Trojanized Gemini and Claude Installers Target Developers Via SEO Poisoning

2026-05-26T20:51:41Z25e7e2d98be9317134285177047c3a81db57d79e74d189d4c07bcff52f815797
api-keysasus-routersbotnetbulletproof-hostingcloud-credentialscredential-theftdata-breachfileless-malwareinfostealerlaw-enforcementmfa-bypassphishingrouter-exploitationseo-poisoningsupply-chain-attackthreat-actor-marketplacevpn-seizurevulnerability-discovery

What happened

Multiple active threats and law-enforcement actions affecting developers, cloud credentials, consumer data, and infrastructure: SEO-poisoned fake Gemini/Claude installer sites are delivering fileless malware to developers to exfiltrate data; Anthropic’s Claude Mythos reportedly found 10,000+ software vulnerabilities (including critical flaws) in one month; a ClickFix macOS infostealer compromised a retail site tied to an FBI official; Dutch authorities dismantled a bulletproof hosting service used for disinformation and cybercrime; a threat actor is selling a 340M OnlyFans aggregate dataset; R

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
25e7e2d98be9317134285177047c3a81db57d79e74d189d4c07bcff52f815797
Enrichment time
2026-05-26T20:51:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Trojanized Gemini and Claude Installers Target Developers Via SEO Poisoning · Baitaphish