A fake Claude Max giveaway harvests Google logins: the pretext is new, the phishing is not
Malwarebytes has documented a phishing site that offers free Claude Max subscriptions and draws a fake Google sign-in window inside the tab. The technique is twenty years old. The lure, an AI subscription people cannot get, is the part that is new.
By Parminder Kumar Sharma · · 18 min read

The only precise number on the page is fiction
The fake Claude Max giveaway documented by Malwarebytes on 23 September 2026 carries exactly one figure precise enough to look like evidence. A counter tells the visitor that fewer than 750 of 10,000 free subscriptions remain. Do the arithmetic the page invites you to do and you get 9,250 claimed, or 92.5 per cent gone, with the number ticking down by a few every several seconds while you read.
None of it is counted. The researcher, Stefan Dasic, found that the number is generated inside the visitor's own browser and resets when the page is reloaded, so every visitor sees the same manufactured shortage. The most persuasive quantity in the campaign is a local variable.
That matters beyond the joke, because it is the only quantity anyone has published about this campaign at all. The write-up gives no victim count, no number of domains, no indicators, no hashes and no campaign name. It is a careful description of one page, by one researcher, on one day. Everything else you may read about it is inference, including some of the inference printed as fact elsewhere this week.
What the research establishes, and what it does not
The observable part needs stating precisely, because the practical advice depends on which step you are trying to interrupt.
The landing page claims Anthropic has passed 100 million users and is thanking people with 10,000 free one-month subscriptions to Claude Max, its highest-usage plan. The presentation is careful: the real logo and colours, invented five-star reviews, and a long footer whose links lead almost entirely to genuine Anthropic pages. That footer is the cheapest and most effective trust signal on the site, because it is largely true.
The frequently asked questions insist repeatedly that no payment details are needed. Dasic's observation about that is the sharpest line in the write-up: "That part is true, which helps make the offer persuasive." Many people have been trained to equate fraud with a request for card details, and this page never makes one.
What it wants is a Google login. Two sign-in options appear and only one works. The Apple button returns a pre-written notice that the method is temporarily unavailable. The email box discards whatever is typed into it and triggers the Google button instead. Every route ends in the same place.
Clicking that button does not open a Google sign-in window. The page draws a browser window inside the existing tab, complete with a padlock and a correctly spelled Google address, and the drawn window can be dragged around the page. It opens on a human-verification step rather than a password box, which Dasic reads as reassuring the visitor while keeping automated scanners away from the next stage.
The most instructive finding is how little the operator built. The malicious functionality is loaded through a single line of code from an outside service that presents itself as a reusable sign-in widget and supplies installation instructions. Comments in that code are in Russian and refer to the target as the victim; one explains that dark-themed fake windows used to flash white while loading, so the widget now fetches the correct colour in advance to remove the flicker. Dasic's conclusion is that it is "a maintained, reusable product rather than something built for this one campaign".
Read against the Malwarebytes write-up of 23 September 2026. The right-hand column is silence in the source, not denial.
| Question | What the research establishes | What it does not establish |
|---|---|---|
| Brand impersonated | Anthropic, via a Claude Max giveaway with real logo, colours and footer links | No statement from Anthropic or Google on this campaign, and no plan tier or price is named |
| Credentials targeted | Google account credentials, sought through a drawn sign-in window | Whether the accounts sought were Google Workspace or consumer Gmail |
| Second factor | The fake window opens on a human-verification step, not a password box | Whether anything was relayed to Google live, so whether a second factor was ever put in play |
| Scale | One page, described in detail | Victim count, page views, number of domains, or any indicator at all |
| Outcome | The page is built to capture Google credentials | Whether a single account was actually compromised |
| Attribution | Russian-language comments inside a third-party sign-in widget | Who operated the campaign; a widget's author is not its customer |
| Delivery | Nothing | How victims reached the page: no email, advert, search or message vector is described |
The path, and where a control can actually reach it
Set out as a sequence, the campaign has six observed steps and two ends that nobody has documented. Defences do not apply evenly across those steps. Most of what organisations buy to stop phishing sits at the arrival end, which is precisely the end this research cannot describe and, for a lure of this class, the end an employer usually does not own.
The padlock was never the control
Browser-in-the-browser is not new. Researchers have documented it since 2022, and in June 2026 Palo Alto Networks Unit 42 described a campaign using draggable fake browser windows against Microsoft 365 users, which adapted its chrome to the victim's operating system and browser and redirected suspected scanners to a genuine Microsoft help page. Four years on, the technique still works for one reason: it attacks the advice rather than the browser.
Generations of security awareness training taught people to look for a padlock and a correctly spelled address on a login page. This attack supplies both, inside a window that does not exist. The address bar shown is a drawing. The only address bar that carries any authority is the real one at the top of the screen, and throughout the whole flow it continues to show the phishing site's domain.
This is the friendly-name fallacy in its purest form. The padlock was never a control. It was a label describing transport encryption, which any operator can obtain for nothing, and it has been meaningless as a trust signal for years. The industry kept teaching it because it was easy to teach.
The human-verification step is the second instance of the same fallacy, and it is a cleverer one. A verification challenge reads to the visitor as a security measure standing between them and the prize, which makes the page feel more legitimate rather than less. To the operator it is an evasion control, filtering automated analysis out before the credential form is ever served. One interface element, doing opposite jobs for the two parties looking at it.
There is one test that survives all of this and costs nothing: try to drag the sign-in window off the edge of the web page. A real pop-up is a separate operating system window and can go anywhere on the screen. A drawn one is trapped inside the page that created it. Dasic offers it as the most reliable check available to a non-technical user, and it is the rare piece of security advice that requires no judgement at all.
Why an AI subscription is such a good pretext
The technique here is ordinary. The pretext is the story.
Anthropic's published pricing puts Claude Pro at 20 dollars a month billed monthly, or 17 dollars a month on an annual plan billed at 200 dollars up front, and lists Max as starting from 100 dollars a month for either five times or twenty times the Pro usage. On those figures, the advertised prize of 10,000 one-month Max subscriptions represents at least a million dollars of notional value, given away by a company that would have no reason to do so and did not.
That is the shape of the lure. AI subscriptions are expensive relative to other consumer software, they are tiered by usage rather than by features so the top tier is genuinely desirable rather than a corporate upsell, access to new capability is routinely rationed by waitlist, and an enormous share of them are paid for by individuals on personal cards and personal accounts, entirely outside any procurement process. Nothing else in the current consumer landscape combines cost, scarcity and personal purchase quite so neatly.
Be blunt about who the victim is here. A person who clicks a free upgrade offer for a tool they already use, want more of, and have probably already been told to use more of at work, is not being careless. They are responding to a scarcity the industry manufactured and continues to advertise. The lure works because the underlying frustration is real.
The trend line supports treating this as a class rather than an incident. Microsoft Threat Intelligence published a report on 8 June 2026, 107 days before this write-up, documenting four separate campaigns between March and May that used AI brands as bait. One of them, running from 20 to 22 April 2026, impersonated Claude with account policy violation warnings and reached more than 2,000 organisations, 62 per cent in the United States, 18 per cent in the United Kingdom and 9 per cent in India. On those proportions that is roughly 360 British organisations in a three-day window, from one campaign. Microsoft's own framing is unambiguous: the activity is "purely abuse of AI brand names as lures", not a compromise of any vendor named.
Check Point's Q2 2026 brand phishing report, published on 23 July, recorded an AI brand entering the ten most impersonated brands for the first time. Microsoft led that list at 23 per cent. Anthropic did not appear in it, which makes this giveaway an early instance rather than a representative one.
What the coverage added that the research did not say
This story is a clean worked example of how a careful technical write-up acquires details on its way through the news cycle, because those added details are the ones a reader is most likely to repeat in a meeting.
Primary research compared with the coverage of it, all accessed 23 September 2026.
| Detail | In the Malwarebytes write-up | Added downstream |
|---|---|---|
| Slot counter | Fewer than 750 of 10,000 remain | Help Net Security reports fewer than 760 |
| Plan tier | Claude Max, described as the highest-usage plan | Digital Trends names it a Claude Max x20 giveaway |
| Price | Paid plans start at 20 dollars a month | Digital Trends states 200 dollars a month; Anthropic's page says Max starts from 100 |
| Delivery | Not described at all | Digital Trends states it is typically spread through malicious ads, search campaigns or phishing messages |
| Indicators | None published | None published anywhere, so no domain can be checked against a public abuse feed |
The indicator row is the one that should bother a defender. Unit 42 published a domain list alongside its June browser-in-the-browser research. Malwarebytes published none here, and links to no sample. That is a defensible editorial choice for a consumer-facing blog describing a live scam, and it also means there is nothing to feed a block list, nothing to search in proxy logs, and no way to check whether the infrastructure is already listed in any public abuse feed. Anyone claiming to have confirmed that is working from a domain the research did not give them.
This briefing has not sought, and does not publish, the domain involved.
The impersonated party, and what it has and has not said
Neither Anthropic nor Google appears to have published anything about this specific campaign as at 23 September 2026, and the research does not report contacting either. Neither company is under any obligation to comment on every site that copies its logo.
Anthropic has, however, published on adjacent abuse of its own brand. Its September 2026 threat intelligence report describes an actor it tracks as GTG-50021 running fraudulent Claude reseller operations, where customers who believed they were buying discounted access instead had a credential harvester installed that stole their Anthropic account credentials for onward sale. The report is explicit that in the API key cases it documents, the keys were stolen from customer environments and Anthropic's own systems were not compromised. Malwarebytes separately reported earlier in September on infostealers hijacking Claude accounts to spend victims' paid usage allowances.
The pattern across all of these is the same, and it is the reason the lure class will persist: a paid AI account is now a liquid asset. It has a resale value, a usage allowance that costs real money, and in many cases it is reachable through a single consumer identity provider. That last property is what this campaign is attacking.
The gateway never sees it
Here is the operational consequence, and it is the reason this belongs in a corporate briefing rather than a consumer one.
An AI brand lure of this type lands on a personal account, on a personal device, very often outside working hours, and asks for a personal identity provider's credentials. A corporate secure email gateway does not see the message. Corporate web filtering does not see the click. Corporate endpoint protection is not on the phone. The identity being phished may not be one the organisation manages, and the compromise may never generate a single event in the organisation's own telemetry.
That does not make it someone else's problem, because the blast radius crosses back. A personal Google account routinely holds the password reset path for business services bought on a personal card, the multi-factor recovery codes somebody saved to their own Drive, documents mailed home to work on, and the single sign-on route into whatever AI tooling the person set up for themselves. The organisation inherits the consequence of a compromise it had no ability to observe.
The honest conclusion is that perimeter controls are the wrong instrument for this class, and reaching for more awareness training is only marginally better. The training in question told people to check for a padlock, and the attack draws a padlock.
Three controls that bite, and what each one does not do
Phishing-resistant authentication on the accounts that matter. A passkey or a hardware security key is bound cryptographically to the real domain. Presented with a drawn window on an attacker's site, the authenticator finds no credential registered for that origin, so there is nothing for the user to hand over and no decision for them to get wrong. The NCSC put this plainly in a paper published on 23 April 2026, five months ago: traditional multi-factor authentication, which it lists as including passwords, SMS codes, email codes, TOTP codes and push approvals, is "inherently phishable", while FIDO2 credentials are not. This is the only control in this list that removes the user's judgement from the loop entirely, which is why it is first.
The qualification is important. Adding a passkey does not help if the password and a phishable second factor remain enabled as fallbacks on the same account, and Microsoft documented a campaign in September 2026 in which attackers targeted the enrolment and cross-device registration flows rather than the cryptography. The control is not the passkey. The control is the removal of the phishable alternatives.
Watch OAuth grants to unknown applications. A stolen Google session is rarely monetised by a human logging in and reading email. It is monetised by attaching an application, because an OAuth grant survives a password change, persists without further interaction and can be sold. In Google Workspace the relevant surfaces are named, and worth finding before you need them: API controls under Security, Access and data control, where third-party applications are set to Trusted, Limited, specific scopes or Blocked, and where unconfigured applications can be blocked wholesale; and OAuth log events under Reporting, Audit and investigation, which records each time a third-party application is authorised to reach account data.
The qualification is that none of this covers the personal account the lure actually targeted. For that, the equivalent action is individual and manual: reviewing third-party access on the personal Google account and signing out of other sessions.
Make a legitimate route to AI tooling exist. This is the control that operates at step one, and it is the only one that reduces the number of people who want what the advert is offering. Unmet, unfunded demand is the fuel. If the sanctioned answer to a request for AI tooling is a six-week wait, a refusal, or silence, then a free upgrade offer is competing against nothing, and staff will keep buying access on personal cards and personal identities where the organisation can neither see it nor protect it.
This is a budget and procurement decision rather than a security one, which is precisely why it gets left out of phishing responses. It belongs in this one.
Controls mapped to the step they interrupt. The step numbers refer to the diagram above.
| Control | Where it bites | What it does not do |
|---|---|---|
| Passkey or hardware key, phishable factors removed | Step 6: nothing to type into the drawn window | Nothing about enrolment abuse or account recovery flows |
| Password manager domain matching | Steps 4 to 6: silence where it normally fills | Nothing if the user overrides it and types the password manually |
| OAuth grant review and session revocation | After step 6: cuts the usual route to cashing out | Nothing on a personal account the organisation does not administer |
| A funded, sanctioned route to AI tooling | Step 1: removes the demand the advert exploits | Nothing for anyone already phished, and nothing this quarter |
| Secure email gateway and web filtering | Nowhere in this path, on a personal device | Nothing the organisation can even record |
What to do, in the order worth doing it
Take this with you
For a UK security lead reading this on 23 September 2026
- Identify which of your business services can be reached through a personal Google or Apple identity, including anything bought on expenses. That list is the actual exposure from this lure class.
- Enforce phishing-resistant authentication on the accounts that matter, and then remove the phishable fallbacks, because leaving SMS or push enabled leaves the phishable path open.
- In Google Workspace, set unconfigured third-party applications to blocked under Security, Access and data control, API controls, and review the existing Trusted list against what people actually use.
- Put OAuth log events on a schedule rather than an incident, under Reporting, Audit and investigation, and alert on first-seen third-party authorisations.
- Write down the revocation runbook for a suspected personal account compromise: password change on the real site, sign out of all sessions, review connected applications and devices, then rotate anything that account could reset.
- Tell staff the drag test rather than the padlock test, because a drawn window cannot leave the page that drew it and a padlock proves nothing.
- Ask finance for the list of AI subscriptions reimbursed through expenses in the last two quarters, and treat it as a demand signal rather than a policy breach.
- Fund a sanctioned route to AI tooling with a stated turnaround time, and publish it, so that a free upgrade advert has something legitimate to compete against.
- Do not build detections around this specific campaign. No indicators were published, and the widget behind it is a reusable product that will reappear under other brands.
The question that exposes the gap
The interesting fact about this campaign is not that someone built a convincing fake Google window. Someone builds one of those every week, and the widget behind this one is sold as a maintained product with installation instructions, which tells you how routine the supply side has become.
The interesting fact is that the operator chose an AI subscription as the thing worth wanting, and was right. That choice will be copied, because the conditions that made it work are not a security failure at all. They are the current commercial arrangement of the AI industry: expensive tiers, rationed access, and a purchasing route that runs through individuals rather than organisations.
So the question to put to your own organisation is not whether staff would fall for a fake giveaway. It is this. How many of the AI tools your people use every day are attached to an identity you do not administer, on a device you do not manage, bought with a card you reimburse? Until you can answer that with a number, the only honest description of your exposure to this lure class is that you cannot see it.
Sources
- PrimaryStefan Dasic's original write-up of the fake Claude Max giveaway, read in full: the only primary account of the landing page, the scarcity counter, the forced fork to Google, the browser-in-the-browser window and the reusable widget behind itMalwarebytes ThreatLabsaccessed 2026-09-23
- PrimaryAnthropic's published consumer pricing, used to check the value of the advertised prize and to test the 200 dollar figure that secondary coverage attached to Max 20xAnthropicaccessed 2026-09-23
- PrimaryThe June 2026 report on AI brands used as social engineering bait, used for the campaign dates, volumes and target counts, and for the statement that no referenced vendor was compromisedMicrosoft Threat Intelligenceaccessed 2026-09-23
- PrimaryThe NCSC comparison of traditional credentials and FIDO2, used for the claim that all traditional multi-factor authentication is phishable and that FIDO2 credentials are notNational Cyber Security Centreaccessed 2026-09-23
- PrimaryAnthropic's September 2026 threat intelligence report, used to establish that Anthropic has published on fraudulent Claude resellers that harvest its customers' credentials, but not on this giveaway campaignAnthropicaccessed 2026-09-23
- PrimaryGoogle Workspace admin documentation for API controls and app access states, used for the named OAuth controls in the checklistGoogleaccessed 2026-09-23
- PrimaryGoogle Workspace OAuth log events documentation, used for the console path where an administrator sees third party authorisationsGoogleaccessed 2026-09-23
- Reported bySinisa Markovic's coverage of the Malwarebytes research, used to show where secondary reporting diverges from the primary on the slot counter figureHelp Net Securityaccessed 2026-09-23
- Reported byConsumer coverage that added a price, a plan tier and a delivery vector that the primary research does not state, used as the worked example of driftDigital Trendsaccessed 2026-09-23
- Reported byCoverage of the Unit 42 browser-in-the-browser campaign against Microsoft 365, the comparison case where indicators were published; the Unit 42 original could not be reachedHelp Net Securityaccessed 2026-09-23
- Reported byThe Q2 2026 brand phishing report, used for the first appearance of an AI brand in the top ten most impersonated brandsCheck Point Researchaccessed 2026-09-23


