Attackers Abuse SEO Poisoning to Spread Fake Gemini and Claude Installers
ID: 9c0c52ee-3e3e-5ffd-b017-e97f5da1fc16
STIX ID: report--9c0c52ee-3e3e-5ffd-b017-e97f5da1fc16
Feed Name: Cyber Press
Threat actors are using SEO-poisoned, typosquatted installation pages for popular AI developer tools (Gemini CLI, Claude Code, Node.js, etc.) to lure developers into pasting a one-line PowerShell command that installs a legitimate package while loading a fileless infostealer. The malware disables ETW/AMSI, runs in memory, harvests session cookies, credentials, VPN and remote access data, and exfiltrates to C2 servers; researchers observed multiple related domains, a hosting IP, C2 endpoints, and a downloader script name and recommend hunting for 'irm | iex' patterns and enforcing PowerShell constrained language on developer workstations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
