{"id":11150,"date":"2026-03-06T10:04:02","date_gmt":"2026-03-06T10:04:02","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/03\/06\/threat-actors-using-fake-claude-code-download-to-deploy-infostealer\/"},"modified":"2026-03-06T10:04:02","modified_gmt":"2026-03-06T10:04:02","slug":"threat-actors-using-fake-claude-code-download-to-deploy-infostealer","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/03\/06\/threat-actors-using-fake-claude-code-download-to-deploy-infostealer\/","title":{"rendered":"Threat Actors Using Fake Claude Code Download to Deploy Infostealer"},"content":{"rendered":"<p>    Threat Actors Using Fake Claude Code Download to Deploy Infostealer<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Cybercriminals have found a new way to target developers and IT professionals by setting up fake download pages that impersonate Claude Code, a legitimate AI coding assistant. <\/p>\n<p>These deceptive pages trick users into downloading what appears to be an official installation package, but instead silently deploy an infostealer malware onto the victim\u2019s system. <\/p>\n<p>The use of a well-known AI tool as bait reflects a growing trend where threat actors exploit the popularity of artificial intelligence platforms to gain trust and bypass suspicion.\u200b<\/p>\n<p>The attack was first observed through a distribution campaign using it<math><semantics><mrow><mi mathvariant=\"normal\">.<\/mi><\/mrow><\/semantics><\/math>.com as the delivery domain. <\/p>\n<p>Victims are lured to these sites, which are carefully designed to mimic the look and feel of legitimate software download portals. <\/p>\n<p>Once a user clicks the download button, they are not getting any real software \u2014 instead, the site triggers a malicious execution chain that begins the moment the file is opened. <\/p>\n<p>The convincing design of these fake pages gives users very little reason to question the file\u2019s authenticity before it is too late.\u200b<\/p>\n<p>Cybersecurity analyst <a href=\"https:\/\/www.linkedin.com\/posts\/mauricefielenbach_threathunting-cyberdefense-blueteam-activity-7433214415958843392-qEv0\/?utm_source=social_share_send&amp;utm_medium=member_desktop_web&amp;rcm=ACoAABO-jCkB1he5ufTfbYYMNKmaojg8M31OVpM\" id=\"https:\/\/www.linkedin.com\/posts\/mauricefielenbach_threathunting-cyberdefense-blueteam-activity-7433214415958843392-qEv0\/?utm_source=social_share_send&amp;utm_medium=member_desktop_web&amp;rcm=ACoAABO-jCkB1he5ufTfbYYMNKmaojg8M31OVpM\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Maurice Fielenbach noted the campaign<\/a> and highlighted that the attack ends in a straightforward MSHTA-based infostealer. <\/p>\n<p>He pointed out that mshta.exe, a legitimate Microsoft Windows binary, remains one of the most important processes for defenders to monitor, as it is frequently abused by attackers to run malicious HTML Application (HTA) files fetched directly from remote sources. <\/p>\n<p>Fielenbach also stressed that monitoring HTA execution from remote sources is a high-signal indicator of real attacker activity.<a href=\"https:\/\/www.ontinue.com\/resource\/obfuscated-powershell-leads-to-lumma-c2-stealer\/\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a>\u200b\u200b<\/p>\n<p>The broader context of this campaign fits into a well-documented pattern where threat actors weaponize the growing trust people place in AI tools. <\/p>\n<p>As AI-assisted <a href=\"https:\/\/cybersecuritynews.com\/c-development-and-secure-coding-strengthening-cyber-defenses\/\" id=\"56587\" target=\"_blank\" rel=\"noreferrer noopener\">coding platforms<\/a> see wider adoption across developer communities, criminals find a larger pool of potential victims who may be less cautious when downloading what appears to be a legitimate productivity tool. <\/p>\n<p>This is not the first time Claude-themed lures have been used \u2014 earlier campaigns exploited AI branding the same way, showing that this trend is far from isolated.<\/p>\n<p>The impact of this infostealer can be severe for any affected user. Once the malware runs on a victim\u2019s machine, it is capable of harvesting browser-stored credentials, session tokens, and other sensitive data before sending it to attacker-controlled infrastructure. <\/p>\n<p>For developers who are the primary targets, the consequences extend well beyond personal data loss \u2014 compromised credentials can open doors to code repositories, cloud environments, and internal systems, potentially triggering much broader organizational security incidents.<a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/claude-llm-artifacts-abused-to-push-mac-infostealers-in-clickfix-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a>\u200b<\/p>\n<h2 class=\"wp-block-heading\" id=\"mshta-based-execution-and-lolbin-abuse\"><strong>MSHTA-Based Execution and LOLBin Abuse<\/strong><\/h2>\n<p>The infection mechanism in this campaign centers on the abuse of mshta.exe, a signed Microsoft binary that is part of the core Windows operating system. <\/p>\n<p>Since it is a trusted, system-native tool, many security products do not flag its activity by default, making it a low-profile vehicle for attackers. <\/p>\n<p>This technique is known as Living off the Land and is cataloged under MITRE ATT&amp;CK as T1218.005, which allows malware to execute without dropping a traditional executable file to disk, significantly reducing its overall detection footprint.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjuAzMmEFIpOETycxfBEtGUt82N2yu_4g-ZzLvxNZwztjneXr-Sm8MBugSvsmbwkqfprLcoqhhQHxDi-X7RjHjpfPgZeFZWE8R6lv6kSgOFmhz5gGvV4jO9z02gA5ANcDykU9AoMJay16hSuCcQxxLlvwlcrxSc_CjUj7wQEM9rX3YxPtjAXetYzd81ZmI\/s16000\/Screenshot%2520of%2520the%2520fake%2520Claude%2520Code%2520download%2520page%2520used%2520to%2520lure%2520victims%2520into%2520triggering%2520the%2520MSHTA-based%2520infostealer%2520execution%2520chain%2520%28Source%2520-%2520Linkedin%29.webp?ssl=1\" alt=\"Screenshot of the fake Claude Code download page used to lure victims into triggering the MSHTA-based infostealer execution chain (Source - Linkedin)\"><figcaption class=\"wp-element-caption\">Screenshot of the fake Claude Code download page used to lure victims into triggering the MSHTA-based infostealer execution chain (Source \u2013 Linkedin)<\/figcaption><\/figure>\n<\/div>\n<p>When a victim interacts with the fake download page, mshta.exe is invoked to fetch and run a remote HTA file that contains embedded malicious script. <\/p>\n<p>This script carries out the <a href=\"https:\/\/cybersecuritynews.com\/clickfix-infostealer-campaign\/\" id=\"143519\" target=\"_blank\" rel=\"noreferrer noopener\">infostealer\u2019s core functions<\/a> \u2014 collecting credentials, browser data, and other sensitive information \u2014 entirely within memory. <\/p>\n<p>The use of remote HTA execution means the payload never physically lands on the system as a standalone file, making forensic recovery considerably more difficult for incident responders after an attack.<\/p>\n<p>Security teams are strongly advised to enable detailed logging for mshta.exe activity across <a href=\"https:\/\/cybersecuritynews.com\/securing-remote-endpoints\/\" id=\"107366\" target=\"_blank\" rel=\"noreferrer noopener\">all endpoints<\/a> and flag any instance where it connects to external URLs. <\/p>\n<p>Organizations should also consider restricting mshta.exe execution through application control policies where their operational requirements allow it. <\/p>\n<p>Users should always verify software downloads from official vendor sources and avoid downloading tools from third-party or unfamiliar websites, regardless of how genuine the page may appear.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/threat-actors-using-fake-claude-code\/\">Threat Actors Using Fake Claude Code Download to Deploy Infostealer<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/threat-actors-using-fake-claude-code\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Threat Actors Using Fake Claude Code Download to Deploy Infostealer Cybercriminals have found a new way to target developers and IT professionals by setting up fake download pages that impersonate Claude Code, a legitimate AI coding assistant. These deceptive pages trick users into downloading what appears to be an official installation package, but instead silently [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-11150","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11150"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11150"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11150\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11150"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11150"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11150"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}