Hackers Using Fake Claude AI Installer Pages to Trick Users Into Running Malware on Their Systems
ID: 4cd2907c-4e86-5ac2-b6ec-250c4086d20c
STIX ID: report--4cd2907c-4e86-5ac2-b6ec-250c4086d20c
Feed Name: cybersecurityNews.com
Trend Micro documented an "InstallFix"/Fake Claude Installer campaign that uses sponsored Google Ads and convincing fake Claude AI install pages to entice victims to run OS-specific commands; the commands trigger a multi-stage infection (mshta -> HTA/VBScript -> obfuscated PowerShell) that delivers an info‑stealer linked to RedLine, establishes persistence via scheduled tasks, and exfiltrates browser and e‑wallet data. The report includes domains, URLs, file names, file hashes, and IPs as IoCs and recommends blocking malicious domains/IPs, using DNS filtering, restricting legacy scripting tools (mshta.exe), and user training to avoid running commands from sponsored search results.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
