The InstallFix Trap: Fake Claude AI Google Ads Drop Fileless RedLine Malware on Developers
ID: 3c363193-63be-5594-9b6a-3162f757536c
STIX ID: report--3c363193-63be-5594-9b6a-3162f757536c
Feed Name: securityonline.info
The report documents the InstallFix campaign: attackers buy high‑rank Google Ads to push fake Claude AI installers that instruct victims to paste shell commands, which fetch a deceptive claude.msixbundle (a ZIP/HTA polyglot). Execution via mshta.exe runs an appended VBScript that launches an obfuscated PowerShell stager employing AMSI and SSL bypasses to download RedLine Stealer variants in memory, harvest browser credentials/cookies and crypto wallets, and establish persistence; telemetry shows global targeting across government, education and industry.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
