Skip to content

Security2 publishers2 min readPublished

Fake Claude Max giveaway harvests Google logins through a window it draws itself

Malwarebytes found a page promising 10,000 free months of Claude Max that skips the card and collects Google logins through a fake browser window loaded from a rented, actively maintained widget.

The Watch · Security desk

Photograph accompanying Fake Claude Max giveaway harvests Google logins through a window it draws itself
Photo: malwarebytes.com

What happened

  • Malwarebytes found a phishing site claiming Anthropic has passed 100 million users and is thanking them with 10,000 free one-month subscriptions to Claude Max, its highest-usage plan.
  • Nothing on the page asks for a card or pushes a download. Of its sign-in options only Google works: the Apple button reports itself temporarily unavailable, and the email box silently triggers Google.
  • Clicking the Google button draws a browser window inside the existing tab, complete with a padlock and a correctly spelled Google sign-in address. The visitor can drag it around the page.
  • The malicious functionality loads through a single line of code pulled from an outside service that presents itself as a reusable sign-in widget and supplies installation instructions.
  • The fake window opens on a human verification step instead of a password box, which Malwarebytes said may reassure visitors while keeping automated scanners away from the next stage.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure One captured Google password reaches the victim's mail and documents plus the password-reset messages for their other services. Where Google is the Claude login, the paid AI account goes with it.
  • capability A rented widget puts a convincing Google login inside any landing page for one line of code. The operator borrows all of it and needs no browser bug.
  • constraint The padlock-and-address check users have been trained to perform fails against chrome the page draws itself. Only the browser's own address bar, at the top of the screen, reports the real domain.
  • precedent Unit 42 saw draggable fake windows aimed at Microsoft 365 in June. The brand inside the window is a setting the operator picks.

Comments in the widget's code are written in Russian and refer to the target as the victim [9]. One of them explains that dark-themed fake windows used to flash white while loading, so the component now fetches the correct color in advance [10]. "The code appears to be a maintained, reusable product rather than something built for this one campaign," said Stefan Dasic, the Malwarebytes researcher who analyzed the campaign [11][2].

Researchers have documented the browser-in-the-browser trick since 2022 [12]. The AI-subscription fraud Microsoft described in June ran cruder plays: pages claiming a payment had failed and pushing visitors to a fake checkout, and app downloads that installed malware, in campaigns impersonating ChatGPT, Claude, DeepSeek and Copilot [14].

The page copies Claude's logo and colors, invents five-star reviews, and carries a long footer whose links lead almost entirely to genuine Anthropic pages. That footer cost the operator nothing, and Malwarebytes calls it probably the most effective trust signal on the site [18].

Malwarebytes recorded fewer than 750 of the 10,000 slots left [19]. Help Net Security, writing up the same research, recorded fewer than 760 [20]. Both figures are right, because the counter is generated inside the visitor's browser and resets on reload, so each visitor can see a different number [19][21].

The advertised prize is thin. Claude's paid plans start at $20 a month and cost considerably more at higher usage limits, and Max is the highest-usage plan [16][3]; 10,000 one-month seats at the $20 entry price works out to $200,000 of giveaway [24]. The FAQ's repeated promise that no card is needed is accurate, and Dasic said that is part of why it works: "That part is true, which helps make the offer persuasive. Many people associate scams with requests for card details, and this page never asks for them" [17].

Malwarebytes did not disclose how visitors reach the page or how many signed in [25]. The resale side of a stolen paid account is already on the record: last month the same team reported infostealers hijacking Claude accounts and spending the victims' paid allowances [22].

What to watch

  • Whether the same sign-in widget turns up branded for Microsoft 365, Okta or Google Workspace logins.
  • Whether anyone publishes the widget service's domains, so the single line of code can be blocked at DNS.
  • Whether the human-verification first stage keeps the credential page out of URL reputation feeds long enough to survive takedown.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories