PULSE NAME
IOC - Windows and macOS Malware Spreads via Fake “Claude Code” Google Ads
WHITE celestre 2026-05-20 Modified: 2026-05-20
14
IOCs
MEDIUM VOLUME
Claude has been in the news for quite some time, and cybercriminals are capitalizing by anticipating people will be searching for tools and downloads related to this LLM. To exploit this interest, they bought a convincing sponsored result that shows up above legitimate search results, redirecting victims to a fake documentation page that looks much like the real one.
Indicators of Compromise (1 / 14 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL hostname
TYPEINDICATORDESCRIPTIONCREATED
URL https://download.active-version.com/claude 2026-05-20