Cybercriminals continue to evolve their methods, now even exploiting trusted artificial intelligence platforms and popular software development services. A new, highly organized campaign has revealed that perpetrators are using Google Ads, GitLab pages, and Claude AI’s shared chat feature to convince unsuspecting users to execute malicious commands on their systems themselves.

The ClickFix technique and the new form of social engineering
At the heart of the attack is the method ClickFix, a modern form of social engineering that does not rely on automatic malware installation. Instead, attackers convince victims to copy and manually execute commands, believing them to be legitimate installation or troubleshooting procedures.
See also: Amos malware distributed via Google Ads – How are ChatGPT & Grok involved?
This approach is proving to be highly effective, as it exploits the human factor and bypasses several traditional protection mechanisms. According to security researchers at Trend Micro, more than 2,000 users were led to malicious pages through Google sponsored search results.
How attackers exploit trust in AI platforms
The most disturbing aspect of the campaign is that almost every stage of the attack is carried out through perfectly legitimate and widely used services. The perpetrators created dozens of pages on GitLab, using names that mimic popular tools, including ChatGPT Codex, Claude AI, Perplexity, Cursor IDE, and JetBrains.
Later, the campaign evolved even further, moving much of its activity to Claude AI’s shared chat. Through public links to claude.ai, the attackers were able to present malicious instructions within an environment that users considered safe and trustworthy.
A seven-week operation with constant evolution
Experts found that the campaign unfolded in six different waves over a seven-week period. Each new wave featured different baits, new keywords, and additional impersonations of well-known brands.
The constant adaptation of the campaign reveals a high level of organization and strategic planning. The attackers monitored user reactions and modified their tactics, seeking to increase success rates and remain under the radar of security systems.
See also: Google Ads spread malware via fake Homebrew Site
Why traditional defenses failed
This campaign is a prime example of what’s known as “stacking trust,” or the sequential use of multiple trusted services. Each step in the chain seems perfectly normal. Users see an ad on Google, are redirected to a GitLab page , and then receive instructions via Claude AI.
This model makes it extremely difficult to detect attacks. Domain reputation-based security systems cannot easily flag services like Google, GitLab, or Claude AI as suspicious, as these are platforms used daily by millions of users and businesses.

Developers at the center of attacks
The campaign appears to be primarily targeting developers and technical users. The computers of this user group often contain highly sensitive data, such as SSH keys, login tokens, source code, Git credentials, and access to cloud environments.
See also: Google Ads: Fake “Claude” site leads to ACR Stealer infection
If an attacker gains access to such a system, they can quickly expand their presence to code repositories, CI/CD pipelines, corporate collaboration platforms, and cloud infrastructures. In many cases, stealing passwords is not even required, as active session tokens or already authenticated browser sessions are sufficient.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The new reality in cybersecurity
This campaign is yet another reminder that modern cyberattacks are not solely based on malware. Attackers are increasingly turning to exploiting trust and human behavior.
For this reason, enterprises are urged to restrict administrator privileges, monitor PowerShell and shell command execution, implement the principle of least privilege , and separate everyday browsing activities from critical software development workflows. In an era where even the most trusted platforms can be turned into attack tools, vigilance and ongoing user education are now the first line of defense.
