Malvertising attacks remain one of the most effective infection methods, especially when exploiting popular brands. The latest case documented by the SANS Internet Storm Center involves fake pages impersonating Claude (Anthropic) and displayed to users via Google Ads , ultimately leading to an infection linked to the infostealer ACR Stealer .

The scenario is simple and therefore dangerous: the user searches for “Claude download” or a related term, sees an ad, clicks , and lands on a page that looks legit. The page offers a “Download for Windows” option (and corresponding instructions for macOS depending on the operating system), but the content is designed to lead to the execution of malicious files.
See also: Infostealer in Ukraine: 18-year-old stole 28,000 accounts
How the fake Claude trap works
According to the analysis , the perpetrators used pages that imitate Claude and were detected through malicious ads on Google search. In addition, it is reported that they use URLs that are “hidden” within sites.google[.]com, which often acts as a “trust amplifier” for the user.
The content of the page changes based on the operating system:
- On macOS it displays instructions targeted at Mac users.
- On Windows, it displays “Download for Windows” and installation steps that ultimately lead to infection.
The observed chain of infection (with IOCs)
SANS ISC gives specific examples/indicators for the chain:
- Decoy page (fake Claude): hxxps[:]//fairpoint29.com/
- Original download: hxxps[:]//primemetricsa[.]com/1518925 (ZIP, SHA256: 70b5ecc110e074dbca92932c0e840ea3492ea0a43c3f215b71392c12b02213b2)
- Follow-up download (PowerShell script): hxxps[:]//6ryuefl.creativecommunityinfo[.]art/Camel-91267b64-989f-49b4-89b4-9e015844d42d (SHA256: a14c3ecf5eb3d2543358482e43dc765dbf9ee7a4bec7571f5ecb8829ca719692)
- Domain for post-infection HTTPS traffic to C2: yw.enhanceblabber[.]cc
The analysis notes that the ZIP had a "problem" and is not extracted correctly with standard tools, which can be used either as a technical trick or as an anti-analysis measure.
See also: SHub Reaper: New infostealer disguises itself as legitimate Apple tools

ACR Stealer: Why infostealers are so dangerous in 2026
An infostealer, like ACR Stealer, doesn't "lock" files like ransomware, but it often does something equally destructive:
- collects credentials (browsers, password managers, cookies)
- steals session tokens (thus bypassing MFA in some scenarios)
- targets crypto wallets and stored credentials
- paves the way for business email compromise or subsequent attacks (ransomware/corporate infiltration)
This means that a “simple” mistaken download of an ad can develop into an account takeover, theft of money, or data leak.
Practical: What users should do now
1) Don't download apps from ads in search results. Go to the official domain by typing it in or via trusted bookmarks.
2) Check the domain very carefully: typosquats and unrelated domains are a classic sign.
3) If you've already downloaded/run something suspicious:
- instantly change passwords on key accounts (email, banking, social, cloud)
- sign out of all devices (where available)
- enable MFA where it is missing
- run a scan with updated AV/EDR
See also: Four malicious npm packages with infostealers and DDoS malware

What should admins/SOC do?
1) Threat hunting based on published IOCs (domains/hashes/URLs).
2) Web filtering: restrict access to newly created/suspicious domains, enforce download policies.
3) User awareness: micro-awareness campaign specifically for “download via Google Ads”.
4) If compromise is found: treat it as a credential compromise. Rotate tokens, revoke sessions, check for lateral movement.
What does it mean for Greece/businesses/admins/users?
In Greece, where many users “find” tools via Google and download installers without a second thought, such campaigns are particularly effective. For businesses and IT departments, the message is clear: even if the infrastructure is “tight”, a single endpoint compromise with infostealer can open the door to cloud accounts, emails and corporate repos.
