Fake Claude AI Installer Pages Trick Users Into Malware Downloads
ID: d6062099-cc62-5232-bb62-ed0edae62011
STIX ID: report--d6062099-cc62-5232-bb62-ed0edae62011
Feed Name: Cyber Press
A sophisticated social-engineering campaign (InstallFix / Fake Claude Installer) uses deceptive Google Ads and pixel-perfect fake installation pages to trick developers into running malicious commands that download a polyglot msixbundle containing an appended HTML Application payload. The chain uses mshta.exe to load a COM Shell Launcher that runs obfuscated VBScript and a heavily disguised PowerShell stager which disables SSL validation, establishes persistence via scheduled tasks, harvests browser and e-wallet data, and contacts attacker-controlled infrastructure across multiple regions and industries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
