← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 8, 2026 · 05:00via The CyberWire

A little help from your search engine.

Brief

Today we are joined by ⁠Brian Hussey⁠, SVP of Howler Cell Threat Services at ⁠Cyderes⁠, discussing their work on "Bad Ads, Worse Binaries: Fake Claude Code Installer Drops Infostealer." Howler Cell identified an SEO poisoning campaign targeting people searching for Claude Code installation guides, using a fake Anthropic page and a ClickFix lure to trick victims into running a malicious MSHTA command.

The attack uses a six-stage, largely fileless chain that employs an MP3/HTA polyglot, PowerShell obfuscation, AMSI bypasses, per-victim infrastructure, and in-memory execution to evade detection. The final payload is a . NET infostealer that steals credentials, while Anthropic and the legitimate Claude Code installation process were not compromised.

Read more on The CyberWire