Malwarebytes Finds Fake Claude Max Giveaway Built to Steal Google Logins

The page asks for no payment details. Instead, it draws a fake browser window with a Google address and padlock that belong to the phishing site.

By 4 min read
Malwarebytes Finds Fake Claude Max Giveaway Built to Steal Google Logins
Malwarebytes Finds Fake Claude Max Giveaway Built to Steal Google Logins

Listen to this story

The audio brief

About 1:21
0:001:21
Read transcript
A supposed free month of Claude Max is being used to steal Google passwords—not payment details. Malwarebytes found a fake Anthropic giveaway that draws a Google sign-in window inside its own webpage. The address and padlock shown in that window are part of the page; the browser’s real address bar still points to the scam site. The offer claims Anthropic is giving away 10,000 subscriptions to celebrate reaching 100 million users. A countdown suggests places are running out, but Malwarebytes found it resets when the page reloads and doesn’t track real subscriptions. The sign-in choices are theater, too: Apple sign-in is unavailable, and the email field leads to the same fake Google prompt. A visitor who enters a password there hands it to the scammers. That could put more than an AI subscription at risk. A compromised Google account may expose email, documents, and password-reset messages for other services. Malwarebytes traced the fake prompt to an outside service’s reusable widget, but that does not reveal who is running this campaign. If you entered your password, the advice is to change it on Google’s real site, sign out other sessions, and check connected apps and devices. The clearest check is the browser’s actual address bar—not the convincing one inside the page. How many people saw or used the offer remains unknown, and investigators have not identified the operator.

Story brief

3 key points

Malwarebytes found that a site advertising 10,000 free Claude Max subscriptions uses a fake, in-page Google login prompt to capture credentials. The apparent Google address, padlock, and movable popup are drawn by the scam page; the browser’s real address bar still shows the site’s domain. A stolen Google account could expose email, documents, and password-reset messages, but investigators have not reported a victim...

  1. 01

    The site’s countdown resets on reload and is generated in the visitor’s browser; it does not track remaining subscriptions.

  2. 02

    Apple sign-in is unavailable, while the email field routes visitors to the same fake Google prompt.

  3. 03

    Malwarebytes traced the prompt to an outside service’s reusable widget, but that does not identify the campaign’s operator.

A free month of Claude Max is the bait; a Google password is the target. Malwarebytes has uncovered a phishing site that poses as an Anthropic giveaway and draws a convincing Google sign-in window inside its own page. The window looks separate, but entering credentials there would hand them to the scammers.

The offer is designed to look routine

The site falsely says Anthropic is celebrating 100 million users by giving 10,000 people a free month of Claude Max. It borrows Anthropic’s logo and colors, displays invented five-star reviews, and fills a long footer mostly with links to genuine Anthropic pages. Those real destinations help the fake offer look credible without making the offer real.

A counter claims that fewer than 750 subscriptions remain and ticks downward. Malwarebytes found that nothing is being counted: the number is generated in the visitor’s browser and resets when the page reloads. The site also repeatedly promises that no payment details are needed. That promise is true in a narrow sense, because this scam wants a login rather than a card number.

Every sign-in route leads to Google

Visitors appear to have choices, but the page funnels them toward one prompt. Its Apple sign-in button says it is temporarily unavailable. The email box ignores what a visitor types and triggers the Google button instead. Clicking that button does not open Google: it makes the phishing page draw a window inside the existing browser tab.

The imitation has a correctly spelled Google sign-in address and a padlock. It can even be dragged around, like a separate popup. But those details are pictures and controls supplied by the phishing site. The browser’s real address bar, at the top of the screen, still shows that site’s domain. Malwarebytes says the prompt begins with a human-verification step before showing a password box.

Why a free AI plan could cost more

The potential loss is not limited to Claude. A stolen Google login could expose email and documents, along with password-reset messages for other accounts. If someone uses Google to sign in to Claude, the same credentials could also give the attacker a route into that account. These are potential consequences of a compromised login, not a count of accounts breached in this campaign.

Electronics, Mobile Phone, Phone
Shikhar Mehrotra / Digital Trends Source: digitaltrends.com.

The fake login is not an elaborate window built solely for this giveaway. Malwarebytes found that the page loads its malicious sign-in function with a single line of code from an outside service presented as a reusable widget. That finding explains how a polished-looking prompt can be added to this site; it does not identify who operates the campaign.

Check the window, not its picture

The scam exploits a habit that normally helps: checking the address and padlock before signing in. Here, both appear inside a window the site drew. Malwarebytes recommends checking signals the page cannot draw for itself:

  • Look at the browser’s actual address bar above the page, not the address displayed inside the sign-in prompt.
  • Try dragging the supposed popup beyond the edge of the webpage. A window drawn by the site cannot leave it.
  • Notice if your password manager does not offer to fill a Google password where it normally would. It checks the real web address.
  • Visit Anthropic’s site directly to check a promotion instead of following a link to the offer.

If you already entered a password, closing the tab will not undo it. Malwarebytes advises changing the password through Google’s real site, signing out of other sessions, and reviewing connected apps and unfamiliar devices.

The campaign’s reach is still unknown

Malwarebytes researcher Stefan Dasic told CNET it was too early to say how widely the scam had spread or how many people it had reached. Investigators traced the site to a UK-registered company, but the server was rented; that trail does not identify who rented it. For now, the warning rests on the site’s observed behavior, not a known victim total or a confirmed operator.

Sources

  1. malwarebytes.comFake Claude Max giveaway hides a Google account phishing trap
  2. cnet.comNew Phishing Attack Promises Claude Max, but Steals Your Google Credentials Instead - CNET

Loading discussion...

YOUR READING SPACE

Notifications