Trojanized Gemini and Claude Installers Target Developers Via SEO Poisoning
2026-05-26T20:51:41Z•25e7e2d98be9317134285177047c3a81db57d79e74d189d4c07bcff52f815797
api-keysasus-routersbotnetbulletproof-hostingcloud-credentialscredential-theftdata-breachfileless-malwareinfostealerlaw-enforcementmfa-bypassphishingrouter-exploitationseo-poisoningsupply-chain-attackthreat-actor-marketplacevpn-seizurevulnerability-discovery
What happened
Multiple active threats and law-enforcement actions affecting developers, cloud credentials, consumer data, and infrastructure: SEO-poisoned fake Gemini/Claude installer sites are delivering fileless malware to developers to exfiltrate data; Anthropic’s Claude Mythos reportedly found 10,000+ software vulnerabilities (including critical flaws) in one month; a ClickFix macOS infostealer compromised a retail site tied to an FBI official; Dutch authorities dismantled a bulletproof hosting service used for disinformation and cybercrime; a threat actor is selling a 340M OnlyFans aggregate dataset; R
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- 25e7e2d98be9317134285177047c3a81db57d79e74d189d4c07bcff52f815797
- Enrichment time
- 2026-05-26T20:51:41Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.