Fake Claude Max Giveaway Phishing Campaign Uses Browser-in-the-Browser to Steal Google Credentials
Fake Claude Max Giveaway Phishing Campaign Uses (TL-2026-2626), also tracked as Fake Claude Max Giveaway Phishing, is a medium-severity phishing campaign, first published 2026-09-23. It has no confirmed attribution, affects Anthropic Claude Max subscription (brand impersonated by the phishing, maps to 12 MITRE ATT&CK techniques (T1027, T1036.005, T1056.003), and is covered by 9 detection rules and 5 indicators of compromise.
Key facts for TL-2026-2626
- Threat ID
- TL-2026-2626
- Also known as
- Fake Claude Max Giveaway Phishing, Claude Max BITB Google Credential Phishing
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-09-23
- Last reviewed
- 2026-09-23
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Detection rules
- 9
- Indicators of compromise
- 5
Malware and tooling in Fake Claude Max Giveaway Phishing Campaign Uses
Malware and tooling: Browser-in-the-Browser (BITB) phishing technique/toolkit
A phishing campaign impersonates Anthropic's Claude Max subscription with a fake 'free month' giveaway and a false-scarcity countdown, funneling every visitor into a Browser-in-the-Browser (BITB) fake Google sign-in window that harvests real Google account credentials. The reusable, Russian-commented phishing widget mirrors a technique family also used against Microsoft 365 logins in June 2026, and a compromised Google account can expose email, documents, password-reset messages, and any Claude account linked via Google sign-in.
How Fake Claude Max Giveaway Phishing Campaign Uses works
In September 2026, Malwarebytes documented a credential-phishing campaign that impersonates Anthropic's Claude Max subscription tier to steal Google account credentials via a Browser-in-the-Browser (BITB) technique. The lure page advertises a fake giveaway of '10,000 free one-month subscriptions to Claude Max,' reinforced by a fabricated urgency counter that displays fewer than 750 slots 'remaining' and appears to tick down every few seconds — the counter is generated entirely client-side and resets on every page reload, meaning it has no relationship to real inventory or visitor count.
The page borrows Anthropic's genuine logo and brand colors, invents five-star user reviews, and links its footer to real Anthropic web pages — a low-cost trust-building technique the source analysis called 'probably the most effective trust signal on the site, and it cost the operator nothing.' Two sign-in options are presented: an Apple button that is permanently disabled with a 'temporarily unavailable' message, and an email-entry field that silently discards any text typed into it and instead triggers the same Google sign-in flow. Every path on the page funnels the visitor toward one outcome: a fake Google authentication window.
That window is not a real browser popup — it is an HTML/CSS/JS element rendered inside the page itself, built to imitate a native OS window: a fake address bar showing a correct-looking Google URL, a fraudulent padlock/HTTPS icon, and a draggable title bar. The flow opens with what looks like a human-verification step rather than an immediate password prompt, mirroring how real Google OAuth flows sometimes present a device/human check before credentials. This Browser-in-the-Browser (BITB) technique was first publicly documented by researcher mr.d0x in March 2022 (contemporaneously covered by The Register) and has since become a broadly reused methodology across unrelated phishing campaigns — Palo Alto Networks Unit 42 reported a closely related BITB kit in June 2026 that used OS/browser-fingerprinted, matching fake popups to steal Microsoft 365 credentials, complete with console-disabling anti-analysis code, split/obfuscated visible strings to dodge keyword scanners, and automatic redirection of suspected bots/scanners to a legitimate Microsoft support page.
The Claude Max phishing page's fake sign-in widget is loaded through 'a single line of code from an outside service,' consistent with a reusable, externally hosted phishing-kit-as-a-service component rather than a bespoke one-off build. Developer comments embedded in that code are written in Russian and refer to the target using the word for 'victim' (жертва); one comment specifically documents a UX fix where dark-themed fake windows used to flash white while loading, so the kit now pre-fetches the correct theme color in advance to eliminate the flicker — the kind of maintenance-driven detail that points to an actively developed, reused toolkit rather than a single disposable page.
Because the page only harvests Google credentials — rather than delivering malware — the practical impact depends entirely on what a compromised Google account exposes: email, stored documents, password-reset messages for other linked services, and, per the source reporting, any Claude account a victim has connected via 'Sign in with Google.' That linkage matters given Anthropic's own September 1, 2026 disclosure that infostealer malware (harvesting active browser session cookies rather than passwords) has separately been used to hijack Claude accounts and consume victims' paid usage allowances — a related but mechanically distinct threat to the same asset class (Claude account access) that underscores why identity-provider credential theft is a live concern for Claude subscribers specifically.
This campaign is one data point in a broader wave of Claude/Anthropic brand abuse through 2026: a separate April 2026 Malwarebytes report documented a trojanized Claude desktop installer ('Claude-Pro-windows-x64.zip') that sideloaded PlugX malware via a signed G DATA antivirus updater binary, and a May 2026 BforeAI domain-monitoring report counted 3,188 domains registered to exploit the Claude and 'Mythos' brands in just the six weeks following Anthropic's Mythos product announcement, spanning fake AI security scanners, fake developer tooling, and underground AI-account resale sites. No specific threat actor or group name is attributed to this BITB/Google-credential campaign in the primary source; the Russian-language code comments are a linguistic artifact of the phishing kit's origin, not a formal attribution claim, and no domains, IP addresses, or file hashes were disclosed for this specific campaign.
MITRE ATT&CK techniques used in TL-2026-2626
Defense Evasion
T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1622 Debugger Evasion; T1684.001 Impersonation
Credential Access
Initial Access
T1078.004 Cloud Accounts; T1566.002 Spearphishing Link
Collection
T1114.002 Remote Email Collection; T1530 Data from Cloud Storage
Execution
Resource Development
Affected products and versions in Fake Claude Max Giveaway Phishing Campaign Uses
- Anthropic — Claude Max subscription (brand impersonated by the phishing lure)
Vulnerable versions: Not applicable — social-engineering/credential-phishing threat, no Anthropic software or service version is vulnerable
Fixed in: Not applicable - Google — Google Account sign-in / OAuth (identity provider UI spoofed via BITB)
Vulnerable versions: Not applicable — the phishing page spoofs Google's sign-in UI client-side; no Google software or service version is vulnerable
Fixed in: Not applicable
Remediation for Fake Claude Max Giveaway Phishing Campaign Uses
Immediate actions
- Verify that any 'Google sign-in' popup is a true separate OS window and not an element trapped inside the browser tab — try dragging it fully off the visible webpage; if it cannot leave the page, it is fake.
- Check that the actual browser address bar (not a bar drawn inside the page) shows accounts.google.com before entering any Google credentials.
- Treat 'free Claude Max' giveaway offers, artificial countdown counters, and 'limited slots remaining' language as illegitimate — Anthropic does not run this type of promotion through third-party landing pages.
- Configure password managers to refuse auto-fill on any domain that is not the identity provider's real domain; a manager that stays silent on a fake Google popup is itself a phishing indicator.
Workarounds
- Avoid Apple/Google sign-in prompts on any unsolicited 'Claude Max giveaway' page; navigate to claude.ai directly instead of through a promotional link.
- Use a tool such as Malwarebytes Scam Guard to evaluate a suspicious subscription-giveaway offer before interacting with it.
Longer-term hardening
- Deploy browser-level anti-phishing/anti-scam protection (e.g., Malwarebytes Browser Guard or equivalent) that blocks known phishing and scam domains before the page renders.
- Enforce phishing-resistant authentication (FIDO2/WebAuthn hardware security keys) for Google Workspace and other SSO-linked accounts so a harvested password or verification step alone cannot complete an account takeover.
- Extend security-awareness training to explicitly cover Browser-in-the-Browser popups, since the technique is now reused across unrelated brands (Google here, Microsoft 365 in the June 2026 Unit 42 campaign) and defeats the traditional 'check the URL' advice.
- Monitor for suspicious sign-ins to Google Workspace or linked SaaS accounts (e.g., Claude accounts connected via 'Sign in with Google') following any reported exposure to a Claude/Anthropic-themed giveaway page.
Weaknesses (CWE) in Fake Claude Max Giveaway Phishing Campaign Uses
CWE-451
Timeline of Fake Claude Max Giveaway Phishing Campaign Uses
- Security researcher mr.d0x publicly discloses the Browser-in-the-Browser (BITB) phishing technique with ready-to-use HTML/CSS templates, the foundational fake-popup methodology this campaign's Google sign-in spoof implements.
- Malwarebytes reports a separate fake Claude Pro download site distributing a trojanized installer that sideloads PlugX malware via a signed G DATA antivirus updater binary — a mechanically different but brand-adjacent Claude-impersonation campaign.
- BforeAI reports 3,188 domains registered to exploit the Claude and Anthropic 'Mythos' brands in the six weeks following Anthropic's Mythos announcement, illustrating the scale of Claude-brand abuse this campaign is part of.
- Palo Alto Networks Unit 42 publishes a closely related Browser-in-the-Browser campaign using OS/browser-fingerprinted fake popups, console-disabling anti-analysis code, and bot-redirection logic to steal Microsoft 365 credentials, sharing the same BITB technique family as this Claude Max campaign.
- Anthropic and Malwarebytes disclose that infostealer malware is separately hijacking active Claude browser sessions to consume victims' paid usage allowances, establishing why compromise of a Google account linked to Claude is a live concern for subscribers.
- Malwarebytes discloses the fake Claude Max giveaway page and its embedded Browser-in-the-Browser Google credential-phishing flow, including the Russian-language developer comments found in the widget's code.
Sources cited for Fake Claude Max Giveaway Phishing Campaign Uses
- Fake Claude Max giveaway hides a Google account phishing trap
- New Browser-in-the-Browser phishing uses fake login popups to steal Microsoft 365 credentials
- Infostealers are hijacking Claude accounts at users' expense
- Fake Claude site installs malware that gives attackers access to your computer
- Anthropic Mythos Phishing Domains: How Threat Actors Are Exploiting the Claude Brand (2026)
- This browser-in-the-browser attack is perfect for phishing
More in phishing
- Fake Claude Max Giveaway Phishing Campaign Uses Browser-in-the-Browser to Steal Google Credentials
- Large-Scale Azure-Hosted Tech Support Scam Campaign Targets Japan (13.38M Emails, 240K+ Relay IPs, 33K+ Disposable Azure Blob Storage Sites)
- Phishing Campaign Impersonates ChatGPT Subscription Billing Alerts to Steal OpenAI Credentials via Google API Open-Redirect and nxcli.io Infrastructure
- Global Fake Parcel Delivery Phishing/Smishing Campaign Steals Card and Bank Details
- Fake myGov 'Secure Message' Phishing Scam Targets Australians with Multi-Step Identity Harvesting Flow
Detection coverage for TL-2026-2626
As of 2026-09-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2626 across Splunk SPL, Microsoft KQL and Sigma, covering 5 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.