VYPR
researchPublished Sep 23, 2026· 2 sources

Fake Claude Max Giveaway Uses 'Browser-in-the-Browser' Tactic to Steal Google Credentials

A deceptive giveaway campaign impersonating Anthropic's Claude Max AI service employs a sophisticated 'browser-in-the-browser' technique to trick users into surrendering their Google account credentials.

Cybercriminals are leveraging the current public fascination with advanced AI services to lure unsuspecting users into phishing attacks. A recent campaign, identified by Malwarebytes researchers, is impersonating Anthropic's popular Claude Max AI to distribute a fake giveaway. The attackers are not seeking direct payment information but are instead targeting users' Google account credentials, a far more valuable prize for malicious actors.

The campaign capitalizes on the perceived value of premium AI services. Claude Max, Anthropic's paid tier, offers enhanced capabilities and higher usage limits compared to its free counterpart. By promising a free upgrade to this premium service, the attackers create an enticing offer that bypasses the typical skepticism associated with requests for financial details. This psychological manipulation is further amplified by a sense of urgency, with a countdown timer and a dwindling number of "available slots" designed to pressure users into acting quickly.

The phishing page meticulously mimics Claude's branding, complete with its logo, color scheme, and even fabricated user reviews. To enhance its legitimacy, the footer of the fake site includes links to genuine Anthropic web pages. The attackers also employ a deceptive FAQ section that explicitly states no payment details are required, further disarming potential victims who might otherwise be wary of such offers. This careful construction aims to build trust before the critical credential harvesting step.

The core of the attack lies in a sophisticated social engineering technique known as "browser-in-the-browser" (BiB). Instead of redirecting users to a genuine Google sign-in page, the attackers use JavaScript to render a fake, draggable browser window directly within the phishing page. This window displays a convincing replica of a Google sign-in interface, complete with a padlock icon and a legitimate-looking URL, making it appear as if the user is interacting with Google's own authentication system.

This BiB technique is not entirely new, having been observed in previous campaigns targeting services like Microsoft 365. However, its application here highlights the evolving tactics of phishing operations. The attackers have streamlined the process by embedding a single line of code from an external service that provides a reusable sign-in widget. Comments within the code, written in Russian, suggest that this widget is a maintained product, indicating a potentially wider use beyond this specific Claude giveaway campaign.

Once a user attempts to log in via the fake Google prompt, they are first presented with a "human verification" step. This may serve to reassure users that the process is legitimate or to deter automated scanning tools from reaching the credential harvesting stage. Following this, the attackers capture the entered Google username and password. The attackers also appear to have engineered the sign-in form to exclusively push users towards the Google login, disabling other options like signing in with Apple or direct email entry.

The compromise of a Google account grants attackers significant access. Beyond the immediate ability to log into the fake Claude service, a compromised Google account can provide access to the victim's emails, cloud documents, and crucially, password reset emails for other online services. This makes Google credentials a highly sought-after target for cybercriminals seeking to expand their reach and compromise multiple accounts.

This campaign underscores the persistent threat of credential theft, especially as threat actors increasingly leverage current trends and sophisticated techniques. The use of AI service impersonation, combined with advanced phishing methods like BiB, demonstrates the need for enhanced user awareness and robust security measures to protect against evolving online threats.

This new report from Malwarebytes Labs provides further technical details on the 'browser-in-the-browser' technique used in the fake Claude Max giveaway. It highlights that the malicious functionality is loaded via a single line of code from an external service, suggesting a reusable, maintained product rather than a one-off campaign. The article also offers practical advice for users on how to detect fake browser windows, emphasizing checking the actual browser's address bar and using password managers.

Synthesized by Vypr AI