logo

The InstallFix Trap: Fake Claude AI Google Ads Drop Fileless RedLine Malware on Developers

ID: 3c363193-63be-5594-9b6a-3162f757536c

STIX ID: report--3c363193-63be-5594-9b6a-3162f757536c

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-05-08

Date Updated: 2026-05-08

Author: Ddos

...
...

The report documents the InstallFix campaign: attackers buy high‑rank Google Ads to push fake Claude AI installers that instruct victims to paste shell commands, which fetch a deceptive claude.msixbundle (a ZIP/HTA polyglot). Execution via mshta.exe runs an appended VBScript that launches an obfuscated PowerShell stager employing AMSI and SSL bypasses to download RedLine Stealer variants in memory, harvest browser credentials/cookies and crypto wallets, and establish persistence; telemetry shows global targeting across government, education and industry.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.