
Fake Advisors, ClickFix, and Chrome Sync Spying
This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…
This roundup describes multiple real-world campaigns where attackers trick people into installing malicious software that looks legitimate (a fake Claude desktop app, a fake emergency alert app, and banking-malware phishing). The common pattern is “looks normal, feels urgent,” leading users to click, download, or install, and then the malware steals data or enables surveillance.
These campaigns share a simple pattern: make something look normal, add urgency, and let the victim do the work of infecting their own device. In one case, a malvertising campaign redirected users to a malicious artifact hosted on the legitimate claude.ai domain, then pushed them to an attacker-controlled site to download what appeared to be a Claude desktop app. The executable actually installed SectopRAT. At least 29 organizations were affected.
A separate campaign targeted Portuguese users with phishing emails impersonating financial and administrative communications. These messages carried ZIP attachments containing heavily obfuscated HTML files, which retrieved additional scripts from attacker infrastructure to deliver the Lampion banking malware.
A third campaign used an Android app masquerading as a Bahraini Civil Defense "BH Alert" siren app. It was distributed through look-alike domains that clone the Google Play Store and official government sites, relying on social engineering and abuse of legitimate Android permissions to embed malware called OctagonPanel. Related Iran-nexus activity used fake VPN and media-tool apps to distribute MarkiRAT for surveillance.
Each case exploited trust in something familiar: a well-known AI product, a routine finance email, or a public-safety brand. Because the delivery mechanisms (a legitimate-looking domain, a ZIP with a document inside, an official-sounding app) matched normal expectations, targets had little reason to pause before downloading, opening, or installing.
Organizations can reduce exposure by reinforcing a few habits across employees, IT, finance, and mobile users:
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
A malvertising campaign redirected users from a malicious artifact on the legitimate claude.ai domain to an attacker-controlled site, where they downloaded an executable that looked like a Claude desktop app but actually installed SectopRAT.
They impersonated financial and administrative communications and delivered ZIP archives containing heavily obfuscated HTML files, which then retrieved additional scripts to install the Lampion banking malware.
It is a fake Android app masquerading as a Bahraini Civil Defense siren app, distributed through look-alike domains that clone the Google Play Store and official government sites, and it uses social engineering and abused permissions to embed the OctagonPanel malware.
Yes, Iran-nexus activity used fake VPN and media-tool Android apps as lures to distribute MarkiRAT for surveillance purposes.
You click a Claude ad, land on claude.ai, and still end up installing malware. How? At least 29 orgs hit this malvertising trap: a malicious Claude Artifact on claude.ai silently redirects you to an attacker-controlled site, pushes ClaudeDesktop.exe, and actually drops SectopRAT. Same playbook in email: a 'finance' message with a ZIP, inside it an HTML ‘document’ that runs scripts and pulls Lampion banking malware. Or a fake BH Alert app from a look‑alike site that grabs your SMS codes and screenshots. Here’s the move: if a download or app install starts from an ad, redirect, ZIP, or look‑alike site, stop, close it, and get the software only from our official company portal or the real app store.

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

ClickFix is a fast-growing social engineering tactic that gets people to run malware themselves by pasting a command into Windows Run or macOS Terminal.…

FortiGuard Labs reports an active phishing operation (“TTF Trap”) where emails posing as invoices, shipping documents, or business proposals deliver an archive…

This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and…

Researchers linked DigiCert’s April 2026 breach to a GoldenEyeDog sub-group that tricked support staff into running a malicious file delivered through a…

Kaspersky reports an active OkoBot malware campaign targeting Windows users who manage cryptocurrency. Victims are lured via “ClickFix” fake-error pages that…