InstallFix: Hackers Use Fake Claude AI Installer Pages and Google Ads to Deploy RedLine Stealer Malware
A malware campaign called InstallFix is using paid Google Ads to push fake Claude AI installation pages to the top of search results, tricking users into running malicious commands that deploy a multi-stage attack chain linked to RedLine Stealer. Confirmed victims span the US, Malaysia, the Netherlands, and Thailand across government, education, and enterprise sectors. Trend Micro documented the full infection chain, which uses ClickFix, mshta.exe abuse, and per-victim C2 infrastructure to evade detection.
Itagora tiene in archivio titolo e sommario per la ricerca interna. Il testo completo resta sulla fonte. Il link in uscita non invia referrer.