logo

AI Hype Hijacked: How a Fake Claude Installer Blinds Windows Security

ID: b9f918cf-e08b-5b3e-9e24-82a865fd2e98

STIX ID: report--b9f918cf-e08b-5b3e-9e24-82a865fd2e98

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-21

Date Updated: 2026-04-23

Author: Ddos

...
...

Rapid7 analysis describes a sophisticated ClickFix campaign using a fake Claude MSIX bundle that is actually a ZIP containing an HTA with obfuscated VBScript. The VBScript decodes and runs a PowerShell staging payload that tailors callbacks using an MD5 of the host identifiers, disables AMSI by corrupting amsiContext, and injects encrypted shellcode into memory via native NT APIs; detection occurred when mshta.exe was observed executing suspicious arguments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.