Possible ACR Stealer From Page Impersonating Claude, (Tue, May 26th)
ID: 3765c49c-1822-5882-a7a4-3ae3ca9b3c0c
STIX ID: report--3765c49c-1822-5882-a7a4-3ae3ca9b3c0c
Feed Name: SANS ISC Diary
Threat Score
This report describes a campaign delivering malware via impersonated "Claude" download pages promoted through malicious Google search ads; the pages present OS-specific install instructions that lead to downloads tied to ACR Stealer. The author provides multiple IOCs — initial and follow-up download URLs, a JPEG linked in the chain, SHA256 hashes, file sizes and types, and an observed post-infection C2 domain — along with traffic captures showing infection behavior.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
