Google Ads Turn Claude Downloads Into Malware Lures
The lure works because it sits inside a trusted discovery path, not because victims chase a random phishing link. Google search ads send users to Google Sites pages impersonating Claude, and the page changes its download instructions based on whether the visitor is on Windows or macOS.
Brad Duncan found these pages in recent searches. On the Windows path, a sample seen on 2026-05-25 appears tied to ACR Stealer based on post-infection traffic, which shows the campaign is using a familiar AI download brand to feed credential theft across platforms.
The risk is broader than one fake app page. If users search for software and trust the ad result, the hosting domain and the OS-specific content both help the lure blend in and keep scaling.