For years, the standard advice for protecting yourself online has been simple: check the URL, look for the padlock, and don't trust suspicious domains. Now, new research from TrendAI shows how attackers have managed to get around this awareness.
The malicious campaigns were able to spread by attackers purchasing Google Ads targeting searches on popular AI tools such as Claude, ChatGPT and Cursor. But the ads didn't lead to a fake copy of the AI tools as is traditionally often the case, but instead led to a genuine claude.ai page. Through Anthropic's shared chat feature, the attackers were able to place convincing fake ”support” instructions that tricked people into running a terminal command, which unnoticed installed malware that stole passwords, browser data, and crypto wallets.
The entire attack originated from legitimate infrastructure, leaving many of the security tools used by the affected organizations undetected. The campaign deliberately targeted tech-savvy users, people most organizations assume are least likely to fall for social engineering.
TrendAI tracked six different attack waves and over 100 malicious hostnames. Anthropic has removed the malicious content after TrendAI reported it.
“What made the campaign so effective wasn’t sophisticated technology, it was about leveraging trust,” says Martin Fribrock, Country Manager Sweden, Finland and Baltics at TrendAI. The attackers didn't need to create convincing fakes, because they found a way to post their instructions on the real page. Once the decoy is on a legitimate domain with a valid certificate, most of the protection mechanisms we rely on simply have no use for it.
Read more here








