Find notable cyber news and cases, enriched with sources, timelines, and signals.

InstallFix Claude Code malvertising campaign

Campaign
First reported
Last updated
Happening score
H score 32
1 unique sources, 1 articles

Summary

Hide ▲

InstallFix is being used in an active malvertising operation that pushes cloned Claude Code install pages and malicious CLI instructions, putting users who search for installation help at risk of malware delivery and credential theft. The campaign matters because the lure is designed to look legitimate while redirecting victims through promoted search results and fake documentation. It targets a specific developer-oriented query set, making the operation both focused and scalable.

Related Happenings

Silver Fox counterfeit-installer SEO-poisoning campaign across Asia

Campaign
H score32 First: 10.07.2026 16:15 Last: 10.07.2026 16:15 Sources 1

About this happening: Silver Fox is running a counterfeit-installer SEO-poisoning campaign that delivers malware across Asia and puts technology, education, and state-owned enterprise...

ChatGPT and Claude phishing and malvertising campaign

Campaign
H score36 First: 01.06.2026 12:30 Last: 01.06.2026 12:30 Sources 1

About this happening: The ChatGPT- and Claude-themed phishing and malvertising campaign is actively steering users to fake download pages that can deliver malware. Attackers are using Goo...

Fake Claude Code installation-page infostealer campaign targeting developers

Campaign
H score33 First: 11.05.2026 17:00 Last: 11.05.2026 17:00 Sources 1

About this happening: A fake Claude Code installer campaign is using sponsored search results and operator-controlled domains to deliver an infostealer to developer workstations, pu...

Fake Claude PlugX phishing campaign

Campaign
H score34 First: 13.04.2026 12:52 Last: 13.04.2026 12:52 Sources 1

About this happening: A February phishing campaign used a fake Claude website and fake meeting invitations to deliver PlugX malware to recipients, turning a popular AI brand into a malw...

Latest development: 07.05.2026 13:02

A fake Claude AI site at claude-pro[.]com distributed Claude-Pro-windows-x64.zip, which drops NOVupdate.exe, NOVupdate.exe.dat, and avk.dll to sideload DonutLoader and load the Beagle backdoor on Windows. The backdoor uses license[.]claude-pro[.]com for command-and-control over TCP 443 and/or UDP 8080, and related Beagle samples were submitted to VirusTotal between February and April this year.

Claude Code leak GitHub Vidar lure campaign

Campaign
H score32 First: 02.04.2026 23:30 Last: 02.04.2026 23:30 Sources 1

About this happening: A malicious GitHub repository campaign is abusing the Claude Code leak to deliver Vidar to users searching for leaked code. The lure uses a fake leak, search-eng...

Timeline

  1. 06.03.2026 17:00 2 articles · 4mo ago

    InstallFix malvertising against Claude Code

    Initial Disclosure

    Threat actors used InstallFix, a new ClickFix variation, to push cloned Claude Code installation pages through Google Ads malvertising and lure users into running malicious CLI install commands that retrieve payloads from attacker-controlled endpoints, including a chain that launches mshta.exe and delivers the Amatera info-stealer. The fake pages mirrored legitimate layout and documentation while redirecting only the install instructions to malicious infrastructure, and the activity also appeared on legitimate hosting platforms such as Cloudflare Pages, Squarespace, and Tencent EdgeOne.

    Show sources