logo

Hackers Using Fake Claude AI Installer Pages to Trick Users Into Running Malware on Their Systems

ID: 4cd2907c-4e86-5ac2-b6ec-250c4086d20c

STIX ID: report--4cd2907c-4e86-5ac2-b6ec-250c4086d20c

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-05-07

Date Updated: 2026-05-08

Author: Tushar Subhra Dutta

...
...

Trend Micro documented an "InstallFix"/Fake Claude Installer campaign that uses sponsored Google Ads and convincing fake Claude AI install pages to entice victims to run OS-specific commands; the commands trigger a multi-stage infection (mshta -> HTA/VBScript -> obfuscated PowerShell) that delivers an info‑stealer linked to RedLine, establishes persistence via scheduled tasks, and exfiltrates browser and e‑wallet data. The report includes domains, URLs, file names, file hashes, and IPs as IoCs and recommends blocking malicious domains/IPs, using DNS filtering, restricting legacy scripting tools (mshta.exe), and user training to avoid running commands from sponsored search results.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.