HomeSecurityGoogle Ads: Fake “Claude” site leads to ACR Stealer infection

Google Ads: Fake “Claude” site leads to ACR Stealer infection

Malvertising attacks remain one of the most effective infection methods, especially when exploiting popular brands. The latest case documented by the SANS Internet Storm Center involves fake pages impersonating Claude (Anthropic) and displayed to users via Google Ads , ultimately leading to an infection linked to the infostealer ACR Stealer .

Google Ads Fake Claude ACR Stealer

The scenario is simple and therefore dangerous: the user searches for “Claude download” or a related term, sees an ad, clicks , and lands on a page that looks legit. The page offers a “Download for Windows” option (and corresponding instructions for macOS depending on the operating system), but the content is designed to lead to the execution of malicious files.

See also: Infostealer in Ukraine: 18-year-old stole 28,000 accounts

How the fake Claude trap works

According to the analysis , the perpetrators used pages that imitate Claude and were detected through malicious ads on Google search. In addition, it is reported that they use URLs that are “hidden” within sites.google[.]com, which often acts as a “trust amplifier” for the user.

The content of the page changes based on the operating system:

  • On macOS it displays instructions targeted at Mac users.
  • On Windows, it displays “Download for Windows” and installation steps that ultimately lead to infection.

The observed chain of infection (with IOCs)

SANS ISC gives specific examples/indicators for the chain:

  • Decoy page (fake Claude): hxxps[:]//fairpoint29.com/
  • Original download: hxxps[:]//primemetricsa[.]com/1518925 (ZIP, SHA256: 70b5ecc110e074dbca92932c0e840ea3492ea0a43c3f215b71392c12b02213b2)
  • Follow-up download (PowerShell script): hxxps[:]//6ryuefl.creativecommunityinfo[.]art/Camel-91267b64-989f-49b4-89b4-9e015844d42d (SHA256: a14c3ecf5eb3d2543358482e43dc765dbf9ee7a4bec7571f5ecb8829ca719692)
  • Domain for post-infection HTTPS traffic to C2: yw.enhanceblabber[.]cc

The analysis notes that the ZIP had a "problem" and is not extracted correctly with standard tools, which can be used either as a technical trick or as an anti-analysis measure.

See also: SHub Reaper: New infostealer disguises itself as legitimate Apple tools

Google Ads: Fake “Claude” site leads to ACR Stealer infection

ACR Stealer: Why infostealers are so dangerous in 2026

An infostealer, like ACR Stealer, doesn't "lock" files like ransomware, but it often does something equally destructive:

  • collects credentials (browsers, password managers, cookies)
  • steals session tokens (thus bypassing MFA in some scenarios)
  • targets crypto wallets and stored credentials
  • paves the way for business email compromise or subsequent attacks (ransomware/corporate infiltration)

This means that a “simple” mistaken download of an ad can develop into an account takeover, theft of money, or data leak.

Practical: What users should do now

1) Don't download apps from ads in search results. Go to the official domain by typing it in or via trusted bookmarks.
2) Check the domain very carefully: typosquats and unrelated domains are a classic sign.
3) If you've already downloaded/run something suspicious:

  • instantly change passwords on key accounts (email, banking, social, cloud)
  • sign out of all devices (where available)
  • enable MFA where it is missing
  • run a scan with updated AV/EDR

See also: Four malicious npm packages with infostealers and DDoS malware

Google Ads: Fake “Claude” site leads to ACR Stealer infection

What should admins/SOC do?

1) Threat hunting based on published IOCs (domains/hashes/URLs).
2) Web filtering: restrict access to newly created/suspicious domains, enforce download policies.
3) User awareness: micro-awareness campaign specifically for “download via Google Ads”.
4) If compromise is found: treat it as a credential compromise. Rotate tokens, revoke sessions, check for lateral movement.

What does it mean for Greece/businesses/admins/users?

In Greece, where many users “find” tools via Google and download installers without a second thought, such campaigns are particularly effective. For businesses and IT departments, the message is clear: even if the infrastructure is “tight”, a single endpoint compromise with infostealer can open the door to cloud accounts, emails and corporate repos.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS