Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Exploit AI Craze with Fake Claude Code Installer

Hackers Exploit AI Craze with Fake Claude Code Installer

Posted on June 5, 2026 By CWS

Cyber attackers are capitalizing on the rising interest in AI coding tools by creating fraudulent Claude Code installation pages, putting users at risk of credential theft. These fake pages are strategically optimized to appear at the top of search results, tricking users into downloading malicious software.

Exploiting User Excitement

The hackers are specifically targeting novices and non-technical users keen to use the new AI tool, Claude Code. Their lack of familiarity with proper installation procedures makes them vulnerable to such scams. The campaign unfolds through a complex, mostly fileless six-stage process that begins with a deceptive first step.

Security experts at Cyderes, through their Howler Cell research unit, have identified this active campaign. The attackers use SEO poisoning to promote a fake Anthropic installation page, which executes harmful commands on the victim’s system.

Advanced Attack Techniques

Upon visiting the spoofed page, users are instructed to execute a pre-configured command via the Windows Run dialog, a tactic known as the ClickFix method. This method employs social engineering to disguise malicious commands as part of routine setup steps. The initial stage involves retrieving a polyglot payload that appears as an MP3 file, which security tools mistakenly identify as legitimate.

Subsequent stages utilize the HTA to create a scheduled task that runs a PowerShell process, specifically targeting 32-bit architecture to evade detection. The process includes AMSI bypasses and victim fingerprinting, leading to the download of an obfuscated script from a Russian server, leaving no trace on the victim’s device.

Fileless Infostealer Deployment

The final phase involves a reflective .NET infostealer that operates entirely within the PowerShell process, making it difficult for security systems to detect. This infostealer communicates with a command-and-control server to exfiltrate credentials. Security experts warn that any Claude Code install page requesting execution of commands should be treated with suspicion.

Blocking outbound HTTPS connections from mshta.exe and monitoring DNS queries to domains like *.oakenfjrod.ru can help detect and prevent these attacks. Such strategies are crucial in defending against this highly sophisticated and targeted campaign.

Indicators of Compromise

The following indicators of compromise (IoCs) have been identified: download.version-516[.]com for payload delivery, oakenfjrod[.]ru for command and control activities, and IP 185[.]177[.]239[.]255 as the final exfiltration point. Security teams are advised to incorporate these IoCs into their detection systems to mitigate potential breaches.

As cyber threats evolve, staying informed and implementing robust security measures are critical. Follow our updates on Google News, LinkedIn, and X for real-time information on emerging threats.

Cyber Security News Tags:AI tools, Anthropic, Claude Code, Cybersecurity, fileless malware, InfoStealer, PowerShell, SEO poisoning, social engineering, threat intelligence

Post navigation

Previous Post: Malicious Ads Deploy FlutterShell Backdoor on macOS
Next Post: Phishing Tactics Evolve: Infostealer Malware on the Rise

Related Posts

New Report on Commercial Spyware Vendors Detailing Their Targets and Infection Chains New Report on Commercial Spyware Vendors Detailing Their Targets and Infection Chains Cyber Security News
Critical WordPress Plugin Vulnerability Exposes 10K+ Sites to Cyber Attack Critical WordPress Plugin Vulnerability Exposes 10K+ Sites to Cyber Attack Cyber Security News
INE Earns Multiple G2 Winter 2026 Badges Across Global Markets INE Earns Multiple G2 Winter 2026 Badges Across Global Markets Cyber Security News
Axis Communications Vulnerability Exposes Azure Storage Account Credentials Axis Communications Vulnerability Exposes Azure Storage Account Credentials Cyber Security News
Handala Hack Targets US, Israel with Destructive Cyberattacks Handala Hack Targets US, Israel with Destructive Cyberattacks Cyber Security News
Windows Defender Zero-Day Exploit Unveiled by Researcher Windows Defender Zero-Day Exploit Unveiled by Researcher Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Exploit System Tools to Deploy Malware
  • New Malware Strikes npm with IronWorm and Miasma Variants
  • OWASP Project Enhances Security by Identifying Vulnerable Dependencies
  • Android Spyware Asin Targets Arabic Users via Fake Apps
  • Microsoft 365 Resolves Driver Auto-Update Bypass Issue

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Exploit System Tools to Deploy Malware
  • New Malware Strikes npm with IronWorm and Miasma Variants
  • OWASP Project Enhances Security by Identifying Vulnerable Dependencies
  • Android Spyware Asin Targets Arabic Users via Fake Apps
  • Microsoft 365 Resolves Driver Auto-Update Bypass Issue

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark