Back Blog.Eclecticiq SEO poisoning campaign leverages Gemini and Claude Code impersonation to deliver infostealer
The Gemini CLI impersonation campaign was first publicly identified by independent threat researcher @g0njxa [1] , whose initial discovery enabled analysis and infrastructure pivoting documented in this report. The infection chain begins with a Google by a developer looking for the official Gemini CLI [2] or Claude Code [3] installation page. Threat actors use SEO poisoning to surface a fake domain at the top of results, above the legitimate source. The victim clicks through, lands on a malicious page visually consistent with a genuine vendor installation guide and is prompted to execute a single command to complete the install.
Figure 1 - Impersonation of Gemini CLI installation page.
In Gemini CLI impersonation campaign, victims were directed to fake installation page geminicli[.]co[.]com, which displays what appears to be a legitimate installation instruction. The page prompts the user to copy and paste a PowerShell command into their terminal but when executed, the command reaches out to gemini-setup[.]com to download the infostealer downloader payload (Install.ps1).
Figure 2 - Malicious instruction used to deliver infostealer downloader.
Once downloading is finished infostealer establishes a connection to command-and-control server hosted at events[.]msft23[.]com, it’s an infrastructure used to receive exfiltrated data from compromised hosts.
Figure 3 - C2 communication after the execution of the infostealer.
The same threat actor also, almost certainly, targeted users of Anthropic's Claude Code. This assessment is based on use of same malware family, structure of the command-and-control server and consistency in social engineering lure.
On March 30, 2026, threat actor registered two additional domains for Claude code impersonation, which were claudecode[.]co[.]com and claude-setup[.]com, both leveraging the identical naming patterns with the co[.]com suffix and the -setup[.]com convention. Threat actor used this domain name selection to appear legitimate against the victim users. Malicious domain claudecode[.]co[.]com was hosting a cloned installation page visually consistent with Anthropic's official documentation and presents the user with a PowerShell command to "install" the tool, while claude-setup[.]com hosts the final payload that was downloaded.
Figure 4 - Similarities of domain names between two AI platform impersonation campaigns.
After the execution, the infostealer malware sends exfiltrated data to events[.]ms709[.]com, which serves as the C2 server for Claude Code impersonation campaign. The attack chain mirrors behavior observed in the Gemini impersonation campaign, including the use of identical themed domain conventions to stage and deliver payloads. This behavioral overlap increases analyst confidence in the assessment that the same threat actor is responsible for both campaigns.
Malware analysis reveals the infection chain begins with a short first-stage PowerShell script embedded in the fake installation page, which performs two simultaneous actions rather than executing the payload directly:
Figure 5 - Downloader PowerShell script.
The real CLI completes while the stealer runs in parallel, appearing genuine to the user. By the time the npm install finishes and the user begins working with the tool, the infostealer has already completed its data collection and exfiltration cycle.
Once the second stage PowerShell payload is executed, it immediately moves to neutralize Microsoft Windows endpoint visibility by disabling two core defensive mechanisms:
Figure 6 - Final PowerShell infostealer disabling ETW.
After Microsoft Defender's telemetry collection is neutralized, the script operates in an effectively unmonitored environment. The malicious PowerShell script performs all of the collection, staging and exfiltration natively. It is heavily obfuscated with approximately 6,800 lines of junk code branches and includes a qemu-ga string check as a basic anti-sandbox gate designed to detect virtualized environments before proceeding.
To interact with the operating system at a level beyond what PowerShell cmdlets expose, the script loads three embedded C# types at runtime via Add-Type, each targeting a different aspect of host interrogation:
The stealer's collection scope reveals a deliberate focus on enterprise users and developer workstations. It iterates across all detected browser profiles, invoking dedicated routines for Chromium-family browsers, Chrome, Edge, and Brave and a separate handler for Firefox, extracting login credentials, session cookies, autofill data, and form history. Beyond browsers, the script directly targets collaboration and communication platforms that are standard in corporate environments:
For an attacker, a valid session cookie or Local State key from any of these platforms grants authenticated access to the victim's workspace, including internal channels, shared files, client communications, and connected integrations. This access bypasses password and MFA requirements entirely, making stolen session material a high-value commodity for immediate resale in underground markets. This is the data that feeds the access broker market and enables account takeover at scale.
Collection extends further into access tokens, cloud storage and sensitive user files. The script targets:
Data exfiltration from SSH keys and VPN configurations to cloud-synced documents, ensures that even a single compromised workstation yields credentials, session tokens, and files spanning both personal and corporate contexts. A full breakdown of all targeted software and data types is provided in Table 1, Software and Data Targeted by the Infostealer.
The infostealer sample also includes a command-and-control feature that allows the operator to run arbitrary follow-on payloads on infected hosts. But no persistence method is found in the PowerShell script.
Figure 7 – De-obfuscated C2 server and staging URL paths embedded in the PowerShell script.
The infostealer communicates with events.msft23[.]com over three URL endpoints:
The task dispatch flow works as follows:
EclecticIQ analysts used passive DNS records and pivoted from the claude-code.co[.]com domain, which is hosted at 109.107.170[.]111, an IP address assigned to the Netherlands-based bulletproof hosting provider MIRhosting [5] . This pivot revealed larger cluster of malicious infrastructure with more than 30 domains, exposing a highly likely coordinated campaign also designed to impersonate package manager Node.js and Chocolatey, open-source password manager KeePassXC, cryptocurrency Monero and other developer productivity tooling.
Figure 8 - Pivoted domains from AI impersonation campaign.
This impersonation campaign is likely geographically tailored to mostly target users in the United States and United Kingdom, as evidenced by the selection of .co.uk, .us.com and .us.org top-level domains in some of the attacker-controlled domains.
The inclusion of Monero lures indicates a multi-faceted objective, combining crypto theft with the compromise of developer environments. The rapid registration of these domains between late March and early April 2026 suggests highly likely an active campaign.
One example from this pivoted cluster is nodejs-setup.co[.]com, a domain impersonating the official Node.js installation page. Rather than delivering a legitimate Node.js installer, the page instructs the visitor to execute the following PowerShell command:
Figure 9 - Impersonation of Node.js package manager.
The lure using a fake Node.js installation page, deliberately invoking Chocolatey as the installation method which is a calculated choice, as legitimate Node.js installations genuinely support Chocolatey-based setup. The one-liner PowerShell script references community.chocolatey[.]net, a domain impersonating Chocolatey's official infrastructure, stacking two spoofed domains into a single, social-engineering flow that closely mirrors authentic developer workflows.
The technique is tailored to the habits of developers and IT administrators, who routinely paste one-line PowerShell installers from package manager websites without close inspection. The execution chain ultimately delivers the same fileless PowerShell infostealer documented earlier in this report, with the only meaningful change being a rotation of the command-and-control endpoint from events.msft23[.]com to events.ms709[.]com.
Both C2 domains follow the same structural pattern, an "events." subdomain paired with a short, brand-adjacent root that loosely evokes Microsoft, indicating that the operator is reusing a single tooling and infrastructure template and rotating only the lure brand and C2 hostname while keeping the underlying implant and naming logic intact.
Across this campaign, the threat actor shows an understanding of developer behavior and exploits the current hype of AI coding platforms. These attack patterns are highly likely targets the developers and IT administrators. By impersonating brands embedded in routine developer workflows, including Node.js, Chocolatey, and KeePassXC, the actor weaponized familiar installation patterns to deliver infostealer malware. This approach target trust in developer tooling, turning routine software adoption into an initial access vector.
This targeting approach will very likely persist and expand over the coming months, as developers typically hold elevated privileges across enterprise networks, source code repositories, and software supply chains. Financially motivated eCrime actors will highly likely continue prioritizing developer-focused campaigns, as a single compromised developer endpoint can yield disproportionate access and enable high-impact intrusions against the wider enterprise environment.
Detection opportunities
Prevention opportunities
Attacker controlled domains:
api[.]bio9438[.]com claude code-install[.]co[.]com openclow[.]co[.]com geninicli[.]co[.]com keepassxc[.]us[.]org claude-code[.]co[.]com chocolatey[.]net claudecode[.]co[.]com chocolatey-setup[.]co[.]com get-monero[.]co[.]uk getmonero[.]us[.]com metrics[.]msft17[.]com claude-setup[.]com keepassxc[.]us[.]com olive3451[.]com events[.]ms709[.]com chocolatey-download[.]co[.]com chocolatey[.]co[.]com
Targeted Software / Data
Google Chrome, Microsoft Edge, Brave
Login Data, Cookies, Web Data, autofill, form history per user profile
cookies.sqlite, formhistory.sqlite, logins.json, sessionstore.jsonlz4 per profile
Collaboration — Messaging
Local State key extraction, Network cookies
Collaboration — Messaging
EBWebView Local State + per-partition Network cookies (DPAPI-protected)
Collaboration — Messaging
Local Storage LevelDB files + Local State
Collaboration — Messaging
Cookies + Local State
Collaboration — Messaging
tdata session directory from Desktop, Documents, and Downloads
Collaboration — Video
DPAPI-protected win_osencrypt_key from Zoom.us.ini
Collaboration — Support
Partitioned Network cookies
Per-partition cookies + Local State
Stored session passwords from registry (HKCU:\SOFTWARE\Martin Prikryl\WinSCP 2\)
Saved session configurations from registry (HKCU:\Software\SimonTatham\PuTTY\Sessions)
Config files with embedded key material + DPAPI-protected GUI login data
Wallet preferences and data
Proton Drive, iCloud Drive, Google Drive, MEGA, OneDrive
Enumeration of locally synced file directories
Installation path data and configuration files
CredEnumerate via P/Invoke (advapi32.dll) — all stored credentials including RDP, web, and enterprise app entries
Desktop, Documents, Downloads
Recursive enumeration of .txt and .docx files
System Reconnaissance
OS, software, display, network, processes, wallpaper
EnumDisplaySettings, Restart Manager API, WMI queries, TranscodedWallpaper capture
Stored session passwords from registry (HKCU:\SOFTWARE\Martin Prikryl\WinSCP 2\)
Saved session configurations from registry (HKCU:\Software\SimonTatham\PuTTY\Sessions)
Config files with embedded key material + DPAPI-protected GUI login data
Wallet preferences and data
Proton Drive, iCloud Drive, Google Drive, MEGA, OneDrive
Enumeration of locally synced file directories
Installation path data and configuration files
CredEnumerate via P/Invoke (advapi32.dll) — all stored credentials including RDP, web, and enterprise app entries
Desktop, Documents, Downloads
Recursive enumeration of .txt and .docx files
System Reconnaissance
OS, software, display, network, processes, wallpaper
EnumDisplaySettings, Restart Manager API, WMI queries, TranscodedWallpaper capture
Victims directed to attacker-controlled sites via SEO-poisoned results
Stage Capabilities: SEO Poisoning
Malicious domains above legitimate vendor sites in Google results
Command and Scripting Interpreter: PowerShell
First- and second-stage payloads executed in memory via PowerShell
User Execution: Malicious Link
User clicks SEO-poisoned result
User Execution: Malicious File
User pastes one-liner PowerShell command into terminal (irm | iex pattern)
Obfuscated Files or Information
Approximately 6,800 lines of junk code branches in second-stage script
Deobfuscate/Decode Files or Information
RSA-encrypted task list decrypted at runtime
Impair Defenses: Disable or Modify Tools
AMSI bypass via in-memory patching of amsi.dll
Impair Defenses: Indicator Blocking
ETW disabled by patching PSEtwLogProvider.m_enabled flag
Virtualization/Sandbox Evasion: System Checks
qemu-ga string check as anti-sandbox gate
System Binary Proxy Execution
Shell.Application.ShellExecute used to launch hidden PowerShell window
Restart Manager API used to enumerate processes (avoids Get-Process cmdlet)
File and Directory Discovery
Recursive enumeration of .txt and .docx files in user directories
Credentials from Web Browsers
Chrome, Edge, Brave, Firefox login data, cookies, autofill extracted
Credentials from Windows Credential Manager
CredEnumerate via advapi32.dll P/Invoke
Steal Web Session Cookie
Slack, Teams, Discord, Mattermost session cookies harvested
Unsecured Credentials: Credentials In Files
OpenVPN configs, embedded key material, Zoom encryption keys
Unsecured Credentials: Credentials in Registry
PuTTY and WinSCP saved sessions extracted from HKCU registry hives
Data from Local System
Cloud-synced directories (Proton Drive, iCloud, Google Drive, OneDrive) enumerated
Application Layer Protocol: Web Protocols
HTTPS C2 to events.msft23[.]com and events.ms709[.]com (/take, /process, /validate)
RSA-encrypted task list returned in C2 response
Ingress Tool Transfer
Operator-supplied URLs fetched and executed via IEX(Invoke-WebRequest)
Exfiltration Over C2 Channel
Stolen credentials and files exfiltrated to /process endpoint in encrypted form
[1] Who said what? [@g0njxa], “Related Windows malware campaign new deployments impersonating Google’s Gemini CLI tool 🤖👾 Detonation: geminicli[.]co[.]com >> gemini-setup[.]com Prompting user to execute a malicious Powershell script hosted at the fake gemini website Twitter. Accessed: Apr. 28, 2026. [Online]. Available:
[2] “Build, debug & deploy with AI,” Gemini CLI. Accessed: Apr. 28, 2026. [Online]. Available:
[3] “Claude Code | Anthropic’s agentic coding system.” Accessed: Apr. 28, 2026. [Online]. Available:
[4] “pinvoke.net: credwrite (advapi32).” Accessed: Apr. 28, 2026. [Online]. Available:
[5] “Bulletproof Host Stark Industries Evades EU Sanctions – Krebs on Security.” Accessed: Apr. 28, 2026. [Online]. Available:
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
