logo

Threat Actors Exploit Fake Claude Code Downloads to Deploy Infostealer Malware

ID: 700e91f2-46b5-51a4-abb7-13badf4c98bb

STIX ID: report--700e91f2-46b5-51a4-abb7-13badf4c98bb

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-03-05

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

**Executive summary:** Threat actors are distributing a lightweight infostealer by hosting fake Claude Code download portals that deliver script-based loaders or shortcuts which invoke mshta.exe to fetch and execute remote HTA payloads; the HTA harvests credentials, browser data, and system information and exfiltrates it to attacker-controlled infrastructure. Defenders should monitor mshta.exe invoking remote URLs, unexpected parent processes, and outbound connections to newly seen domains (e.g., it.com) as early indicators for containment and hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.