**New Phishing Scam Promises Claude Max, But Steals Your Google Credentials Instead**
A new phishing scam has been reported by Malwarebytes, a cybersecurity service, which promises a free month of Anthropic's Claude Max service to 10,000 users. However, the real intention of this scam is to steal login and password information from unsuspecting victims, potentially giving scammers access to everything in their Google accounts. This phishing scam is particularly convincing, with a carefully designed page that includes a real logo, invented reviews, and a footer with links to genuine Anthropic pages.
The scam works by claiming that Anthropic is celebrating attracting 100 million users by offering a free month of Claude Max with x20 limits. The offer includes "extended thinking" and "priority access to Opus and Sonnet, no caps," which sounds too good to be true. And it is. The page leads to a Google login page, which is designed to steal login and password information. This information can then be used to access Gmail, Google Docs, and other non-Google accounts that use your Google information.
**The Scam's Convincing Design**
The presentation of the scam is careful and convincing, even down to the real logo and colors used. The page includes a running counter showing how many of the fake 10,000 accounts have been given away. For those who fall for the scam, clicking on the offer leads to a login page to upgrade a Claude account. An Apple login option is disabled, leaving only the option to "Sign in with Google." The login page employs a browser-in-a-browser trick that makes it convincing enough to fool those who don't look carefully.
"The page draws a browser window inside the existing tab, complete with a padlock and a correctly spelled Google sign-in address," said Stefan Dasic, senior malware research engineer at Malwarebytes. "It can even be dragged around the page." The login prompt is convincing enough to fool those who don't take the time to examine the login page. This is because Claude has no password of its own: You get in either by continuing with Google or by a login link sent to your email. So if someone's Claude account is tied to the Google account that was phished, the attacker reaches it either way.
**How to Spot Fake Browser Scams**
Malwarebytes offered a few tips in its post for detecting a fake browser window:
* Examine the URL: Make sure the URL is correct and not a fake one. * Check the browser window: Look for signs of a fake browser window, such as a padlock that doesn't match the real one or a login prompt that doesn't match the real one. * Look for inconsistencies: Check for inconsistencies in the design and layout of the page. * Use a browser extension: Consider using a browser extension that can help detect phishing scams.
It's too early to tell how widespread the scam has gone or how many people it's reached. However, an investigation has traced the site to a UK-registered company, but the server is rented, "which tells us where the server was rented, not who rented it." The web page has components that contain developer-written code in Russian; it could, however, be part of a tool built by someone who isn't necessarily the scammer involved in this campaign.
In conclusion, this phishing scam is particularly convincing, with a carefully designed page that includes a real logo, invented reviews, and a footer with links to genuine Anthropic pages. To avoid falling victim to this scam, make sure to examine the URL, check the browser window, look for inconsistencies, and use a browser extension that can help detect phishing scams.