P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

A fake Claude Max giveaway harvests Google logins: the pretext is new, the phishing is not

Malwarebytes has documented a phishing site that offers free Claude Max subscriptions and draws a fake Google sign-in window inside the tab. The technique is twenty years old. The lure, an AI subscription people cannot get, is the part that is new.

By Parminder Kumar Sharma · · 18 min read

Editorial illustration for the briefing: A fake Claude Max giveaway harvests Google logins: the pretext is new, the phishing is not

The only precise number on the page is fiction

The fake Claude Max giveaway documented by Malwarebytes on 23 September 2026 carries exactly one figure precise enough to look like evidence. A counter tells the visitor that fewer than 750 of 10,000 free subscriptions remain. Do the arithmetic the page invites you to do and you get 9,250 claimed, or 92.5 per cent gone, with the number ticking down by a few every several seconds while you read.

None of it is counted. The researcher, Stefan Dasic, found that the number is generated inside the visitor's own browser and resets when the page is reloaded, so every visitor sees the same manufactured shortage. The most persuasive quantity in the campaign is a local variable.

That matters beyond the joke, because it is the only quantity anyone has published about this campaign at all. The write-up gives no victim count, no number of domains, no indicators, no hashes and no campaign name. It is a careful description of one page, by one researcher, on one day. Everything else you may read about it is inference, including some of the inference printed as fact elsewhere this week.

What the research establishes, and what it does not

The observable part needs stating precisely, because the practical advice depends on which step you are trying to interrupt.

The landing page claims Anthropic has passed 100 million users and is thanking people with 10,000 free one-month subscriptions to Claude Max, its highest-usage plan. The presentation is careful: the real logo and colours, invented five-star reviews, and a long footer whose links lead almost entirely to genuine Anthropic pages. That footer is the cheapest and most effective trust signal on the site, because it is largely true.

The frequently asked questions insist repeatedly that no payment details are needed. Dasic's observation about that is the sharpest line in the write-up: "That part is true, which helps make the offer persuasive." Many people have been trained to equate fraud with a request for card details, and this page never makes one.

What it wants is a Google login. Two sign-in options appear and only one works. The Apple button returns a pre-written notice that the method is temporarily unavailable. The email box discards whatever is typed into it and triggers the Google button instead. Every route ends in the same place.

Clicking that button does not open a Google sign-in window. The page draws a browser window inside the existing tab, complete with a padlock and a correctly spelled Google address, and the drawn window can be dragged around the page. It opens on a human-verification step rather than a password box, which Dasic reads as reassuring the visitor while keeping automated scanners away from the next stage.

The most instructive finding is how little the operator built. The malicious functionality is loaded through a single line of code from an outside service that presents itself as a reusable sign-in widget and supplies installation instructions. Comments in that code are in Russian and refer to the target as the victim; one explains that dark-themed fake windows used to flash white while loading, so the widget now fetches the correct colour in advance to remove the flicker. Dasic's conclusion is that it is "a maintained, reusable product rather than something built for this one campaign".

Read against the Malwarebytes write-up of 23 September 2026. The right-hand column is silence in the source, not denial.

QuestionWhat the research establishesWhat it does not establish
Brand impersonatedAnthropic, via a Claude Max giveaway with real logo, colours and footer linksNo statement from Anthropic or Google on this campaign, and no plan tier or price is named
Credentials targetedGoogle account credentials, sought through a drawn sign-in windowWhether the accounts sought were Google Workspace or consumer Gmail
Second factorThe fake window opens on a human-verification step, not a password boxWhether anything was relayed to Google live, so whether a second factor was ever put in play
ScaleOne page, described in detailVictim count, page views, number of domains, or any indicator at all
OutcomeThe page is built to capture Google credentialsWhether a single account was actually compromised
AttributionRussian-language comments inside a third-party sign-in widgetWho operated the campaign; a widget's author is not its customer
DeliveryNothingHow victims reached the page: no email, advert, search or message vector is described

The path, and where a control can actually reach it

Set out as a sequence, the campaign has six observed steps and two ends that nobody has documented. Defences do not apply evenly across those steps. Most of what organisations buy to stop phishing sits at the arrival end, which is precisely the end this research cannot describe and, for a lure of this class, the end an employer usually does not own.

A flow diagram of the fake Claude Max giveaway. Six observed steps run from the branded landing page and its manufactured scarcity counter, through a forced fork to Google sign-in, a browser window drawn inside the tab and a human verification step, to the capture of Google credentials. Dashed boxes mark what is not stated: how visitors arrived, and what the research does not establish. A band at the foot places four controls against the steps they bite at.
Drawn from the Malwarebytes write-up of 23 September 2026. Solid boxes are observed; dashed boxes are not stated in the source. Placing the controls against the steps is this briefing's analysis.

The padlock was never the control

Browser-in-the-browser is not new. Researchers have documented it since 2022, and in June 2026 Palo Alto Networks Unit 42 described a campaign using draggable fake browser windows against Microsoft 365 users, which adapted its chrome to the victim's operating system and browser and redirected suspected scanners to a genuine Microsoft help page. Four years on, the technique still works for one reason: it attacks the advice rather than the browser.

Generations of security awareness training taught people to look for a padlock and a correctly spelled address on a login page. This attack supplies both, inside a window that does not exist. The address bar shown is a drawing. The only address bar that carries any authority is the real one at the top of the screen, and throughout the whole flow it continues to show the phishing site's domain.

This is the friendly-name fallacy in its purest form. The padlock was never a control. It was a label describing transport encryption, which any operator can obtain for nothing, and it has been meaningless as a trust signal for years. The industry kept teaching it because it was easy to teach.

The human-verification step is the second instance of the same fallacy, and it is a cleverer one. A verification challenge reads to the visitor as a security measure standing between them and the prize, which makes the page feel more legitimate rather than less. To the operator it is an evasion control, filtering automated analysis out before the credential form is ever served. One interface element, doing opposite jobs for the two parties looking at it.

There is one test that survives all of this and costs nothing: try to drag the sign-in window off the edge of the web page. A real pop-up is a separate operating system window and can go anywhere on the screen. A drawn one is trapped inside the page that created it. Dasic offers it as the most reliable check available to a non-technical user, and it is the rare piece of security advice that requires no judgement at all.

Why an AI subscription is such a good pretext

The technique here is ordinary. The pretext is the story.

Anthropic's published pricing puts Claude Pro at 20 dollars a month billed monthly, or 17 dollars a month on an annual plan billed at 200 dollars up front, and lists Max as starting from 100 dollars a month for either five times or twenty times the Pro usage. On those figures, the advertised prize of 10,000 one-month Max subscriptions represents at least a million dollars of notional value, given away by a company that would have no reason to do so and did not.

That is the shape of the lure. AI subscriptions are expensive relative to other consumer software, they are tiered by usage rather than by features so the top tier is genuinely desirable rather than a corporate upsell, access to new capability is routinely rationed by waitlist, and an enormous share of them are paid for by individuals on personal cards and personal accounts, entirely outside any procurement process. Nothing else in the current consumer landscape combines cost, scarcity and personal purchase quite so neatly.

Be blunt about who the victim is here. A person who clicks a free upgrade offer for a tool they already use, want more of, and have probably already been told to use more of at work, is not being careless. They are responding to a scarcity the industry manufactured and continues to advertise. The lure works because the underlying frustration is real.

The trend line supports treating this as a class rather than an incident. Microsoft Threat Intelligence published a report on 8 June 2026, 107 days before this write-up, documenting four separate campaigns between March and May that used AI brands as bait. One of them, running from 20 to 22 April 2026, impersonated Claude with account policy violation warnings and reached more than 2,000 organisations, 62 per cent in the United States, 18 per cent in the United Kingdom and 9 per cent in India. On those proportions that is roughly 360 British organisations in a three-day window, from one campaign. Microsoft's own framing is unambiguous: the activity is "purely abuse of AI brand names as lures", not a compromise of any vendor named.

Check Point's Q2 2026 brand phishing report, published on 23 July, recorded an AI brand entering the ten most impersonated brands for the first time. Microsoft led that list at 23 per cent. Anthropic did not appear in it, which makes this giveaway an early instance rather than a representative one.

What the coverage added that the research did not say

This story is a clean worked example of how a careful technical write-up acquires details on its way through the news cycle, because those added details are the ones a reader is most likely to repeat in a meeting.

Primary research compared with the coverage of it, all accessed 23 September 2026.

DetailIn the Malwarebytes write-upAdded downstream
Slot counterFewer than 750 of 10,000 remainHelp Net Security reports fewer than 760
Plan tierClaude Max, described as the highest-usage planDigital Trends names it a Claude Max x20 giveaway
PricePaid plans start at 20 dollars a monthDigital Trends states 200 dollars a month; Anthropic's page says Max starts from 100
DeliveryNot described at allDigital Trends states it is typically spread through malicious ads, search campaigns or phishing messages
IndicatorsNone publishedNone published anywhere, so no domain can be checked against a public abuse feed

The indicator row is the one that should bother a defender. Unit 42 published a domain list alongside its June browser-in-the-browser research. Malwarebytes published none here, and links to no sample. That is a defensible editorial choice for a consumer-facing blog describing a live scam, and it also means there is nothing to feed a block list, nothing to search in proxy logs, and no way to check whether the infrastructure is already listed in any public abuse feed. Anyone claiming to have confirmed that is working from a domain the research did not give them.

This briefing has not sought, and does not publish, the domain involved.

The impersonated party, and what it has and has not said

Neither Anthropic nor Google appears to have published anything about this specific campaign as at 23 September 2026, and the research does not report contacting either. Neither company is under any obligation to comment on every site that copies its logo.

Anthropic has, however, published on adjacent abuse of its own brand. Its September 2026 threat intelligence report describes an actor it tracks as GTG-50021 running fraudulent Claude reseller operations, where customers who believed they were buying discounted access instead had a credential harvester installed that stole their Anthropic account credentials for onward sale. The report is explicit that in the API key cases it documents, the keys were stolen from customer environments and Anthropic's own systems were not compromised. Malwarebytes separately reported earlier in September on infostealers hijacking Claude accounts to spend victims' paid usage allowances.

The pattern across all of these is the same, and it is the reason the lure class will persist: a paid AI account is now a liquid asset. It has a resale value, a usage allowance that costs real money, and in many cases it is reachable through a single consumer identity provider. That last property is what this campaign is attacking.

The gateway never sees it

Here is the operational consequence, and it is the reason this belongs in a corporate briefing rather than a consumer one.

An AI brand lure of this type lands on a personal account, on a personal device, very often outside working hours, and asks for a personal identity provider's credentials. A corporate secure email gateway does not see the message. Corporate web filtering does not see the click. Corporate endpoint protection is not on the phone. The identity being phished may not be one the organisation manages, and the compromise may never generate a single event in the organisation's own telemetry.

That does not make it someone else's problem, because the blast radius crosses back. A personal Google account routinely holds the password reset path for business services bought on a personal card, the multi-factor recovery codes somebody saved to their own Drive, documents mailed home to work on, and the single sign-on route into whatever AI tooling the person set up for themselves. The organisation inherits the consequence of a compromise it had no ability to observe.

The honest conclusion is that perimeter controls are the wrong instrument for this class, and reaching for more awareness training is only marginally better. The training in question told people to check for a padlock, and the attack draws a padlock.

Three controls that bite, and what each one does not do

Phishing-resistant authentication on the accounts that matter. A passkey or a hardware security key is bound cryptographically to the real domain. Presented with a drawn window on an attacker's site, the authenticator finds no credential registered for that origin, so there is nothing for the user to hand over and no decision for them to get wrong. The NCSC put this plainly in a paper published on 23 April 2026, five months ago: traditional multi-factor authentication, which it lists as including passwords, SMS codes, email codes, TOTP codes and push approvals, is "inherently phishable", while FIDO2 credentials are not. This is the only control in this list that removes the user's judgement from the loop entirely, which is why it is first.

The qualification is important. Adding a passkey does not help if the password and a phishable second factor remain enabled as fallbacks on the same account, and Microsoft documented a campaign in September 2026 in which attackers targeted the enrolment and cross-device registration flows rather than the cryptography. The control is not the passkey. The control is the removal of the phishable alternatives.

Watch OAuth grants to unknown applications. A stolen Google session is rarely monetised by a human logging in and reading email. It is monetised by attaching an application, because an OAuth grant survives a password change, persists without further interaction and can be sold. In Google Workspace the relevant surfaces are named, and worth finding before you need them: API controls under Security, Access and data control, where third-party applications are set to Trusted, Limited, specific scopes or Blocked, and where unconfigured applications can be blocked wholesale; and OAuth log events under Reporting, Audit and investigation, which records each time a third-party application is authorised to reach account data.

The qualification is that none of this covers the personal account the lure actually targeted. For that, the equivalent action is individual and manual: reviewing third-party access on the personal Google account and signing out of other sessions.

Make a legitimate route to AI tooling exist. This is the control that operates at step one, and it is the only one that reduces the number of people who want what the advert is offering. Unmet, unfunded demand is the fuel. If the sanctioned answer to a request for AI tooling is a six-week wait, a refusal, or silence, then a free upgrade offer is competing against nothing, and staff will keep buying access on personal cards and personal identities where the organisation can neither see it nor protect it.

This is a budget and procurement decision rather than a security one, which is precisely why it gets left out of phishing responses. It belongs in this one.

Controls mapped to the step they interrupt. The step numbers refer to the diagram above.

ControlWhere it bitesWhat it does not do
Passkey or hardware key, phishable factors removedStep 6: nothing to type into the drawn windowNothing about enrolment abuse or account recovery flows
Password manager domain matchingSteps 4 to 6: silence where it normally fillsNothing if the user overrides it and types the password manually
OAuth grant review and session revocationAfter step 6: cuts the usual route to cashing outNothing on a personal account the organisation does not administer
A funded, sanctioned route to AI toolingStep 1: removes the demand the advert exploitsNothing for anyone already phished, and nothing this quarter
Secure email gateway and web filteringNowhere in this path, on a personal deviceNothing the organisation can even record

What to do, in the order worth doing it

Take this with you

For a UK security lead reading this on 23 September 2026

  • Identify which of your business services can be reached through a personal Google or Apple identity, including anything bought on expenses. That list is the actual exposure from this lure class.
  • Enforce phishing-resistant authentication on the accounts that matter, and then remove the phishable fallbacks, because leaving SMS or push enabled leaves the phishable path open.
  • In Google Workspace, set unconfigured third-party applications to blocked under Security, Access and data control, API controls, and review the existing Trusted list against what people actually use.
  • Put OAuth log events on a schedule rather than an incident, under Reporting, Audit and investigation, and alert on first-seen third-party authorisations.
  • Write down the revocation runbook for a suspected personal account compromise: password change on the real site, sign out of all sessions, review connected applications and devices, then rotate anything that account could reset.
  • Tell staff the drag test rather than the padlock test, because a drawn window cannot leave the page that drew it and a padlock proves nothing.
  • Ask finance for the list of AI subscriptions reimbursed through expenses in the last two quarters, and treat it as a demand signal rather than a policy breach.
  • Fund a sanctioned route to AI tooling with a stated turnaround time, and publish it, so that a free upgrade advert has something legitimate to compete against.
  • Do not build detections around this specific campaign. No indicators were published, and the widget behind it is a reusable product that will reappear under other brands.

The question that exposes the gap

The interesting fact about this campaign is not that someone built a convincing fake Google window. Someone builds one of those every week, and the widget behind this one is sold as a maintained product with installation instructions, which tells you how routine the supply side has become.

The interesting fact is that the operator chose an AI subscription as the thing worth wanting, and was right. That choice will be copied, because the conditions that made it work are not a security failure at all. They are the current commercial arrangement of the AI industry: expensive tiers, rationed access, and a purchasing route that runs through individuals rather than organisations.

So the question to put to your own organisation is not whether staff would fall for a fake giveaway. It is this. How many of the AI tools your people use every day are attached to an identity you do not administer, on a device you do not manage, bought with a card you reimburse? Until you can answer that with a number, the only honest description of your exposure to this lure class is that you cannot see it.

Sources

  1. PrimaryStefan Dasic's original write-up of the fake Claude Max giveaway, read in full: the only primary account of the landing page, the scarcity counter, the forced fork to Google, the browser-in-the-browser window and the reusable widget behind itMalwarebytes ThreatLabsaccessed 2026-09-23
  2. PrimaryAnthropic's published consumer pricing, used to check the value of the advertised prize and to test the 200 dollar figure that secondary coverage attached to Max 20xAnthropicaccessed 2026-09-23
  3. PrimaryThe June 2026 report on AI brands used as social engineering bait, used for the campaign dates, volumes and target counts, and for the statement that no referenced vendor was compromisedMicrosoft Threat Intelligenceaccessed 2026-09-23
  4. PrimaryThe NCSC comparison of traditional credentials and FIDO2, used for the claim that all traditional multi-factor authentication is phishable and that FIDO2 credentials are notNational Cyber Security Centreaccessed 2026-09-23
  5. PrimaryAnthropic's September 2026 threat intelligence report, used to establish that Anthropic has published on fraudulent Claude resellers that harvest its customers' credentials, but not on this giveaway campaignAnthropicaccessed 2026-09-23
  6. PrimaryGoogle Workspace admin documentation for API controls and app access states, used for the named OAuth controls in the checklistGoogleaccessed 2026-09-23
  7. PrimaryGoogle Workspace OAuth log events documentation, used for the console path where an administrator sees third party authorisationsGoogleaccessed 2026-09-23
  8. Reported bySinisa Markovic's coverage of the Malwarebytes research, used to show where secondary reporting diverges from the primary on the slot counter figureHelp Net Securityaccessed 2026-09-23
  9. Reported byConsumer coverage that added a price, a plan tier and a delivery vector that the primary research does not state, used as the worked example of driftDigital Trendsaccessed 2026-09-23
  10. Reported byCoverage of the Unit 42 browser-in-the-browser campaign against Microsoft 365, the comparison case where indicators were published; the Unit 42 original could not be reachedHelp Net Securityaccessed 2026-09-23
  11. Reported byThe Q2 2026 brand phishing report, used for the first appearance of an AI brand in the top ten most impersonated brandsCheck Point Researchaccessed 2026-09-23

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

One email per briefing. Unsubscribe any time.