TI Mindmap HUB
Threat Intelligence Report

InstallFix and Claude Code: How Fake Install Pages Lead to Real Compromise

๐Ÿ“… May 23, 2026 ๐Ÿ“ฐ www.trendmicro.com ๐Ÿ” 0 CVE(s) referenced

The InstallFix campaign exploits trust in AI platforms by distributing sophisticated, multi-stage malware through fake Claude AI installer pages promoted via Google Ads, enabling attackers to steal data, disable security controls, and maintain persistent access across global industries.

vendor

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

๐Ÿ” Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

๐Ÿ“Š Visual Mindmap
๐ŸŽฏ IOC Extraction
โš”๏ธ MITRE ATT&CK TTPs
๐Ÿ“ฆ STIX 2.1 Bundle