According to Malwarebytes, a new phishing scam aims to steal login credentials by redirecting users to a fake Google sign-in page with the promise of a free Claude Max subscription. Experts shared tips on how to detect fake pages prepared with the browser-in-browser technique.
A new phishing scam reported by cybersecurity company Malwarebytes aims to seize users' Google account credentials by promising free access to Anthropic's Claude Max service, which is worth about $200. According to the company's statement, the scam lures users with the claim that 10,000 people are being given a one-month free Claude Max subscription to celebrate Anthropic reaching 100 million users.
The fake campaign claims to offer privileges such as "extended thinking" and "priority access to Sonnet with Opus, unlimited usage." However, according to Malwarebytes, this offer is completely fake and redirects users to a Google sign-in page designed to steal their login credentials. The captured information can provide access to Gmail, Google Docs, and other services linked to the Google account.
Stefan Dasic, a senior malware research engineer at Malwarebytes, stated that the fake campaign stands out from many other phishing attempts because it is visually much more convincing. According to Dasic, the page design includes real logos and colors, fabricated five-star reviews, and a long footer section that links almost entirely to Anthropic's real pages. The page also features a working counter showing how many of the fake 10,000 accounts have been "distributed."
Browser-in-Browser Technique
Users who click on the offer are redirected to a sign-in page designed to upgrade a Claude account. On the page, the Sign in with Apple option is disabled, and only the "Sign in with Google" option is offered. According to Dasic, this page uses a "browser-in-browser" technique convincing enough to deceive users who do not look carefully; a fake browser window is drawn within the current tab, complete with a lock icon and a correctly spelled Google sign-in address, and this window can even be dragged across the page.
In an interview with CNET, Dasic noted that Claude does not have its own password, which increases the risk. Users access Claude either by continuing with Google or through a login link sent to their email. Therefore, if a person's Claude account is linked to a Google account that falls victim to phishing, the attacker can reach the account through both paths.
Prevalence and Traces of the Scam
Dasic stated that it is still too early to say how widespread the scam has become and how many people it has reached. In the investigation so far, he said the site could be traced to a company registered in the United Kingdom, but the server was rented. According to Dasic, this only shows where the server was rented from, not who rented it.
Some components of the web page contain developer comments written in Russian. However, Dasic added that the language in the code alone is weak evidence and has previously been seen to be placed there for misleading purposes. Therefore, it is assessed that these comments may belong to a tool developed by someone else rather than a scammer directly connected to the campaign.
How to Recognize Fake Browser Windows
Malwarebytes shared some tips for detecting fake browser windows. One should try dragging a pop-up-style sign-in screen outside the browser; a real pop-up window cannot be trapped inside a web page. Whether the password manager fills in the text boxes is also an important indicator; if the password manager does not fill in the information, the site is most likely fake.
The authenticity of a site reached through a link can be confirmed by searching for the offer on the company's real website; in this case, the offer will not be found on Anthropic's site. The presentation of a single sign-in option also requires attention; a disabled Apple login may be a sign that the scammer is trying to lure users into a trap. Additionally, quota counters and countdowns do not prove that a site or offer is real.