BR100 Increased By (0.36%)
BR30 Decreased By (-0.13%)
KSE100 Increased By (0.22%)
KSE30 Increased By (0.37%)
AGHA 6.68 Increased By ▲ 0.01 (0.15%)
BECO 4.37 No Change ▼ 0.00 (0%)
BML 57.32 Increased By ▲ 0.88 (1.56%)
BOP 30.35 Increased By ▲ 0.01 (0.03%)
CNERGY 13.12 Increased By ▲ 0.03 (0.23%)
CSIL 5.41 Increased By ▲ 0.05 (0.93%)
FCCL 52.79 Increased By ▲ 0.41 (0.78%)
FFL 14.72 Decreased By ▼ -0.02 (-0.14%)
FNEL 1.12 No Change ▼ 0.00 (0%)
KEL 6.09 No Change ▼ 0.00 (0%)
KOSM 5.73 Increased By ▲ 0.77 (15.52%)
LOTCHEM 26.46 Decreased By ▼ -0.89 (-3.25%)
MLCF 93.16 Increased By ▲ 0.41 (0.44%)
NBP 164.66 Decreased By ▼ -0.32 (-0.19%)
NCPL 55.66 Increased By ▲ 0.02 (0.04%)
NPL 61.16 Decreased By ▼ -0.10 (-0.16%)
OGDC 316.73 Decreased By ▼ -1.03 (-0.32%)
PACE 9.87 Decreased By ▼ -0.06 (-0.6%)
PAEL 35.63 Increased By ▲ 0.13 (0.37%)
PIBTL 14.68 Increased By ▲ 0.11 (0.75%)
PPL 226.91 Decreased By ▼ -0.88 (-0.39%)
PRL 93.02 Increased By ▲ 0.45 (0.49%)
PTC 60.26 Decreased By ▼ -0.37 (-0.61%)
SSGC 23.81 Increased By ▲ 0.01 (0.04%)
TBL 8.75 Increased By ▲ 0.07 (0.81%)
TELE 7.80 Increased By ▲ 0.02 (0.26%)
TPL 22.35 Increased By ▲ 0.12 (0.54%)
TPLP 12.97 Increased By ▲ 0.30 (2.37%)
TREET 22.16 Decreased By ▼ -0.38 (-1.69%)
TRG 56.56 Decreased By ▼ -1.24 (-2.15%)

ISLAMABAD: A global cybersecurity company Thursday disclosed that around 8,500 users from small and medium-sized businesses (SMBs) faced cyberattacks where malicious or unwanted software was disguised as popular online productivity tools during 2025.

In this regard, the Kaspersky has issued a report. Based on the unique malicious and unwanted files observed, the most common lures included Zoom and Microsoft Office, with newer AI-based services like ChatGPT and DeepSeek being increasingly exploited by attackers. Kaspersky has released threat analysis and mitigation strategies to help SMBs respond.

Kaspersky analysts explored how frequently malicious and unwanted software are disguised as legitimate applications commonly used by SMBs, using a sample of 12 online productivity apps. In total, Kaspersky observed more than 4,000 unique malicious and unwanted files disguised as popular apps in 2025. With the growing popularity of AI services, cyber criminals are increasingly disguising malware as AI tools. The number of cyber threats mimicking ChatGPT increased by 115% in the first four months of 2025 compared to the same period last year, reaching 177 unique malicious and unwanted files. Another popular AI tool, DeepSeek, accounted for 83 files. This large language model launched in 2025 immediately

appeared on the list of impersonated tools.

“Always check the correct spelling of the website and links in suspicious emails. In many cases these links may turn out to be phishing or a link that downloads malicious or potentially unwanted software,” says Vasily Kolesnikov, security expert at Kaspersky.

Another cyber criminal tactic to look for in 2025 is the growing use of collaboration platform brands to trick users into downloading or launching malware. The number of malicious and unwanted software files disguised as Zoom increased by nearly 13% in 2025, reaching 1,652, while such names as “Microsoft Teams” and “Google Drive” saw increases of 100% and 12%, respectively, with 206 and 132 cases. This pattern likely reflects the normalization of remote work and geographically distributed teams, which has made these platforms integral to business operations across industries.

Among the analyzed sample, the highest number of files mimicked Zoom, accounting for nearly 41% of all unique files detected. Microsoft Office applications remained frequent targets for impersonation: Outlook and PowerPoint each accounted for 16%, Excel for nearly 12%, while Word and Teams made up 9% and 5%, respectively.

The top threats targeting SMBs in 2025 included downloaders, trojans and adware.

Apart from malware threats, Kaspersky continues to observe a wide range of phishing and scam schemes targeting SMBs. Attackers aim to steal login credentials for various services — from delivery platforms to banking systems — or manipulate victims into sending them money through deceptive tactics. One example is a phishing attempt targeting Google Accounts. Attackers promise potential victims to increase sales by advertising their company on X, with the ultimate goal to steal their credentials, the report added.

Copyright Business Recorder, 2025

Comments

Comments are closed for this article.