installation patterns observed by the SOC
- Quarterly trend data that shows how credential weaponization changed heading into Q2
Deepen your knowledge
NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, secrets management, workload identity, and identity lifecycle controls. It gives security and identity practitioners a structured way to govern access artefacts that AI-era attacks increasingly target.
Published by the NHIMG editorial team on August 18, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org