Malwarebytes Phishing Scam Exploits Claude Max Giveaway to Steal Google Credentials
Article Content
- •The phishing scam offers fake Claude Max subscriptions to lure victims.
- •It uses a convincing browser-in-the-browser technique to capture Google credentials.
- •Malwarebytes researchers have confirmed the scam's existence and are investigating its reach.
A new phishing campaign has emerged, masquerading as a giveaway of Anthropic's Claude Max service. The scam claims to offer 10,000 free one-month subscriptions to users, leveraging the popularity of AI services. Users are directed to a spoofed Google sign-in page designed to capture their login credentials. The phishing site mimics Claude's branding and creates a sense of urgency with a countdown timer. It does not request payment details, which makes it more convincing. The attack method uses a 'browser-in-the-browser' technique, creating a fake Google sign-in window within the existing browser tab. This method has been documented since 2022 and poses significant risks to users' Google accounts and any linked services. The campaign has been reported by Malwarebytes, with researchers noting its sophisticated design. As of now, the extent of the scam's reach is still being investigated.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Anthropic in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…
Massive Network of AI Proxy Servers Used for Malicious Activities Uncovered Security researchers from Team Cymru have identified over 10,000 proxy servers in China facilitating malicious AI activities. These servers, termed 'transfer stations,' are primarily used to bypass geographic restrictions and conduct model distillation attacks against frontier AI models. The infrastructure allows…