SEO poisoning campaign leverages Gemini and Claude Code impersonation to deliver infostealer
ID: 940619b4-488c-56b7-9945-a6202f9c91a7
STIX ID: report--940619b4-488c-56b7-9945-a6202f9c91a7
Feed Name: Security Boulevard
Threat Score
Financially motivated actors are conducting an SEO-poisoning campaign that surfaces typosquatted installation pages for Gemini CLI and Claude Code to trick developers into running a single command. The resulting in-memory PowerShell infostealer harvests credentials, OAuth tokens, CI/CD and VPN secrets, and sensitive files, exfiltrating encrypted data to a C2 and providing arbitrary remote code execution that enables hands-on-keyboard intrusions into enterprise environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
