Fake Claude Code Installer on Google Sites Steals Credentials
ID: 5ac99735-5b44-56d0-b38c-9e3d03cae571
STIX ID: report--5ac99735-5b44-56d0-b38c-9e3d03cae571
Feed Name: GBHackers
## Executive Summary: The report describes a ClickFix-style campaign abusing trusted Google Sites to host fake installers for AI developer tools (e.g., Claude Code/Codex) that instruct victims to run an mshta command. That command retrieves obfuscated PowerShell which bypasses AMSI and certificate checks, decodes steganographically concealed shellcode from images, injects and executes it in-memory inside powershell.exe, and exfiltrates browser credentials, email data, and cryptocurrency wallet information.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
