logo

Fake Claude Code Installer on Google Sites Steals Credentials

ID: 5ac99735-5b44-56d0-b38c-9e3d03cae571

STIX ID: report--5ac99735-5b44-56d0-b38c-9e3d03cae571

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-06-04

Date Updated: 2026-06-04

Author: Mayura Kathir

...
...

## Executive Summary: The report describes a ClickFix-style campaign abusing trusted Google Sites to host fake installers for AI developer tools (e.g., Claude Code/Codex) that instruct victims to run an mshta command. That command retrieves obfuscated PowerShell which bypasses AMSI and certificate checks, decodes steganographically concealed shellcode from images, injects and executes it in-memory inside powershell.exe, and exfiltrates browser credentials, email data, and cryptocurrency wallet information.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.