logo

Trojanized Gemini and Claude Installers Target Developers Via SEO Poisoning

ID: e40a128f-901b-5f62-97c3-817db0104213

STIX ID: report--e40a128f-901b-5f62-97c3-817db0104213

Feed Name: HackRead

Threat Score
78/100

Date Published: 2026-05-26

Date Updated: 2026-05-26

Author: Deeba Ahmed

...
...

Cybercriminals are using SEO-poisoned, typosquatted sites that mimic AI developer tools (e.g., geminicli.co.com, claudecode.co.com) to trick developers into running a PowerShell command that downloads a fileless infostealer. The in-memory payload disables AMSI/ETW, steals browser credentials, DPAPI-protected app/session keys, cloud-stored files and crypto wallet data, provides remote code execution, and exfiltrates encrypted data to C2 domains such as vents.msft23.com, events.ms709.com, and mo2307.com; the campaign has been active since March–May 2026 and even used a stolen EV certificate to bypass warnings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.