Fake Claude App and Alert Apps Drive New Scams

The Hacker News · Medium sophistication
Last updated July 30, 2026

This roundup describes multiple real-world campaigns where attackers trick people into installing malicious software that looks legitimate (a fake Claude desktop app, a fake emergency alert app, and banking-malware phishing). The common pattern is “looks normal, feels urgent,” leading users to click, download, or install, and then the malware steals data or enables surveillance.

How the attacks worked

These campaigns share a simple pattern: make something look normal, add urgency, and let the victim do the work of infecting their own device. In one case, a malvertising campaign redirected users to a malicious artifact hosted on the legitimate claude.ai domain, then pushed them to an attacker-controlled site to download what appeared to be a Claude desktop app. The executable actually installed SectopRAT. At least 29 organizations were affected.

A separate campaign targeted Portuguese users with phishing emails impersonating financial and administrative communications. These messages carried ZIP attachments containing heavily obfuscated HTML files, which retrieved additional scripts from attacker infrastructure to deliver the Lampion banking malware.

A third campaign used an Android app masquerading as a Bahraini Civil Defense "BH Alert" siren app. It was distributed through look-alike domains that clone the Google Play Store and official government sites, relying on social engineering and abuse of legitimate Android permissions to embed malware called OctagonPanel. Related Iran-nexus activity used fake VPN and media-tool apps to distribute MarkiRAT for surveillance.

Why these lures succeeded

Each case exploited trust in something familiar: a well-known AI product, a routine finance email, or a public-safety brand. Because the delivery mechanisms (a legitimate-looking domain, a ZIP with a document inside, an official-sounding app) matched normal expectations, targets had little reason to pause before downloading, opening, or installing.

What to watch for

  • Unexpected software downloads triggered by ads, redirects, or web content rather than an official app store or vendor page
  • ZIP attachments in routine finance or admin emails, especially ones containing HTML files instead of standard documents
  • Mobile apps distributed through look-alike domains rather than official stores, particularly those requesting permissions that don't match their stated purpose
  • Branding that mimics trusted names, whether an AI company, a bank, or a government safety agency

Building resistance

Organizations can reduce exposure by reinforcing a few habits across employees, IT, finance, and mobile users:

  • Install software only through approved channels, never from ad redirects or unfamiliar download prompts
  • Treat ZIP attachments containing HTML files as suspicious, particularly in unsolicited financial or administrative emails
  • Verify the source and developer of any "official" or "alert" app before installing it or granting permissions
  • Remind staff that convincing branding, including from well-known products or public-safety agencies, does not guarantee legitimacy

Key findings

  • Portuguese users were targeted with phishing emails impersonating financial/administrative communications to deliver Lampion banking malware via ZIP files containing obfuscated HTML.
  • At least 29 organizations were hit by a malvertising campaign that redirected users to a malicious Claude Artifact hosted on the legitimate claude.ai domain, leading to a fake “Claude desktop app” download and RAT infection.
  • An Android app impersonating Bahrain Civil Defense “BH Alert” was distributed via look-alike domains and used social engineering to get permissions, then collected sensitive data including SMS/one-time codes and screenshots.
  • Iran-nexus activity also used fake VPN and media-tool Android apps as lures to distribute MarkiRAT for surveillance.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance and Accounting, IT and Helpdesk, Executives, Mobile device users, Procurement / Software request approvers.
  • Affected industries: Technology / Software development, General business (cross-industry), Consumers / Mobile users, Finance (banking malware victims), Government / Public safety (impersonated branding), Critical infrastructure (OT/PLC targeting mentioned).
  • Attack channels: website, email.
  • Impersonated: Claude (legitimate-looking Claude desktop app), Financial and administrative communications (unspecified sender), Bahraini Civil Defense 'BH Alert' siren app.

Red flags to watch for

  • Redirect to an attacker-controlled domain before download
  • Executable download pushed from an ad/redirect flow
  • Unexpected desktop-app install prompted by web content
  • Unexpected ZIP attachment for a routine admin/finance message
  • HTML file inside a ZIP (unusual for invoices/forms)
  • Content designed to push you into running scripts/downloads
  • App offered via look-alike domains instead of official app store pages
  • High-permission requests that don’t match an alert app’s purpose
  • Fake install animations or unusual tracking/redirect behavior
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the fake Claude desktop app infect victims?

A malvertising campaign redirected users from a malicious artifact on the legitimate claude.ai domain to an attacker-controlled site, where they downloaded an executable that looked like a Claude desktop app but actually installed SectopRAT.

What made the Portuguese phishing emails effective?

They impersonated financial and administrative communications and delivered ZIP archives containing heavily obfuscated HTML files, which then retrieved additional scripts to install the Lampion banking malware.

What is the BH Alert app and why is it dangerous?

It is a fake Android app masquerading as a Bahraini Civil Defense siren app, distributed through look-alike domains that clone the Google Play Store and official government sites, and it uses social engineering and abused permissions to embed the OctagonPanel malware.

Were similar tactics used elsewhere?

Yes, Iran-nexus activity used fake VPN and media-tool Android apps as lures to distribute MarkiRAT for surveillance purposes.

Read the video transcript

You click a Claude ad, land on claude.ai, and still end up installing malware. How? At least 29 orgs hit this malvertising trap: a malicious Claude Artifact on claude.ai silently redirects you to an attacker-controlled site, pushes ClaudeDesktop.exe, and actually drops SectopRAT. Same playbook in email: a 'finance' message with a ZIP, inside it an HTML ‘document’ that runs scripts and pulls Lampion banking malware. Or a fake BH Alert app from a look‑alike site that grabs your SMS codes and screenshots. Here’s the move: if a download or app install starts from an ad, redirect, ZIP, or look‑alike site, stop, close it, and get the software only from our official company portal or the real app store.

Similar attacks

Hotel Wi‑Fi Hijack Pushes Fake Updates & Phishing

Hotel Wi‑Fi Hijack Pushes Fake Updates & Phishing

Microsoft reported a campaign where attackers abused hotel Wi‑Fi captive portals to manipulate DNS/HTTP traffic and redirect people to attacker-controlled phishing pages. Victims were tricked into installing malware disguised as browser/operating system updates, and some pages redirected users into…

August 3, 2026
Korea Flags Job-Offer Phish + Watering Holes

Korea Flags Job-Offer Phish + Watering Holes

South Korean agencies warned that a state-backed hacking group is actively targeting citizens and businesses using job-themed phishing emails and “watering hole” attacks on legitimate websites. The phishing lures include fake job applicants sending resume links and impersonated recruiters sending…

July 31, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
“TTF Trap” Uses Fake Font Files to Drop Malware

“TTF Trap” Uses Fake Font Files to Drop Malware

FortiGuard Labs reports an active phishing operation (“TTF Trap”) where emails posing as invoices, shipping documents, or business proposals deliver an archive that ultimately runs malware on Windows. The trick is a file ending in .ttf (TrueType font) that is actually a malicious script executed by…

July 17, 2026
Fake Bank of America Email Pushes Hidden ScreenConnect

Fake Bank of America Email Pushes Hidden ScreenConnect

Attackers are impersonating Bank of America in mass phishing emails to pressure people into clicking a link “to avoid account restrictions.” Mac users are led to a fake login page that steals credentials and personal/financial data, while Windows users are tricked into installing a ScreenConnect…

August 5, 2026
Hackers Hijack Hotel Wi‑Fi to Steal M365 Logins

Hackers Hijack Hotel Wi‑Fi to Steal M365 Logins

Microsoft and ReliaQuest report a real campaign where Russian-linked hackers compromised hotel Wi‑Fi networks and redirected travelers to fake Microsoft login pages or fake update screens. The goal was to steal Microsoft 365 credentials and/or trick victims into installing espionage malware,…

August 3, 2026