<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Fake Claude AI Sites Spread Malware Through Google Ads

Beware of fake Claude Code sites spreading malware via Google ads, targeting developers with near-perfect clones to steal credentials.
Content Team

Cybercriminals are targeting developers with fake Claude Code installation sites that spread through Google-sponsored search results. Push Security researchers discovered the "InstallFix" campaign, where attackers create near-perfect clones of Anthropic's legitimate installation pages.

When users copy installation commands from these fake sites, they unknowingly deploy Amatera Stealer malware that can steal credentials and access enterprise development environments. The attack exploits developers' common practice of copy-pasting terminal commands directly from websites.

The malicious ads appear above legitimate search results for terms like "Claude Code install," making them easy to mistake for official pages. Attackers use trusted hosting services like Cloudflare Pages to make their fake domains appear legitimate.

Source: Dark Reading

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo