A fake Claude Max giveaway uses a spoofed Google sign-in window to steal users’ login credentials, Malwarebytes researchers have found. “Browser-in-the-browser” is not a new technique. Researchers have documented it since 2022, and in June Palo Alto Networks’ Unit 42 reported a campaign that used draggable fake browser windows to target Microsoft 365 users.
Fake Claude Max giveaway tricks users into handing over their Google account credentials
About this summary. This is a short, independently written summary of an article first published by Help Net Security. Cyber Security News did not report or verify the underlying story. Read the original: https://www.helpnetsecurity.com/2026/09/23/fake-claude-max-giveaway-phishing/

Source attribution: headline and facts are from Help Net Security (helpnetsecurity.com). Summary method: excerpt of the source description. See our source attribution policy.






