Threat Actors Exploit Fake Claude Code Downloads to Deploy Infostealer Malware
ID: 700e91f2-46b5-51a4-abb7-13badf4c98bb
STIX ID: report--700e91f2-46b5-51a4-abb7-13badf4c98bb
Feed Name: GBHackers
**Executive summary:** Threat actors are distributing a lightweight infostealer by hosting fake Claude Code download portals that deliver script-based loaders or shortcuts which invoke mshta.exe to fetch and execute remote HTA payloads; the HTA harvests credentials, browser data, and system information and exfiltrates it to attacker-controlled infrastructure. Defenders should monitor mshta.exe invoking remote URLs, unexpected parent processes, and outbound connections to newly seen domains (e.g., it.com) as early indicators for containment and hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
