logo

Fake Gemini and Claude Code Sites Spread Infostealers Through SEO Poisoning

ID: e85b9ae9-1fcd-5e53-a08e-b7a78d4086d1

STIX ID: report--e85b9ae9-1fcd-5e53-a08e-b7a78d4086d1

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

...
...

Security researchers uncovered a phishing and SEO-poisoning campaign that clones Google Gemini CLI and Anthropic Claude Code installation pages to trick developers into executing a PowerShell command that downloads a memory-resident infostealer; the malware harvests credentials, session cookies, collaboration app data, VPN and wallet files, and exfiltrates encrypted results to attacker C2 infrastructure, with indicators pointing to targeting of US and UK developers and enterprise workstations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.