Google Ads Turn Claude Downloads Into Malware Lures

The lure works because it sits inside a trusted discovery path, not because victims chase a random phishing link. Google search ads send users to Google Sites pages impersonating Claude, and the page changes its download instructions based on whether the visitor is on Windows or macOS. Brad Duncan found these pages in recent searches. On the Windows path, a sample seen on 2026-05-25 appears tied to ACR Stealer based on post-infection traffic, which shows the campaign is using a familiar AI download brand to feed credential theft across platforms. The risk is broader than one fake app page. If users search for software and trust the ad result, the hosting domain and the OS-specific content both help the lure blend in and keep scaling.

Part of the PlainSec briefing for 2026-05-26

Every edition of this story: Google Ads Turn Claude Downloads Into Malware Lures

Sources