Fake Claude App and Alert Apps Drive New Scams

The Hacker News · Medium sophistication
Last updated July 30, 2026

This roundup describes multiple real-world campaigns where attackers trick people into installing malicious software that looks legitimate (a fake Claude desktop app, a fake emergency alert app, and banking-malware phishing). The common pattern is “looks normal, feels urgent,” leading users to click, download, or install, and then the malware steals data or enables surveillance.

How the attacks worked

These campaigns share a simple pattern: make something look normal, add urgency, and let the victim do the work of infecting their own device. In one case, a malvertising campaign redirected users to a malicious artifact hosted on the legitimate claude.ai domain, then pushed them to an attacker-controlled site to download what appeared to be a Claude desktop app. The executable actually installed SectopRAT. At least 29 organizations were affected.

A separate campaign targeted Portuguese users with phishing emails impersonating financial and administrative communications. These messages carried ZIP attachments containing heavily obfuscated HTML files, which retrieved additional scripts from attacker infrastructure to deliver the Lampion banking malware.

A third campaign used an Android app masquerading as a Bahraini Civil Defense "BH Alert" siren app. It was distributed through look-alike domains that clone the Google Play Store and official government sites, relying on social engineering and abuse of legitimate Android permissions to embed malware called OctagonPanel. Related Iran-nexus activity used fake VPN and media-tool apps to distribute MarkiRAT for surveillance.

Why these lures succeeded

Each case exploited trust in something familiar: a well-known AI product, a routine finance email, or a public-safety brand. Because the delivery mechanisms (a legitimate-looking domain, a ZIP with a document inside, an official-sounding app) matched normal expectations, targets had little reason to pause before downloading, opening, or installing.

What to watch for

  • Unexpected software downloads triggered by ads, redirects, or web content rather than an official app store or vendor page
  • ZIP attachments in routine finance or admin emails, especially ones containing HTML files instead of standard documents
  • Mobile apps distributed through look-alike domains rather than official stores, particularly those requesting permissions that don't match their stated purpose
  • Branding that mimics trusted names, whether an AI company, a bank, or a government safety agency

Building resistance

Organizations can reduce exposure by reinforcing a few habits across employees, IT, finance, and mobile users:

  • Install software only through approved channels, never from ad redirects or unfamiliar download prompts
  • Treat ZIP attachments containing HTML files as suspicious, particularly in unsolicited financial or administrative emails
  • Verify the source and developer of any "official" or "alert" app before installing it or granting permissions
  • Remind staff that convincing branding, including from well-known products or public-safety agencies, does not guarantee legitimacy

Key findings

  • Portuguese users were targeted with phishing emails impersonating financial/administrative communications to deliver Lampion banking malware via ZIP files containing obfuscated HTML.
  • At least 29 organizations were hit by a malvertising campaign that redirected users to a malicious Claude Artifact hosted on the legitimate claude.ai domain, leading to a fake “Claude desktop app” download and RAT infection.
  • An Android app impersonating Bahrain Civil Defense “BH Alert” was distributed via look-alike domains and used social engineering to get permissions, then collected sensitive data including SMS/one-time codes and screenshots.
  • Iran-nexus activity also used fake VPN and media-tool Android apps as lures to distribute MarkiRAT for surveillance.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance and Accounting, IT and Helpdesk, Executives, Mobile device users, Procurement / Software request approvers.
  • Affected industries: Technology / Software development, General business (cross-industry), Consumers / Mobile users, Finance (banking malware victims), Government / Public safety (impersonated branding), Critical infrastructure (OT/PLC targeting mentioned).
  • Attack channels: website, email.
  • Impersonated: Claude (legitimate-looking Claude desktop app), Financial and administrative communications (unspecified sender), Bahraini Civil Defense 'BH Alert' siren app.

Red flags to watch for

  • Redirect to an attacker-controlled domain before download
  • Executable download pushed from an ad/redirect flow
  • Unexpected desktop-app install prompted by web content
  • Unexpected ZIP attachment for a routine admin/finance message
  • HTML file inside a ZIP (unusual for invoices/forms)
  • Content designed to push you into running scripts/downloads
  • App offered via look-alike domains instead of official app store pages
  • High-permission requests that don’t match an alert app’s purpose
  • Fake install animations or unusual tracking/redirect behavior
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the fake Claude desktop app infect victims?

A malvertising campaign redirected users from a malicious artifact on the legitimate claude.ai domain to an attacker-controlled site, where they downloaded an executable that looked like a Claude desktop app but actually installed SectopRAT.

What made the Portuguese phishing emails effective?

They impersonated financial and administrative communications and delivered ZIP archives containing heavily obfuscated HTML files, which then retrieved additional scripts to install the Lampion banking malware.

What is the BH Alert app and why is it dangerous?

It is a fake Android app masquerading as a Bahraini Civil Defense siren app, distributed through look-alike domains that clone the Google Play Store and official government sites, and it uses social engineering and abused permissions to embed the OctagonPanel malware.

Were similar tactics used elsewhere?

Yes, Iran-nexus activity used fake VPN and media-tool Android apps as lures to distribute MarkiRAT for surveillance purposes.

Read the video transcript

You click a Claude ad, land on claude.ai, and still end up installing malware. How? At least 29 orgs hit this malvertising trap: a malicious Claude Artifact on claude.ai silently redirects you to an attacker-controlled site, pushes ClaudeDesktop.exe, and actually drops SectopRAT. Same playbook in email: a 'finance' message with a ZIP, inside it an HTML ‘document’ that runs scripts and pulls Lampion banking malware. Or a fake BH Alert app from a look‑alike site that grabs your SMS codes and screenshots. Here’s the move: if a download or app install starts from an ad, redirect, ZIP, or look‑alike site, stop, close it, and get the software only from our official company portal or the real app store.

Similar attacks