GTG-30006 Claude-assisted malware and phishing pipeline
Malware Activity
Summary
Hide ▲
Show ▼
An Iranian actor, GTG-30006, used Claude.ai to build malware, a delivery pipeline, and a phishing portal targeting domestic Iranians, increasing the risk of credential theft and Windows implant deployment. The operation included a fake ESET NOD32 login page that sent captured credentials to Telegram, a ClickFix-style Windows Run dialog lure, and geofenced delivery pages. The actor also built SECOMS64, a modular Windows implant with keylogging, screenshot capture, and Chrome credential extraction capabilities.
Related Happenings
SectopRAT fake Claude installer delivery
Malware Activity
H score19
First: 23.07.2026 22:48
Last: 23.07.2026 22:48
Sources 1
About this happening:
The SectopRAT malware is being delivered through a fake Claude desktop installer, exposing at least 29 organizations to credential theft and remote hands-on control. T...
SectopRAT fake Claude installer delivery
Malware ActivityAbout this happening: The SectopRAT malware is being delivered through a fake Claude desktop installer, exposing at least 29 organizations to credential theft and remote hands-on control. T...
REF6045 ClickFix banking fraud campaign targeting Mexican financial users
Campaign
H score36
First: 08.07.2026 15:52
Last: 08.07.2026 15:52
Sources 1
About this happening:
The REF6045 campaign is actively targeting customers of Mexican banks, fintechs, payment processors, and cryptocurrency exchanges, using ClickFix lures to push victims...
REF6045 ClickFix banking fraud campaign targeting Mexican financial users
CampaignAbout this happening: The REF6045 campaign is actively targeting customers of Mexican banks, fintechs, payment processors, and cryptocurrency exchanges, using ClickFix lures to push victims...
SHub Reaper macOS infostealer variant
Malware Activity
H score23
First: 19.05.2026 00:42
Last: 19.05.2026 00:42
Sources 1
About this happening:
The SHub Reaper macOS infostealer now uses AppleScript and a fake Apple security update lure to infect Macs, raising the risk of credential theft and remote access. It...
SHub Reaper macOS infostealer variant
Malware ActivityAbout this happening: The SHub Reaper macOS infostealer now uses AppleScript and a fake Apple security update lure to infect Macs, raising the risk of credential theft and remote access. It...
Fake Claude Code installation-page infostealer campaign targeting developers
Campaign
H score33
First: 11.05.2026 17:00
Last: 11.05.2026 17:00
Sources 1
About this happening:
A fake Claude Code installer campaign is using sponsored search results and operator-controlled domains to deliver an infostealer to developer workstations, pu...
Fake Claude Code installation-page infostealer campaign targeting developers
CampaignAbout this happening: A fake Claude Code installer campaign is using sponsored search results and operator-controlled domains to deliver an infostealer to developer workstations, pu...
Torg Grabber browser-extension theft activity
Malware Activity
H score36
First: 25.03.2026 20:32
Last: 25.03.2026 20:32
Sources 1
About this happening:
The Torg Grabber infostealer is actively stealing data from 850 browser extensions, including 728 cryptocurrency wallet extensions, which raises the risk of account ta...
Torg Grabber browser-extension theft activity
Malware ActivityAbout this happening: The Torg Grabber infostealer is actively stealing data from 850 browser extensions, including 728 cryptocurrency wallet extensions, which raises the risk of account ta...
Timeline
-
11.09.2026 17:29 2 articles · 2h ago
GTG-30006 uses Claude.ai to build malware and a phishing portal targeting domestic Iranians
Initial DisclosureAnthropic identified GTG-30006 as an Iranian threat actor that leveraged free Claude.ai accounts to develop malware, a delivery pipeline, and a phishing portal aimed at domestic Iranians. The workflow included a fake ESET NOD32 login page that forwarded captured credentials to Telegram, a ClickFix-style Windows Run dialog lure, geofenced delivery pages, and the SECOMS64 modular Windows implant with keylogging, screenshot capture, and Chrome credential extraction capabilities.
Show sources
- Claude Used to Automate Exploitation and Data Theft Across Multiple Victims — thehackernews.com — 11.09.2026 17:29
- Claude Used to Automate Exploitation and Data Theft Across Multiple Victims — thehackernews.com — 11.09.2026 17:29