A case has been discovered in which phishing sites impersonating the generative AI service 'Claude' are distributing information-stealing malware.

Phishing site disguised as the 'Claude Download Page.' AhnLab.

Phishing site disguised as the 'Claude Download Page.' AhnLab.

View original image

On April 22, AhnLab announced that it had found a phishing site imitating the official Claude homepage to trick users into downloading malware.


This site used the 'Clickjacking' technique, which disguises notifications and error pop-ups to prompt users to execute malicious commands by copying and pasting them. The site displays buttons for downloading by operating system, such as Windows and Mac, alongside the phrase "Use Claude on your desktop."


When users click the download button, a pop-up window appears with installation instructions that direct them to copy a specific command. However, if users follow these instructions, malware is installed. The malware then steals files from the user's personal computer, browser-stored information, and cryptocurrency wallet data, and transmits them to the attacker's server.


The phishing site appeared at the top of Google search results when searching keywords such as "Claude App" and "Claude Desktop." AhnLab suspects that the attackers manipulated the site's ranking by using Google search advertising services to lure users attempting to install Claude on their PCs.


To prevent damage, users should follow basic security measures: ▲ Download programs only from official sources ▲ Always verify the domain address regardless of the site's position in search results ▲ Apply the latest security patches ▲ Enable real-time antivirus monitoring features such as V3.



Donghyun Kim, manager at AhnLab, stated, "There has been a steady increase in cases where phishing sites meticulously impersonate popular and widely-used services to distribute malware. Since many users tend to trust sites that appear at the top of search results, attackers are even manipulating rankings, so extra caution is necessary."


This content was produced with the assistance of AI translation services.

© The Asia Business Daily(www.asiae.co.kr). All rights reserved.

Today’s Briefing