Find notable cyber news and cases, enriched with sources, timelines, and signals.

GTG-30006 Claude-assisted malware and phishing pipeline

Malware Activity
First reported
Last updated
Happening score
H score 20
1 unique sources, 1 articles

Summary

Hide ▲

An Iranian actor, GTG-30006, used Claude.ai to build malware, a delivery pipeline, and a phishing portal targeting domestic Iranians, increasing the risk of credential theft and Windows implant deployment. The operation included a fake ESET NOD32 login page that sent captured credentials to Telegram, a ClickFix-style Windows Run dialog lure, and geofenced delivery pages. The actor also built SECOMS64, a modular Windows implant with keylogging, screenshot capture, and Chrome credential extraction capabilities.

Related Happenings

SectopRAT fake Claude installer delivery

Malware Activity
H score19 First: 23.07.2026 22:48 Last: 23.07.2026 22:48 Sources 1

About this happening: The SectopRAT malware is being delivered through a fake Claude desktop installer, exposing at least 29 organizations to credential theft and remote hands-on control. T...

REF6045 ClickFix banking fraud campaign targeting Mexican financial users

Campaign
H score36 First: 08.07.2026 15:52 Last: 08.07.2026 15:52 Sources 1

About this happening: The REF6045 campaign is actively targeting customers of Mexican banks, fintechs, payment processors, and cryptocurrency exchanges, using ClickFix lures to push victims...

SHub Reaper macOS infostealer variant

Malware Activity
H score23 First: 19.05.2026 00:42 Last: 19.05.2026 00:42 Sources 1

About this happening: The SHub Reaper macOS infostealer now uses AppleScript and a fake Apple security update lure to infect Macs, raising the risk of credential theft and remote access. It...

Fake Claude Code installation-page infostealer campaign targeting developers

Campaign
H score33 First: 11.05.2026 17:00 Last: 11.05.2026 17:00 Sources 1

About this happening: A fake Claude Code installer campaign is using sponsored search results and operator-controlled domains to deliver an infostealer to developer workstations, pu...

Torg Grabber browser-extension theft activity

Malware Activity
H score36 First: 25.03.2026 20:32 Last: 25.03.2026 20:32 Sources 1

About this happening: The Torg Grabber infostealer is actively stealing data from 850 browser extensions, including 728 cryptocurrency wallet extensions, which raises the risk of account ta...

Timeline

  1. 11.09.2026 17:29 2 articles · 2h ago

    GTG-30006 uses Claude.ai to build malware and a phishing portal targeting domestic Iranians

    Initial Disclosure

    Anthropic identified GTG-30006 as an Iranian threat actor that leveraged free Claude.ai accounts to develop malware, a delivery pipeline, and a phishing portal aimed at domestic Iranians. The workflow included a fake ESET NOD32 login page that forwarded captured credentials to Telegram, a ClickFix-style Windows Run dialog lure, geofenced delivery pages, and the SECOMS64 modular Windows implant with keylogging, screenshot capture, and Chrome credential extraction capabilities.

    Show sources