logo

Cybercriminals Abuse SEO Poisoning To Spread Fake Gemini CLI Installers

ID: ad1796be-7701-5217-9a22-d70013d78392

STIX ID: report--ad1796be-7701-5217-9a22-d70013d78392

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-05-26

Date Updated: 2026-05-26

Author: Varshini

...
...

Researchers observed financially motivated actors using SEO poisoning to push fake installation pages for AI developer tools (e.g., Gemini CLI, Claude Code). Victims paste a PowerShell command that loads a fileless infostealer into memory (irm | iex) while a legitimate package installs, enabling stealthy ETW/AMSI bypass, credential and session-token theft from developer tools and communication apps, and exfiltration to C2 domains mimicking Microsoft services; indicators and mitigations are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.