Fake Claude AI Installers Used to Spread Malware in New Cyber Scam
ID: 17c21730-1733-5d09-83f7-6e7b0fc0f1be
STIX ID: report--17c21730-1733-5d09-83f7-6e7b0fc0f1be
Feed Name: GBHackers
Threat Score
**Executive summary:** Attackers are running a global campaign that uses sponsored Google search results pointing to cloned Claude AI installer pages; victims copying the provided PowerShell or terminal command trigger a multi-stage, fileless infection (mshta.exe → HTA → obfuscated VBScript → PowerShell) that bypasses AMSI, pulls victim-unique C2 payloads, and focuses on credential theft and reconnaissance, with indicators and tactics overlapping known infostealer families.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
