InstallFix and Claude Code: How Fake Install Pages Lead to Real Compromise
Trend Micro disclosed the InstallFix campaign, a multi-stage malware distribution operation leveraging fake Claude AI installer pages promoted via Google Ads to target users across multiple industries and regions. The attack chain uses mshta.exe, obfuscated PowerShell, VBScript COM abuse, AMSI bypass, SSL validation disabling, and victim-unique C&C URLs to achieve persistence and data collection; the final payload exhibits RedLine stealer indicators and collects browser/e-wallet credentials.