“Claudy Day” Flaws Allow Data Theft via Fake Claude AI Ads, Report
2026-03-18T20:51:47Z•7f6a8b79f91a261284b59b5e1e5b6348205ca7572fb8fdf6f09739d6fb1e0422
.NET AOT malwareAI-service leaksAWS BedrockAgentCoreClaude AI fraudClaudy DayClickFix scamCode InterpreterDNS exfiltrationGitGuardianGitHub malwareHyrax infostealerMacSyncReddit malwareStorm-2561Vidar 2.0black-box evasiondrive mappingfake Google Adsinfostealermalicious browser/extensionssecrets leakagesocial engineeringsupply-chain
What happened
Multiple mid-March 2026 reports describe active campaigns and vulnerabilities enabling data theft and stealthy malware delivery. ‘Claudy Day’ and related Claude fraud campaigns use fake Google Ads and malicious AI extensions to phish tech professionals and seed MacSync and other malware; ClickFix scams trick Windows users into running hidden commands that map attacker-controlled drives and load malware. Threat actors (e.g., Storm-2561) are using fake Fortinet/Ivanti VPN sites to distribute the Hyrax infostealer, while Vidar 2.0 spreads via fake game cheats on GitHub and Reddit. Researchersalso
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- 7f6a8b79f91a261284b59b5e1e5b6348205ca7572fb8fdf6f09739d6fb1e0422
- Enrichment time
- 2026-03-18T20:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.