Fake Claude Download Used in JadeProx Attacks

The Hacker News · High sophistication
Last updated July 30, 2026

Investigators found evidence of a China-linked operation (tracked as JadeProx) targeting government, healthcare, and education organizations, including spear-phishing and a fake software download site. One campaign impersonated Anthropic’s Claude using a lookalike domain to deliver a malicious Windows installer, while another used a decoy “account statement” document to lure victims.

How the attack worked

Group-IB attributed a set of intrusions to a China-nexus cluster it tracks as JadeProx, based on artifacts recovered from an exposed Alibaba Cloud server. That server reportedly held phishing packages, post-exploitation tools, and a spear-phishing package addressed to the National Congress of Honduras, indicating the operation ran multiple lure types in parallel.

One track impersonated Anthropic's Claude software using the lookalike domain claude-pro[.]com. Victims who downloaded the installer were served a malicious MSI file that, once past a UAC prompt, placed a sideloading chain in the Windows Startup folder for persistence. Sophos assessed that the fake Claude site was likely part of an active malvertising campaign, meaning victims could have arrived through search ads or promoted links rather than direct outreach.

A second track used email. One spear-phishing archive carried a fake beverage-company account statement as the decoy, aimed at finance and accounts-payable style targets rather than technical staff.

Why it succeeded

Both lures relied on familiar, low-friction moments. A software download page looks like countless legitimate vendor pages, and an account statement is a routine document that finance staff expect to receive. Neither requires the target to notice anything unusual until a technical step, like a UAC prompt or an archive extraction, is already underway.

The use of a lookalike domain for a well-known AI product also matters. Employees searching for a product download are primed to trust the first plausible-looking result, especially if the site design mirrors the real one.

What to watch for

  • Software downloads from domains that resemble but do not exactly match an official vendor's site
  • Unexpected UAC or admin-approval prompts during what should be a routine install
  • Unsolicited account statement or invoice-style attachments, particularly delivered as compressed archives
  • Persistence artifacts appearing in the Windows Startup folder following a recent install

Building resistance

Organizations across government, healthcare, and education can reduce exposure by limiting software installs to approved sources such as an internal software portal, training staff to pause on unexpected UAC prompts, and treating unfamiliar account statements or invoices as verification tasks rather than routine paperwork. Blocking known indicators tied to this cluster, including the domains referenced in reporting, is also a practical step for security operations teams reviewing this activity.

Key findings

  • Group-IB attributed activity to a China-nexus cluster it tracks as “JadeProx,” based on artifacts found on an exposed Alibaba Cloud server.
  • Evidence included “phishing packages” and a “spear-phishing package addressed to the National Congress of Honduras.”
  • One lure used “a fake beverage-company account statement as the decoy.”
  • Another campaign impersonated Anthropic’s Claude using “claude-pro[.]com” and “serving a malicious MSI installer” that installed persistence via the Windows Startup folder.
  • The fake Claude infrastructure included a reporting endpoint at “license[.]claude-pro[.]com.”
  • The article lists domains and an IP:port used for staging and lookalike ‘security vendor’ update sites.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance, Procurement, Healthcare operations, Government staff, IT helpdesk, IT/security operations.
  • Affected industries: Government, Healthcare, Education.
  • Attack channels: website, email.
  • Impersonated: Anthropic Claude, Beverage company (vendor/accounting).

Red flags to watch for

  • Lookalike domain (claude-pro[.]com) instead of the official vendor site
  • Unexpected UAC prompt during a routine “download”
  • Installer creates persistence by placing files in the Windows Startup folder
  • Unexpected account statement from a vendor you don’t work with
  • Attachment is an archive (compressed file) rather than a standard PDF from a known portal
  • Pressure to open/act without independent verification
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is JadeProx?

JadeProx is a China-nexus activity cluster tracked by Group-IB, identified from artifacts on an exposed Alibaba Cloud server, and linked to spear-phishing and fake software download campaigns.

How did the fake Claude download attack work?

Attackers registered a lookalike domain, claude-pro[.]com, and served a malicious MSI installer that, after a UAC prompt, placed a sideloading chain in the Windows Startup folder for persistence.

What other lure did the attackers use besides the fake Claude installer?

A separate spear-phishing archive used a fake beverage-company account statement as the decoy document.

What should defenders watch for based on this campaign?

Unexpected UAC prompts during software installs, downloads from lookalike domains instead of official vendor sites, and unsolicited account statement attachments sent as compressed archives.

Read the video transcript

You Google “Download Claude software,” click the top result, and it looks legit… but it’s actually claude-pro dot com. This is a JadeProx campaign. The fake Claude site at claude-pro dot com serves a malicious MSI. You click install, get a UAC pop-up, and it quietly drops itself into your Windows Startup folder and phones home to license dot claude-pro dot com. Same group also sends emails like “Account statement (see attached)” from a fake beverage company. The attachment is a compressed archive, not a normal PDF from a vendor portal, and it’s completely out of the blue. Your move: if you see claude-pro dot com or any installer popping an unexpected UAC prompt, stop right there and contact IT, do not click Allow.

Similar attacks