logo

Fake Claude AI Installer Pages Trick Users Into Malware Downloads

ID: d6062099-cc62-5232-bb62-ed0edae62011

STIX ID: report--d6062099-cc62-5232-bb62-ed0edae62011

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-05-07

Date Updated: 2026-05-08

Author: Varshini

...
...

A sophisticated social-engineering campaign (InstallFix / Fake Claude Installer) uses deceptive Google Ads and pixel-perfect fake installation pages to trick developers into running malicious commands that download a polyglot msixbundle containing an appended HTML Application payload. The chain uses mshta.exe to load a COM Shell Launcher that runs obfuscated VBScript and a heavily disguised PowerShell stager which disables SSL validation, establishes persistence via scheduled tasks, harvests browser and e-wallet data, and contacts attacker-controlled infrastructure across multiple regions and industries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.