logo

Possible ACR Stealer From Page Impersonating Claude, (Tue, May 26th)

ID: 3765c49c-1822-5882-a7a4-3ae3ca9b3c0c

STIX ID: report--3765c49c-1822-5882-a7a4-3ae3ca9b3c0c

Feed Name: SANS ISC Diary

Threat Score
70/100

Date Published: 2026-05-26

Date Updated: 2026-05-26

...
...

This report describes a campaign delivering malware via impersonated "Claude" download pages promoted through malicious Google search ads; the pages present OS-specific install instructions that lead to downloads tied to ACR Stealer. The author provides multiple IOCs — initial and follow-up download URLs, a JPEG linked in the chain, SHA256 hashes, file sizes and types, and an observed post-infection C2 domain — along with traffic captures showing infection behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.