Fake Gift Claude Max: Phishing Targets Google Accounts

Le brief IA que les pros lisent chaque soir
Les 7 actus IA du jour, décryptées en 5 min. Gratuit.
Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.
Choisis ton rythme
Gratuit · Pas de spam · Désabonnement en 1 clic
A phishing operation exploits the image of Claude Max from Anthropic to capture Google credentials. The attack, reported by Malwarebytes, relies on a very credible page and a fake login window. The extent remains undetermined, but the technical clues and good practices to protect against it are known.
Undetermined Scope and Technical Trail Limited to the UK
It is still too early to determine the extent of this campaign or the number of victims, according to Stefan Dasic. The site has been linked to a company registered in the UK, but the server used is rented, which does not allow for the identification of the true operator. The page's source code contains comments in Russian, which could come from a third-party tool with no direct connection to the scam. Dasic notes that the presence of this language in the code is a weak indicator, sometimes used to mislead.
A Fake Offer of 10,000 Accesses and an Imitated Google Window
The scam presents itself as a celebration of 100 million users of Anthropic, promising 10,000 people a free month of Claude Max with limits multiplied by 20, as well as "extended thinking" and "priority access to Opus and Sonnet." A real-time counter displays the number of supposed accesses already distributed. The path leads to a Claude account upgrade page where the Apple login option is disabled, leaving only Google login. The technique used mimics a Google login window within the page ("browser within a browser"), complete with a padlock, a correctly spelled Google address, and the ability to move the window around the page. Malwarebytes emphasizes the care taken in the presentation, with credible graphics, fake five-star reviews, and a footer where most links lead to actual Anthropic pages.
Targeting Google Credentials and Potentially Exposed Linked Accounts
The goal of this operation is to steal Google usernames and passwords via a spoofed login page. The offer highlights the equivalent of about $200 worth of Claude Max services, but the real risk is granting access to all data associated with the Google account. A compromise could allow access to Gmail, Google Docs, and other services using those credentials. According to Stefan Dasic, the login prompt can deceive users who do not examine it closely. Since Claude does not have its own password and is used via Google or a link sent by email, a Claude account linked to a compromised Google account becomes accessible to the attacker.
Check the Window and Listen to the Password Manager
To spot these imitations, Malwarebytes recommends trying to drag the login window out of the browser: a real system window does not remain confined within the web page. A password manager that refuses to auto-fill the fields is a warning sign. Any offer discovered via a link should be verified by searching for it on the official site, which is not the case here for Anthropic. The disabling of alternative authentication options, such as Apple, is an indicator of a deliberate steering towards Google. Finally, the presence of seat counters or countdowns does not guarantee the legitimacy of a site or an offer.
Brief IA — L'actualité IA en français
L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.