New Phishing Attack Promises Claude Max, but Steals Your Google Credentials Instead

News Room
5 Min Read

The offer is for access to about $200 worth of Anthropic’s Claude Max service. But the real price could be giving scammers access to everything in your Google accounts.

A new phishing scam reported by the cybersecurity service Malwarebytes works like this: The scam claims that Anthropic is celebrating attracting 100 million users by giving 10,000 people a free month of Claude Max with x20 limits. The offer, which includes “extended thinking” and “priority access to Opus and Sonnet, no caps,” is actually all cap. It’s a fake offer that leads to a Google login page meant to steal login and password information, which could in turn open up access to Gmail, Google Docs and other non-Google accounts that use your Google information.

The fake giveaway, Malwarebytes said in its report, is different from many other phishing attempts because of how convincing it looks.

“The presentation is careful, down to the real logo and colors, invented five-star reviews, and a long footer whose links lead almost entirely to genuine Anthropic pages,” wrote Stefan Dasic, senior malware research engineer at Malwarebytes. The page also includes a running counter showing how many of those fake 10,000 accounts have been given away.

For those who fall for the scam, clicking on the offer leads to a login page to upgrade a Claude account. An Apple login option is disabled, leaving only the option to “Sign in with Google.” The login page employs a browser-in-a-browser trick that Dasic said is convincing enough to fool those who don’t look carefully. “The page draws a browser window inside the existing tab, complete with a padlock and a correctly spelled Google sign-in address. It can even be dragged around the page.”

In a message to CNET, Dasic said that the login prompt might convince those who don’t take the time to examine the login page. “The overlap matters because Claude has no password of its own: You get in either by continuing with Google or by a login link sent to your email. So if someone’s Claude account is tied to the Google account that was phished, the attacker reaches it either way.”

How to spot fake browser scams like this

Dasic told CNET that it’s too early to tell how widespread the scam has gone or how many people it’s reached. So far, he said, an investigation has traced the site to a UK-registered company, but the server is rented, “which tells us where the server was rented, not who rented it.”

The web page has components that contain developer comments written in Russian; it could, however, be part of a tool built by someone who isn’t necessarily the scammer involved in this campaign.

“Language in code is weak evidence on its own and has been planted before to misdirect,” Dasic added.

Malwarebytes offered a few tips in its post for detecting a fake browser window:

  • For a popup login screen, try dragging the window outside the browser. A real popup won’t be trapped inside the web page.
  • Let your password manager determine if it’s providing information to a real site. If it doesn’t populate the text boxes, that’s a good signal that it’s fake.
  • If you arrived on a site through a link, verify it by trying to find it on the company’s actual website. In this case, you wouldn’t find it on Anthropic’s website.
  • Don’t fall for single sign-in options. The disabled login for Apple is an indication that the scammer is trying to steer people into its trap.
  • Slot counters and countdowns aren’t a sign that a website is legitimate or that an offer is real.

Read the full article here

Share This Article
Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *