Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malicious Code Stealer Deployed via Google Sites

Malicious Code Stealer Deployed via Google Sites

Posted on June 4, 2026 By CWS

Cybercriminals are leveraging trusted platforms to execute sophisticated attacks, with recent campaigns targeting the popularity of AI developer tools. Malicious actors have been using fake pages on Google Sites, which imitate Claude Code and OpenAI Codex, to trick users into executing commands that result in credential theft and data breaches.

Exploiting Trusted Platforms

In a crafty ploy, attackers employ a technique called ClickFix to present a seemingly credible setup page, urging victims to run a command. This malicious activity runs entirely in memory, bypassing traditional security detections that rely on file-based scanning. As reported by analysts from ANY.RUN, these campaigns impersonate popular AI tools to lower detection rates.

By masquerading as legitimate tools, these operations exploit the credibility of Google Sites, making users more likely to follow deceptive instructions. This strategic use of trusted domains poses significant challenges for the early detection of malicious activities.

Technical Disguise and Data Exfiltration

The ClickFix strategy involves directing victims to Google Sites pages that appear to provide genuine software installation guidance for AI tools like Codex and Claude Code. Victims are instructed to execute an mshta command, initiating a PowerShell sequence that conceals its payload within an image file using steganography. This process ensures that no files are written to disk, complicating detection by antivirus programs.

The attack rapidly progresses as the Google Sites lure leads to the execution of mshta, which triggers PowerShell to extract hidden data from an image. The resulting shellcode runs in memory, exfiltrating sensitive information such as browser passwords, email credentials, and cryptocurrency wallet data to attacker-controlled servers.

Defense Measures and Recommendations

To mitigate these threats, it is crucial for users to scrutinize any webpage prompting command execution, even if it appears legitimate. Verifying installation instructions through official sources or GitHub repositories is recommended. Organizations should employ endpoint detection solutions capable of behavioral analysis to identify suspicious activities, such as unusual PowerShell traffic.

Security experts advise caution in following instructions from unfamiliar websites and emphasize the need for robust monitoring tools that can detect in-memory attacks. By understanding the tactics used in these campaigns, individuals and businesses can better protect themselves from such sophisticated cyber threats.

As cybercriminals continue to refine their methods, awareness and preparedness remain key components in defending against these innovative exploits. Stay informed by following updates from reliable cybersecurity sources.

Cyber Security News Tags:AI tools, ANY.RUN, Claude Code, ClickFix, Codex, credential theft, cyber threats, Cybersecurity, endpoint detection, Google Sites, in-memory attack, Malware, PowerShell, security tools, Steganography

Post navigation

Previous Post: DoJ Cracks Down on SE Asia Crypto Scams, $3.8M Frozen
Next Post: Critical Magento RCE Flaw Added to CISA Vulnerability List

Related Posts

Silver Fox Hackers Attacking Indian Entities with Income Tax Phishing Lures Silver Fox Hackers Attacking Indian Entities with Income Tax Phishing Lures Cyber Security News
Operation Silk Lure Weaponizing Windows Scheduled Tasks to Drop ValleyRAT Operation Silk Lure Weaponizing Windows Scheduled Tasks to Drop ValleyRAT Cyber Security News
Google Sues ‘Lighthouse’ Phishing-as-a-service Kit Behind Massive Phishing Attacks Google Sues ‘Lighthouse’ Phishing-as-a-service Kit Behind Massive Phishing Attacks Cyber Security News
List of AI Tools Promoted by Threat Actors in Underground Forums and Their Capabilities List of AI Tools Promoted by Threat Actors in Underground Forums and Their Capabilities Cyber Security News
Role of Threat Intelligence in Proactive Defense Strategies Role of Threat Intelligence in Proactive Defense Strategies Cyber Security News
Critical Sophos Firewall Vulnerabilities Enables pre-auth Remote Code Execution Critical Sophos Firewall Vulnerabilities Enables pre-auth Remote Code Execution Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cisco Alerts on PoC for Critical Unified CM Flaw
  • Critical VS Code Flaw Enables GitHub Token Theft
  • Critical Magento RCE Flaw Added to CISA Vulnerability List
  • Malicious Code Stealer Deployed via Google Sites
  • DoJ Cracks Down on SE Asia Crypto Scams, $3.8M Frozen

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cisco Alerts on PoC for Critical Unified CM Flaw
  • Critical VS Code Flaw Enables GitHub Token Theft
  • Critical Magento RCE Flaw Added to CISA Vulnerability List
  • Malicious Code Stealer Deployed via Google Sites
  • DoJ Cracks Down on SE Asia Crypto Scams, $3.8M Frozen

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark