Fake Claude Download Sites Spreading Malware
- A new malware campaign involving phishing sites disguised as Claude download pages was discovered.
- Google Ads were used to place the phishing sites at the top of search results and lure users to click
Phishing sites impersonating the official Claude website have been found distributing infostealers through fake Claude download pages, highlighting the need for caution

Phishing site disguised as a Claude download page
The site displays the phrase “Bring Claude to your Desktop” along with download buttons for eachOS, including Windows and macOS.
When a user clicks the download button for their OS, the site does not deliver an actual installer. Instead, it displays a pop-up window with installation instructions. The instructions tell the user to copy a specific command and paste it into the system on their PC, claiming that this will begin the download. In reality, if the user follows these steps, malware is installed and steals files, browser-stored data, and cryptocurrency wallet information and sends them to the attacker’s server.

Screen prompting execution of a malicious command
This technique is known as ClickFix, in which attackers disguise malicious commands as instruction or error pop-ups and trick users into executing them through copy and paste. Threat actors actively use this technique in a wide range of malware distribution campaigns.
The phishing site appeared at the top of Google search results for keywords such as claude app and claude desktop. The attackers are believed to have used Google Ads to manipulate search placement and lure users seeking to install Claude on their PCs. Users should remain cautious, as attacks that exploit trust in top-ranked search results continue to emerge.

Claude phishing site shown at the top of search results
To prevent damage, users should follow basic security practices, including downloading programs only from official sources, checking domain addresses regardless of search ranking, applying the latest security patches to PCs, OSs, software, and internet browsers, and enabling real-time monitoring in antivirus software such as V3.
Donghyun Kim, at AhnLab who analyzed this case, mentioned, “Threat actors continue to distribute malware through phishing sites that closely impersonate popular or widely used well-known services. Many users tend to trust sites displayed at the top of search results, and attackers are now even manipulating ranking exposure. This makes extra caution essential.”
AhnLab V3 supports detection of and access blocking for such phishing sites. We also provide professional, up-to-date threat intelligence on threats, including this case, through our next-generation threat intelligence platform AhnLab TIP.
- AhnLab