Mass Phishing/Fraud Campaign Impersonating Anthropic Claude and Mythos Brands (3,188 Malicious Domains) — Threadlinqs Intelligence
As of 2026-07-19, Mass Phishing/Fraud Campaign Impersonating Anthropic Claude and Mythos Brands (3,188 Malicious Domains) is a high-severity phishing threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 48 indicators of compromise.
Threat ID: TL-2026-1521 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
BforeAI PreCrime Labs identified 3,188 malicious domains registered between April 1 and May 15, 2026 that impersonate Anthropic's Claude and Mythos brands, spanning fake AI security-scanner platforms,
In the six weeks following Anthropic's Mythos announcement, BforeAI's PreCrime Labs tracked 3,188 domains registered (April 1 - May 15, 2026) engineered to exploit trust in the Claude and Mythos brands. Domains cluster into naming patterns: pure Mythos branding (~500 domains, e.g. mythosaiapp, mythosauth, mythosbench, mythosrouter, mythosproxy) impersonating AI agents, evaluation dashboards, and infrastructure components; Claude-Mythos hybrids (~96 domains, e.g. claudemythospreview, freeclaudemythos) suggesting fake early-access programs or 'Pro unlocks'; Claude-only strings (~2,300 domains, e.g. 10xclaude, 1claude) exploiting the Claude brand directly; and security-themed variants (mythoscyber, mythosprotector, mythosforensics, mythosvulnerabilityscanner) that disguise phishing infrastructure with legitimate cybersecurity language. Registrations span commercial TLDs (.com, .net, .org, .io), tech-aligned TLDs (.ai, .app, .cloud, .tech, .digital), and abuse-prone/novelty TLDs (.xyz, .top, .click, .cfd, .icu, .vip, .space), concentrated at mass-market bulk registrars with WHOIS privacy enabled and registration bursts timed to media cycles.
The campaign spans seven operational categories: (1) fake AI security platforms such as mythos-ai[.]net impersonating 'Mythos by Anthropic' as an enterprise vulnerability-scanning SaaS that solicits infrastructure URLs, API tokens, and repository details via 'request access' workflows without any active intrusion; (2) OAuth/credential-harvesting dashboards branded 'Claude Pro,' 'Claude Research Workspace,' or 'Claude Mythos Agents'; (3) trojanized tool distribution via installers posing as 'Claude Desktop,' 'Claude CLI,' 'Claude Browser Extension,' or 'Claude Security Agent' that deliver infostealers and RATs; (4) account-resale marketplaces (claudekyc[.]shop, claudecode-buy[.]com) advertising unauthorized Claude/ChatGPT accounts with KYC-bypass claims and Telegram-based after-sales support; (5) fake monetization schemes (earnwithclaude[.]com) exploiting 'make money with AI' narratives to harvest leads or funnel victims into subscription scams; (6) narrative-manipulation/whistleblower-style sites such as bannedbyanthropic[.]com posing as a transparency portal documenting fictitious Anthropic bans to harvest identities from frustrated users; and (7) gambling/account-resale ecosystems leveraging Mythos branding for fraudulent gaming platforms with fake top-up mechanics.
The trojanized-tool-distribution category converges with a broader, actively-tracked ecosystem of AI-developer-tool impersonation campaigns documented independently by Straiker and EclecticIQ in 2026. Straiker's investigation ('Fake Claude Code, Real Malware') identified 88 phishing domains (32 active as of May 14, 2026) impersonating Claude Code, NotebookLM, JetBrains, and other AI developer tools, serving weaponized install commands that use shell operators (e.g. '&') to silently background-execute malicious payloads while a legitimate-looking foreground operation completes. The chain deploys a heavily-obfuscated Go binary (compiled with garble) named ServiceCore.dll implementing a full ML-KEM-768 (Kyber) post-quantum key-encapsulation pipeline to protect a 192,015-byte shellcode payload, which loads ACRStealer (also tracked as the Amatera variant; first documented by AhnLab ASEC in February 2025) entirely in memory. ACRStealer exfiltrates browser data, 65+ browser credential stores, 175+ cryptocurrency wallet extensions, and — notably — AI-coding-assistant credentials from Cline (.cline/data/secrets.json) and Continue.dev (.continue/config.yaml), plus Snowflake SSH session tokens. Persistence is established via a scheduled task masquerading as 'Microsoft Edge Update' (MicrosoftEdgeUpdateCore.dll, rundll32 export GetTranslateScript), installed at %LocalAppData%\Microsoft\EdgeUpdate\, guarded by a per-host mutex and a TLS-callback execution trick that runs code during DLL_PROCESS_ATTACH before the host process finishes loading
Weaknesses (CWE)
CWE-451, CWE-506, CWE-494, CWE-522
Target sectors: technology, softwaredevelopment, cybersecurity, finance, cryptocurrency, generalconsumer
Target regions: Global
Related threats
- Coordinated Domain Impersonation Campaign Exploits Fable 5/Mythos 5 AI Model Export-Control Ban — 117+ Malicious Domains Targeting Anthropic, Claude, and Fable Brands
- SEO Poisoning Campaign Impersonates Gemini CLI and Claude Code to Deliver In-Memory PowerShell Infostealer (EclecticIQ)
- Pokémon Brand-Spoofing Campaign: 1,352 Lookalike Domains Ahead of 30th Anniversary
- Red Canary Intelligence Insights July 2026: ClearFake Leads Third Straight Month Amid CastleLoader Debut and Caret-Obfuscated Paste-and-Run Campaigns
- June 2026 Infostealer Campaign Trends: Remus, ACRStealer, LummaC2, Vidar Distributed via SEO Poisoning and DLL Sideloading
- Fake Google/Cloudflare Verification Pages Spread Multiple Malware Families via ClickFix (HijackLoader, StealC, Remus Stealer, Amatera Stealer, CastleLoader, NetSupport RAT, ResiLoader)
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 48 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
3 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
PHISHING, HIGH, threat intelligence, cybersecurity, T1589, T1583.001, T1583.008, T1587.001, T1585.001, T1584.006, T1566.002, T1189, T1204.001, T1059.001