logo

The Claude Code Trap: Bitdefender Unmasks Fake Google Ads Hijacking Developer Terminals

ID: f0e25944-d324-543e-9abb-6efd19505283

STIX ID: report--f0e25944-d324-543e-9abb-6efd19505283

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-03-16

Date Updated: 2026-04-23

Author: Ddos

...
...

Bitdefender uncovered a malvertising campaign that spoofs Anthropic’s Claude documentation in sponsored search results to trick developers into executing terminal commands (a tactic called “ClickFix”). The fake pages host OS-specific payloads: on Windows, commands invoking mshta.exe fetch multi-stage credential stealers identified as Trojan.Stealer.GJ/GK; on macOS, obfuscated Base64-decoded shell commands install a Mach-O backdoor that provides remote reverse-shell control. Attackers used a compromised, previously trusted advertiser account to bypass ad scrutiny.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.