Bottom line: Cybercriminals exploit legitimate AI chat sharing features from Claude to trick developers into manually executing malware and stealing corporate login credentials.
Security researchers from Zscaler have documented an attack campaign that abuses legitimate sharing functions from Anthropic’s Claude to trick developers and IT professionals into manually executing malicious code. The campaign combines social engineering with seemingly authentic AI chat content.
The campaign, dubbed “ClaudeFix,” leverages publicly shareable AI chats distributed via advertisements. The content appears authentic and contains instructions for alleged updates, development environment setup, or security checks. At its core, it is a variant of the already-known “ClickFix” or “InstallFix” technique that induces users to manually enter prepared commands into Terminal (macOS) or Command Line (Windows).
The attack targets developer workstations. After manual execution of the initial command, a multi-stage infection chain begins, with additional malware being loaded in the background. The malware then attempts to extract browser credentials, session cookies, stored cryptocurrency wallets, and system information. Particularly critical for CISOs: stolen login credentials and session tokens enable attackers to move laterally within the corporate network and compromise additional systems.
Zscaler observed that attackers adapted their approach multiple times during the campaign. The shift from using fraudulent websites to exploiting legitimate AI functions increases the credibility of the content and thus the success rate. This demonstrates how cybercriminals deliberately integrate popular AI services into their attack scenarios.
To mitigate risk, security researchers recommend regularly training developers and IT administrators not to execute commands from unknown or unverified sources without review. A combination of security awareness, clearly defined policies for command execution, and technical protective measures reduces the probability of success of such attacks.
Source: www.it-daily.net · Published 23 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.