
APT Lures Shift to Jobs, Code Reviews, Cloud Apps
This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and…
Investigators found evidence of a China-linked operation (tracked as JadeProx) targeting government, healthcare, and education organizations, including spear-phishing and a fake software download site. One campaign impersonated Anthropic’s Claude using a lookalike domain to deliver a malicious Windows installer, while another used a decoy “account statement” document to lure victims.
Group-IB attributed a set of intrusions to a China-nexus cluster it tracks as JadeProx, based on artifacts recovered from an exposed Alibaba Cloud server. That server reportedly held phishing packages, post-exploitation tools, and a spear-phishing package addressed to the National Congress of Honduras, indicating the operation ran multiple lure types in parallel.
One track impersonated Anthropic's Claude software using the lookalike domain claude-pro[.]com. Victims who downloaded the installer were served a malicious MSI file that, once past a UAC prompt, placed a sideloading chain in the Windows Startup folder for persistence. Sophos assessed that the fake Claude site was likely part of an active malvertising campaign, meaning victims could have arrived through search ads or promoted links rather than direct outreach.
A second track used email. One spear-phishing archive carried a fake beverage-company account statement as the decoy, aimed at finance and accounts-payable style targets rather than technical staff.
Both lures relied on familiar, low-friction moments. A software download page looks like countless legitimate vendor pages, and an account statement is a routine document that finance staff expect to receive. Neither requires the target to notice anything unusual until a technical step, like a UAC prompt or an archive extraction, is already underway.
The use of a lookalike domain for a well-known AI product also matters. Employees searching for a product download are primed to trust the first plausible-looking result, especially if the site design mirrors the real one.
Organizations across government, healthcare, and education can reduce exposure by limiting software installs to approved sources such as an internal software portal, training staff to pause on unexpected UAC prompts, and treating unfamiliar account statements or invoices as verification tasks rather than routine paperwork. Blocking known indicators tied to this cluster, including the domains referenced in reporting, is also a practical step for security operations teams reviewing this activity.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
JadeProx is a China-nexus activity cluster tracked by Group-IB, identified from artifacts on an exposed Alibaba Cloud server, and linked to spear-phishing and fake software download campaigns.
Attackers registered a lookalike domain, claude-pro[.]com, and served a malicious MSI installer that, after a UAC prompt, placed a sideloading chain in the Windows Startup folder for persistence.
A separate spear-phishing archive used a fake beverage-company account statement as the decoy document.
Unexpected UAC prompts during software installs, downloads from lookalike domains instead of official vendor sites, and unsolicited account statement attachments sent as compressed archives.
You Google “Download Claude software,” click the top result, and it looks legit… but it’s actually claude-pro dot com. This is a JadeProx campaign. The fake Claude site at claude-pro dot com serves a malicious MSI. You click install, get a UAC pop-up, and it quietly drops itself into your Windows Startup folder and phones home to license dot claude-pro dot com. Same group also sends emails like “Account statement (see attached)” from a fake beverage company. The attachment is a compressed archive, not a normal PDF from a vendor portal, and it’s completely out of the blue. Your move: if you see claude-pro dot com or any installer popping an unexpected UAC prompt, stop right there and contact IT, do not click Allow.

This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and…

Proofpoint linked multiple real-world email campaigns to “Cruciferra,” a commercial crypter service that helps criminals hide malware from security tools. The…

Researchers report multiple real-world email phishing campaigns that used tax and government-benefit themes to trick people into downloading malware. The…

This roundup describes multiple real-world campaigns where attackers trick people into installing malicious software that looks legitimate (a fake Claude…

Researchers linked DigiCert’s April 2026 breach to a GoldenEyeDog sub-group that tricked support staff into running a malicious file delivered through a…

Researchers reported an active PhantomEnigma campaign where attackers hijacked 20+ Brazilian government websites and used them as trusted stepping-stones to…