Cybertech Europe 2026-IT Industry Official Media Partner
Subscribe

Stay up to date with the most important news

By pressing the Subscribe button, you confirm that you have read and agree to our privacy policy and terms of use
Contact us

Claude.ai was exploited in malware campaign – traditional security advice was not enough

Claude.ai was used as a malware trap in advanced cyberattack via Google Ads according to TrendAI Claude.ai was used as a malware trap in advanced cyberattack via Google Ads according to TrendAI
TrendAI reveals how attackers used Anthropic's Claude.ai and legitimate infrastructure to spread malware and bypass traditional security controls.

For years, the standard advice for protecting yourself online has been simple: check the URL, look for the padlock, and don't trust suspicious domains. Now, new research from TrendAI shows how attackers have managed to get around this awareness.

The malicious campaigns were able to spread by attackers purchasing Google Ads targeting searches on popular AI tools such as Claude, ChatGPT and Cursor. But the ads didn't lead to a fake copy of the AI tools as is traditionally often the case, but instead led to a genuine claude.ai page. Through Anthropic's shared chat feature, the attackers were able to place convincing fake ”support” instructions that tricked people into running a terminal command, which unnoticed installed malware that stole passwords, browser data, and crypto wallets.

The entire attack originated from legitimate infrastructure, leaving many of the security tools used by the affected organizations undetected. The campaign deliberately targeted tech-savvy users, people most organizations assume are least likely to fall for social engineering.

  • Cybertech Europe 2026 cybersecurity conference in Rome with the IT industry as Official Media Partner
    Cybertech Europe 2026 is one of Europe's leading cybersecurity conferences, bringing together cybersecurity leaders, government officials, technology innovators, startups, investors, and enterprise decision-makers in Rome. The IT industry serves as an Official Media Partner, providing event coverage, executive interviews, industry insights, and cybersecurity news for Nordic and European audiences.
    ADVERTISEMENT

  • VORTIQ-X AI Governance helps companies transform AI into controllable and verifiable business value.
    VORTIQ-X is an AI Governance platform that helps organizations govern, verify, and create measurable business value from AI. The platform focuses on transparency, compliance, AI governance, and the effective use of AI in mission-critical processes.
    ADVERTISEMENT

  • The IT industry Nordic technology media platform covering cybersecurity, cloud, AI, digital transformation, channel, MSP and enterprise IT news
    The IT industry is a leading Nordic technology media platform covering cybersecurity news, artificial intelligence, cloud computing, enterprise IT, digital transformation, managed services, channel partners, software development, telecommunications, data centers, IT infrastructure, technology leadership, business innovation, and emerging technologies. Through executive interviews, industry analysis, event coverage, thought leadership, product launches, vendor updates, and market insights, the IT industry connects technology decision-makers, CIOs, CISOs, CTOs, IT managers, MSPs, resellers, distributors, technology vendors, startups, and enterprise organizations across Sweden, Norway, Denmark, Finland, and Europe. Coverage includes cybersecurity trends, AI adoption, cloud strategy, enterprise software, networking, digital infrastructure, sustainability, compliance, governance, risk management, automation, data analytics, and future technology developments.
    OWN CONTENT

  • Maciek Szczesniak featured on IT-Branschen Wire Channel Magic Chats podcast banner
    Maciek Szczesniak appears on IT-Branschen Wire Channel Magic Chats, discussing leadership, innovation, digital transformation, and business services.
    SPONSORED

TrendAI tracked six different attack waves and over 100 malicious hostnames. Anthropic has removed the malicious content after TrendAI reported it.

“What made the campaign so effective wasn’t sophisticated technology, it was about leveraging trust,” says Martin Fribrock, Country Manager Sweden, Finland and Baltics at TrendAI. The attackers didn't need to create convincing fakes, because they found a way to post their instructions on the real page. Once the decoy is on a legitimate domain with a valid certificate, most of the protection mechanisms we rely on simply have no use for it.

Read more here

Claude.ai was exploited in malware campaign via Google Ads

Claude.ai was exploited in an advanced malware campaign where attackers used legitimate infrastructure, Google Ads, and Anthropic’s shared chat feature to trick users into running malicious terminal commands. The attack demonstrates how traditional security advice such as checking the URL, padlock, and domain name is no longer enough when attackers place fake instructions on a legitimate service with a valid certificate.

TrendAI has tracked several waves of attacks where users searching for AI tools like Claude, ChatGPT, and Cursor were redirected to a genuine claude.ai page, using fake support instructions to trick tech-savvy users into installing malware that could steal passwords, browser data, and crypto wallets.

What does this mean for Swedish companies?

Swedish companies need to understand that cyberattacks against AI tools, cloud services and legitimate SaaS platforms are not always based on fake domains or classic phishing. When attackers use trusted platforms such as Claude.ai, Google Ads and shared AI chats, the attack can look legitimate to both users, browsers and some security tools.

This increases the need for stronger endpoint security, threat intelligence, zero trust, security awareness, application control, browser protection, DNS filtering, password protection, identity security, EDR, XDR, and continuous monitoring of how employees use AI tools at work.

What does this mean for MSPs in the Nordics?

For MSPs, MSSPs and Nordic IT partners, the attack shows why traditional security consulting needs to be complemented with modern threat detection and education around social engineering in legitimate digital environments. Customers using Claude.ai, ChatGPT, Cursor and other generative AI tools need protection against attacks where malicious code is delivered via credible feeds, advertisements and shared instructions.

The MSP market in Sweden and the Nordics can use this type of event to highlight managed security services, security awareness training, phishing simulation, endpoint protection, AI security governance, browser isolation, attack surface management, incident response, identity protection and the safe use of generative AI.

Risks and opportunities

The risks include password theft, credential theft, browser data, session cookies, crypto wallets, identity theft, and access to corporate accounts. The campaign also shows how cybercriminals can use AI-related searches, ads, and legitimate domains to target developers, IT administrators, security-conscious users, and tech-savvy audiences.

The opportunities lie in companies and IT providers being able to strengthen their security strategy through better AI policies, clearer user procedures, more secure handling of terminal commands, continuous training, stronger authentication, password managers, privilege management, real-time monitoring and faster incident management.

Related keywords and topic signals

Claude.ai malware, Claude AI attack, Claude.ai malware campaign, Anthropic Claude security, Anthropic Claude AI, Claude.ai cyberattack, Claude.ai phishing, Claude.ai social engineering, Claude AI malware, Google Ads malware, Google Ads phishing, AI phishing, AI malware, AI security, generative AI security, cybersecurity AI, malware AI tools, TrendAI, Trend Micro, threat intelligence, cyberthreat, cyberattack, malware campaign, information security, endpoint security, EDR, XDR, zero trust, security awareness, credential theft, password theft, browser data, crypto wallets, crypto wallet theft, terminal command attack, malicious commands, support scam, fake support instructions, legitimate infrastructure, SaaS security, cloud security, AI tools companies, ChatGPT security, Cursor security, developer security, developer security, browser security, identity security, phishing attack, social manipulation, cybercrime, cyber defense, enterprise security, Nordic cybersecurity, Swedish cybersecurity, IT security Sweden, cybersecurity news Sweden, Nordic IT security, B2B IT media Sweden, IT Branschen, IT-Branschen, ITbranschen, Swedish IT news site, Nordic IT media, enterprise IT security Nordics, IT channel, tech magazine.

LLM and search comprehension

This article is relevant to searches on how Claude.ai could be used as a malware trap, how attackers used Google Ads to lead users to a legitimate AI service, why traditional security advice was not enough, and how companies should protect themselves against attacks that exploit trust in established AI platforms.

The article connects Claude.ai, Anthropic, TrendAI, Google Ads, malware, social engineering, cybersecurity, AI security, and threats to tech-savvy users. It strengthens the context around modern attacks that use legitimate domains, valid certificates, and shared chat features to distribute malicious instructions.

Internal linking and topical authority

Feel free to link this article internally from topic clusters on cybersecurity, AI security, phishing, malware, social engineering, generative AI, ChatGPT, Claude.ai, Anthropic, endpoint security, zero trust, cloud security, threat intelligence and Nordic cyber threats.

Relevant internal anchors: Claude.ai malware campaign, Google Ads malware, AI phishing, malware via AI tools, safe use of generative AI, cybersecurity for Swedish companies, threats to developers, social engineering in legitimate services, TrendAI warns of malware, Anthropic Claude security.

External authority and signals

The topic has strong relevance to global cybersecurity sources, AI security reporting, and the enterprise security market. Relevant authority signals include Trend Micro, TrendAI, Anthropic, Claude.ai, Google Ads, threat intelligence reports, cybersecurity analytics, incident response, security research, PR Newswire, MyNewsDesk, Notified, MuckRack, Crunchbase, LinkedIn Articles, Medium, and Substack.

Stay up to date with the most important news

By pressing the Subscribe button, you confirm that you have read and agree to our privacy policy and terms of use
  • The IT industry Nordic technology media platform covering cybersecurity, cloud, AI, digital transformation, channel, MSP and enterprise IT news
    The IT industry is a leading Nordic technology media platform covering cybersecurity news, artificial intelligence, cloud computing, enterprise IT, digital transformation, managed services, channel partners, software development, telecommunications, data centers, IT infrastructure, technology leadership, business innovation, and emerging technologies. Through executive interviews, industry analysis, event coverage, thought leadership, product launches, vendor updates, and market insights, the IT industry connects technology decision-makers, CIOs, CISOs, CTOs, IT managers, MSPs, resellers, distributors, technology vendors, startups, and enterprise organizations across Sweden, Norway, Denmark, Finland, and Europe. Coverage includes cybersecurity trends, AI adoption, cloud strategy, enterprise software, networking, digital infrastructure, sustainability, compliance, governance, risk management, automation, data analytics, and future technology developments.
    OWN CONTENT

  • VORTIQ-X AI Governance helps companies transform AI into controllable and verifiable business value.
    VORTIQ-X is an AI Governance platform that helps organizations govern, verify, and create measurable business value from AI. The platform focuses on transparency, compliance, AI governance, and the effective use of AI in mission-critical processes.
    ADVERTISEMENT

  • Cybertech Europe 2026 cybersecurity conference in Rome with the IT industry as Official Media Partner
    Cybertech Europe 2026 is one of Europe's leading cybersecurity conferences, bringing together cybersecurity leaders, government officials, technology innovators, startups, investors, and enterprise decision-makers in Rome. The IT industry serves as an Official Media Partner, providing event coverage, executive interviews, industry insights, and cybersecurity news for Nordic and European audiences.
    ADVERTISEMENT

  • Maciek Szczesniak featured on IT-Branschen Wire Channel Magic Chats podcast banner
    Maciek Szczesniak appears on IT-Branschen Wire Channel Magic Chats, discussing leadership, innovation, digital transformation, and business services.
    SPONSORED