> Fake Claude Max giveaway hides a Google account phishing trap
[DATE: 23/09/2026 12:45]
[LANGUAGE: EN]
Phishing follows whatever people want at the moment, and right now that includes AI subscriptions they don’t have to pay for. We recently uncovered a new variation on this theme: A fake Claude Max giveaway that uses a convincing Google sign-in window to steal login information.Claude’s paid plans start at $20 a month and cost considerably more for higher usage limits, while free accounts have stricter limits. That makes the promise of a free upgrade an attractive lure.Microsoft reported in June that it had seen a growing number of phishing, malicious advertising, and search-based campaigns impersonating services such as ChatGPT, Claude, DeepSeek and Copilot. Some claim that a payment has failed and send you to a fake checkout. Others offer an app download that installs malware. The campaign we found takes a different approach. There is no form to collect card details and no download. Instead, it offers a free upgrade and asks you to sign in with your Google account.The fake giveaway claims that only a limited number of free Claude Max subscriptions remain.What the page shows you and what it collectsThe site announces that Anthropic has passed 100 million users and is thanking people by giving away 10,000 free one-month subscriptions to Claude Max, its highest-usage plan. The presentation is careful, down to the real logo and colors, invented five-star reviews, and a long footer whose links lead almost entirely to genuine Anthropic pages. This is probably the most effective trust signal on the site, and it cost the operator nothing. A counter claims that fewer than 750 of the 10,000 slots remain, dropping by a few every several seconds. Nothing is actually being counted. The number is generated inside your browser and resets when you reload the page, so every visitor sees the same manufactured shortage. The frequently asked questions repeatedly promise that no payment details are needed. That part is true, which helps make the offer persuasive. Many people associate scams with requests for card details, and this page never asks for them.What it wants instead is your Google login. Two sign-in options appear, but only one works. The Apple button produces a pre-written notice saying that the method is temporarily unavailable. The email box discards whatever you type into it and triggers the Google button instead. Every route leads to the same place, and the prize is far bigger than the lure suggests. A Google account can provide access to email, documents, and the password-reset messages for other accounts. If you use Google to sign in to Claude, it could also give the criminals a route into your Claude account. Paid AI accounts are valuable in their own right because their usage allowances cost money. Last month, our research covered infostealers hijacking Claude accounts and using the victims’ paid allowances.The fake sign-in form steers visitors toward Google by claiming that Apple sign-in is unavailable.Why this sample is notableClicking the Google button doesn’t open a real Google sign-in window. Instead, the page draws a browser window inside the existing tab, complete with a padlock and a correctly spelled Google sign-in address. It can even be dragged around the page. The address bar, padlock, and everything inside the supposed window belong to the phishing page, not Google. It begins with a human-verification step rather than a password box, which may reassure visitors while helping to keep automated scanners away from the next stage.The page displays a fake Google verification window with a fraudulent address bar and padlock.Researchers have documented this “browser-in-the-browser” technique since 2022. Unit 42 reported a campaign in June that used draggable fake browser windows to target Microsoft 365 users.What makes this sample instructive is how little the operator had to do. The malicious functionality is loaded through a single line of code from an outside service that presents itself as a reusable sign-in widget and provides installation instructions.Comments inside the code are written in Russian and refer to the target as the victim. One explains that dark-themed fake windows used to flash white while loading, so the widget now fetches the correct color in advance to remove the flicker. The code appears to be a maintained, reusable product rather than something built for this one campaign.How to spot a fake browser windowThe design assumes you will check the wrong address bar. People have been taught to look for a padlock and the correct address on a login page, so this attack draws both inside a window that does not really exist.The only address bar that matters is the one belonging to your actual browser at the top of the screen. Throughout this process, it continues to show the phishing site’s domain.Try to drag the sign-in window beyond the edge of the webpage. A real popup is a separate browser window and can be moved anywhere on your screen. A fake one is trapped inside the page that created it and stops at its edge. It takes two seconds and is the most reliable test a non-technical user has.Let your password manager decide. It checks the real web address rather than what the page displays. It should not offer to fill your Google password on a site that does not belong to Google. If it stays silent where it normally fills, believe it over your own eyes.Don’t arrive through links. If a promotion is real, you should also be able to find it on the company’s own site. Type the address or use a bookmark and look for the offer there.Treat countdowns and slot counters as decoration. Any page can show a number falling toward zero. It does not prove that an offer is limited.Be suspicious when only one sign-in option works. Claiming that one provider is temporarily unavailable can steer everyone toward the path the attacker built.If you already signed in, secure the account. Change your password through the provider’s real website, sign out of all other sessions, and review connected apps and unfamiliar devices. Closing the tab does not undo a login.How Malwarebytes helpsMalwarebytes Browser Guard blocks phishing and scam domains before the page can load. In an attack like this, once the page is open, the criminals control nearly every visual cue you would normally use to judge whether it’s legitimate. If you’ve been sent an offer and you’re unsure, Scam Guard can assess it before you engage and advise you on what to do next.“One of the best cybersecurity suites on the planet.” According to CNET. Read their review →