Fake Anthropic Sites Deliver Fileless Infostealer to Claude Code Users

https://hackread.com/wp-content/uploads/2026/05/fake-anthropic-sites-fileless-infostealer-claude-code-users-1024x576.png

A new threat intelligence report by security research firm Cyderes has exposed an active credential theft campaign targeting first-time users of Anthropic’s Claude Code tool.

Shared with Hackread.com, the findings show how threat actors exploit the rapid adoption of AI coding tools to compromise small business owners, entrepreneurs, and teachers who lack enterprise-grade protections.

The ClickFix Attack Chain

Cyderes’ research reveals that the attack begins with SEO poisoning; when a user searches for how to install the software, they are taken to a spoofed Anthropic page. They are then instructed to open the Windows Run dialog box (Win+R) and paste a malicious mshta.exe command. This is a classic ClickFix lure that helps the attackers establish hands-on keyboard execution to bypass automated sandbox analysis.

The file mshta.exe, when executed, retrieves a 6.7 MB MP3/HTA polyglot payload from download.version-516.com/claude. This file runs two formats at once; it contains valid audio tags...

Copyright of this story solely belongs to hackread.com. To see the full text click HERE

Read more