Attackers abuse Google Ads, GitLab, and Claude to deliver malware
Summary
Attackers used Google Ads, GitLab pages, and Claude shared chats to deliver malware through a seven-week social engineering campaign. The scheme impersonated popular AI developer tools and pushed victims to manually run malicious PowerShell or terminal commands. Researchers say the attackers relied on trusted platforms and reputation stacking to make the attack chain look legitimate and harder to detect. The campaign targeted developers and technical users, creating a much larger enterprise risk because compromised endpoints can expose credentials, source code, and cloud access.
Classifications
industries
HealthTech
applications
Accounting and Taxes
AskAI Classifications
Labels
SaaS
Consumer Software
Enterprise Software