“Claudy Day” Flaws Allow Data Theft via Fake Claude AI Ads, Report

2026-03-18T20:51:47Z7f6a8b79f91a261284b59b5e1e5b6348205ca7572fb8fdf6f09739d6fb1e0422
.NET AOT malwareAI-service leaksAWS BedrockAgentCoreClaude AI fraudClaudy DayClickFix scamCode InterpreterDNS exfiltrationGitGuardianGitHub malwareHyrax infostealerMacSyncReddit malwareStorm-2561Vidar 2.0black-box evasiondrive mappingfake Google Adsinfostealermalicious browser/extensionssecrets leakagesocial engineeringsupply-chain

What happened

Multiple mid-March 2026 reports describe active campaigns and vulnerabilities enabling data theft and stealthy malware delivery. ‘Claudy Day’ and related Claude fraud campaigns use fake Google Ads and malicious AI extensions to phish tech professionals and seed MacSync and other malware; ClickFix scams trick Windows users into running hidden commands that map attacker-controlled drives and load malware. Threat actors (e.g., Storm-2561) are using fake Fortinet/Ivanti VPN sites to distribute the Hyrax infostealer, while Vidar 2.0 spreads via fake game cheats on GitHub and Reddit. Researchersalso

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
7f6a8b79f91a261284b59b5e1e5b6348205ca7572fb8fdf6f09739d6fb1e0422
Enrichment time
2026-03-18T20:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.