Skip to content
SEO poisoning campaign leverages Gemini and Claude Code impersonation to deliver infostealer

SEO poisoning campaign leverages Gemini and Claude Code impersonation to deliver infostealer

Blog.Eclecticiq • May 21, 2026

The Gemini CLI impersonation campaign was first publicly identified by independent threat researcher @g0njxa [1] , whose initial discovery enabled analysis and infrastructure pivoting documented in this report. The infection chain begins with a Google by a developer looking for the official Gemini CLI [2] or Claude Code [3] installation page. Threat actors use SEO poisoning to surface a fake domain at the top of results, above the legitimate source. The victim clicks through, lands on a malicious page visually consistent with a genuine vendor installation guide and is prompted to execute a single command to complete the install.

Figure 1 - Impersonation of Gemini CLI installation page.

In Gemini CLI impersonation campaign, victims were directed to fake installation page geminicli[.]co[.]com, which displays what appears to be a legitimate installation instruction. The page prompts the user to copy and paste a PowerShell command into their terminal but when executed, the command reaches out to gemini-setup[.]com to download the infostealer downloader payload (Install.ps1).

Figure 2 - Malicious instruction used to deliver infostealer downloader.

Once downloading is finished infostealer establishes a connection to command-and-control server hosted at events[.]msft23[.]com, it’s an infrastructure used to receive exfiltrated data from compromised hosts.

Figure 3 - C2 communication after the execution of the infostealer.

The same threat actor also, almost certainly, targeted users of Anthropic's Claude Code. This assessment is based on use of same malware family, structure of the command-and-control server and consistency in social engineering lure.

On March 30, 2026, threat actor registered two additional domains for Claude code impersonation, which were claudecode[.]co[.]com and claude-setup[.]com, both leveraging the identical naming patterns with the co[.]com suffix and the -setup[.]com convention. Threat actor used this domain name selection to appear legitimate against the victim users. Malicious domain claudecode[.]co[.]com was hosting a cloned installation page visually consistent with Anthropic's official documentation and presents the user with a PowerShell command to "install" the tool, while claude-setup[.]com hosts the final payload that was downloaded.

Figure 4 - Similarities of domain names between two AI platform impersonation campaigns.

After the execution, the infostealer malware sends exfiltrated data to events[.]ms709[.]com, which serves as the C2 server for Claude Code impersonation campaign. The attack chain mirrors behavior observed in the Gemini impersonation campaign, including the use of identical themed domain conventions to stage and deliver payloads. This behavioral overlap increases analyst confidence in the assessment that the same threat actor is responsible for both campaigns.

Malware analysis reveals the infection chain begins with a short first-stage PowerShell script embedded in the fake installation page, which performs two simultaneous actions rather than executing the payload directly:

Figure 5 - Downloader PowerShell script.

The real CLI completes while the stealer runs in parallel, appearing genuine to the user. By the time the npm install finishes and the user begins working with the tool, the infostealer has already completed its data collection and exfiltration cycle.

Once the second stage PowerShell payload is executed, it immediately moves to neutralize Microsoft Windows endpoint visibility by disabling two core defensive mechanisms:

Figure 6 - Final PowerShell infostealer disabling ETW.

After Microsoft Defender's telemetry collection is neutralized, the script operates in an effectively unmonitored environment. The malicious PowerShell script performs all of the collection, staging and exfiltration natively. It is heavily obfuscated with approximately 6,800 lines of junk code branches and includes a qemu-ga string check as a basic anti-sandbox gate designed to detect virtualized environments before proceeding.

To interact with the operating system at a level beyond what PowerShell cmdlets expose, the script loads three embedded C# types at runtime via Add-Type, each targeting a different aspect of host interrogation:

The stealer's collection scope reveals a deliberate focus on enterprise users and developer workstations. It iterates across all detected browser profiles, invoking dedicated routines for Chromium-family browsers, Chrome, Edge, and Brave and a separate handler for Firefox, extracting login credentials, session cookies, autofill data, and form history. Beyond browsers, the script directly targets collaboration and communication platforms that are standard in corporate environments:

For an attacker, a valid session cookie or Local State key from any of these platforms grants authenticated access to the victim's workspace, including internal channels, shared files, client communications, and connected integrations. This access bypasses password and MFA requirements entirely, making stolen session material a high-value commodity for immediate resale in underground markets. This is the data that feeds the access broker market and enables account takeover at scale.

Collection extends further into access tokens, cloud storage and sensitive user files. The script targets:

Data exfiltration from SSH keys and VPN configurations to cloud-synced documents, ensures that even a single compromised workstation yields credentials, session tokens, and files spanning both personal and corporate contexts. A full breakdown of all targeted software and data types is provided in Table 1, Software and Data Targeted by the Infostealer.

The infostealer sample also includes a command-and-control feature that allows the operator to run arbitrary follow-on payloads on infected hosts. But no persistence method is found in the PowerShell script.

Figure 7 – De-obfuscated C2 server and staging URL paths embedded in the PowerShell script.

The infostealer communicates with events.msft23[.]com over three URL endpoints:

The task dispatch flow works as follows:

EclecticIQ analysts used passive DNS records and pivoted from the claude-code.co[.]com domain, which is hosted at 109.107.170[.]111, an IP address assigned to the Netherlands-based bulletproof hosting provider MIRhosting [5] . This pivot revealed larger cluster of malicious infrastructure with more than 30 domains, exposing a highly likely coordinated campaign also designed to impersonate package manager Node.js and Chocolatey, open-source password manager KeePassXC, cryptocurrency Monero and other developer productivity tooling.

Figure 8 - Pivoted domains from AI impersonation campaign.

This impersonation campaign is likely geographically tailored to mostly target users in the United States and United Kingdom, as evidenced by the selection of .co.uk, .us.com and .us.org top-level domains in some of the attacker-controlled domains.

The inclusion of Monero lures indicates a multi-faceted objective, combining crypto theft with the compromise of developer environments. The rapid registration of these domains between late March and early April 2026 suggests highly likely an active campaign.

One example from this pivoted cluster is nodejs-setup.co[.]com, a domain impersonating the official Node.js installation page. Rather than delivering a legitimate Node.js installer, the page instructs the visitor to execute the following PowerShell command:

Figure 9 - Impersonation of Node.js package manager.

The lure using a fake Node.js installation page, deliberately invoking Chocolatey as the installation method which is a calculated choice, as legitimate Node.js installations genuinely support Chocolatey-based setup. The one-liner PowerShell script references community.chocolatey[.]net, a domain impersonating Chocolatey's official infrastructure, stacking two spoofed domains into a single, social-engineering flow that closely mirrors authentic developer workflows.

The technique is tailored to the habits of developers and IT administrators, who routinely paste one-line PowerShell installers from package manager websites without close inspection. The execution chain ultimately delivers the same fileless PowerShell infostealer documented earlier in this report, with the only meaningful change being a rotation of the command-and-control endpoint from events.msft23[.]com to events.ms709[.]com.

Both C2 domains follow the same structural pattern, an "events." subdomain paired with a short, brand-adjacent root that loosely evokes Microsoft, indicating that the operator is reusing a single tooling and infrastructure template and rotating only the lure brand and C2 hostname while keeping the underlying implant and naming logic intact.

Across this campaign, the threat actor shows an understanding of developer behavior and exploits the current hype of AI coding platforms. These attack patterns are highly likely targets the developers and IT administrators. By impersonating brands embedded in routine developer workflows, including Node.js, Chocolatey, and KeePassXC, the actor weaponized familiar installation patterns to deliver infostealer malware. This approach target trust in developer tooling, turning routine software adoption into an initial access vector.

This targeting approach will very likely persist and expand over the coming months, as developers typically hold elevated privileges across enterprise networks, source code repositories, and software supply chains. Financially motivated eCrime actors will highly likely continue prioritizing developer-focused campaigns, as a single compromised developer endpoint can yield disproportionate access and enable high-impact intrusions against the wider enterprise environment.

Detection opportunities

Prevention opportunities

Attacker controlled domains:

api[.]bio9438[.]com claude code-install[.]co[.]com openclow[.]co[.]com geninicli[.]co[.]com keepassxc[.]us[.]org claude-code[.]co[.]com chocolatey[.]net claudecode[.]co[.]com chocolatey-setup[.]co[.]com get-monero[.]co[.]uk getmonero[.]us[.]com metrics[.]msft17[.]com claude-setup[.]com keepassxc[.]us[.]com olive3451[.]com events[.]ms709[.]com chocolatey-download[.]co[.]com chocolatey[.]co[.]com

Targeted Software / Data

Google Chrome, Microsoft Edge, Brave

Login Data, Cookies, Web Data, autofill, form history per user profile

cookies.sqlite, formhistory.sqlite, logins.json, sessionstore.jsonlz4 per profile

Collaboration — Messaging

Local State key extraction, Network cookies

Collaboration — Messaging

EBWebView Local State + per-partition Network cookies (DPAPI-protected)

Collaboration — Messaging

Local Storage LevelDB files + Local State

Collaboration — Messaging

Cookies + Local State

Collaboration — Messaging

tdata session directory from Desktop, Documents, and Downloads

Collaboration — Video

DPAPI-protected win_osencrypt_key from Zoom.us.ini

Collaboration — Support

Partitioned Network cookies

Per-partition cookies + Local State

Stored session passwords from registry (HKCU:\SOFTWARE\Martin Prikryl\WinSCP 2\)

Saved session configurations from registry (HKCU:\Software\SimonTatham\PuTTY\Sessions)

Config files with embedded key material + DPAPI-protected GUI login data

Wallet preferences and data

Proton Drive, iCloud Drive, Google Drive, MEGA, OneDrive

Enumeration of locally synced file directories

Installation path data and configuration files

CredEnumerate via P/Invoke (advapi32.dll) — all stored credentials including RDP, web, and enterprise app entries

Desktop, Documents, Downloads

Recursive enumeration of .txt and .docx files

System Reconnaissance

OS, software, display, network, processes, wallpaper

EnumDisplaySettings, Restart Manager API, WMI queries, TranscodedWallpaper capture

Stored session passwords from registry (HKCU:\SOFTWARE\Martin Prikryl\WinSCP 2\)

Saved session configurations from registry (HKCU:\Software\SimonTatham\PuTTY\Sessions)

Config files with embedded key material + DPAPI-protected GUI login data

Wallet preferences and data

Proton Drive, iCloud Drive, Google Drive, MEGA, OneDrive

Enumeration of locally synced file directories

Installation path data and configuration files

CredEnumerate via P/Invoke (advapi32.dll) — all stored credentials including RDP, web, and enterprise app entries

Desktop, Documents, Downloads

Recursive enumeration of .txt and .docx files

System Reconnaissance

OS, software, display, network, processes, wallpaper

EnumDisplaySettings, Restart Manager API, WMI queries, TranscodedWallpaper capture

Victims directed to attacker-controlled sites via SEO-poisoned results

Stage Capabilities: SEO Poisoning

Malicious domains above legitimate vendor sites in Google results

Command and Scripting Interpreter: PowerShell

First- and second-stage payloads executed in memory via PowerShell

User Execution: Malicious Link

User clicks SEO-poisoned result

User Execution: Malicious File

User pastes one-liner PowerShell command into terminal (irm | iex pattern)

Obfuscated Files or Information

Approximately 6,800 lines of junk code branches in second-stage script

Deobfuscate/Decode Files or Information

RSA-encrypted task list decrypted at runtime

Impair Defenses: Disable or Modify Tools

AMSI bypass via in-memory patching of amsi.dll

Impair Defenses: Indicator Blocking

ETW disabled by patching PSEtwLogProvider.m_enabled flag

Virtualization/Sandbox Evasion: System Checks

qemu-ga string check as anti-sandbox gate

System Binary Proxy Execution

Shell.Application.ShellExecute used to launch hidden PowerShell window

Restart Manager API used to enumerate processes (avoids Get-Process cmdlet)

File and Directory Discovery

Recursive enumeration of .txt and .docx files in user directories

Credentials from Web Browsers

Chrome, Edge, Brave, Firefox login data, cookies, autofill extracted

Credentials from Windows Credential Manager

CredEnumerate via advapi32.dll P/Invoke

Steal Web Session Cookie

Slack, Teams, Discord, Mattermost session cookies harvested

Unsecured Credentials: Credentials In Files

OpenVPN configs, embedded key material, Zoom encryption keys

Unsecured Credentials: Credentials in Registry

PuTTY and WinSCP saved sessions extracted from HKCU registry hives

Data from Local System

Cloud-synced directories (Proton Drive, iCloud, Google Drive, OneDrive) enumerated

Application Layer Protocol: Web Protocols

HTTPS C2 to events.msft23[.]com and events.ms709[.]com (/take, /process, /validate)

RSA-encrypted task list returned in C2 response

Ingress Tool Transfer

Operator-supplied URLs fetched and executed via IEX(Invoke-WebRequest)

Exfiltration Over C2 Channel

Stolen credentials and files exfiltrated to /process endpoint in encrypted form

[1] Who said what? [@g0njxa], “Related Windows malware campaign new deployments impersonating Google’s Gemini CLI tool 🤖👾 Detonation: geminicli[.]co[.]com >> gemini-setup[.]com Prompting user to execute a malicious Powershell script hosted at the fake gemini website Twitter. Accessed: Apr. 28, 2026. [Online]. Available:

[2] “Build, debug & deploy with AI,” Gemini CLI. Accessed: Apr. 28, 2026. [Online]. Available:

[3] “Claude Code | Anthropic’s agentic coding system.” Accessed: Apr. 28, 2026. [Online]. Available:

[4] “pinvoke.net: credwrite (advapi32).” Accessed: Apr. 28, 2026. [Online]. Available:

[5] “Bulletproof Host Stark Industries Evades EU Sanctions – Krebs on Security.” Accessed: Apr. 28, 2026. [Online]. Available: