Particle.news
Download on the App Store

Phishers Use Fake Claude Max Giveaway to Steal Google Logins

Malwarebytes researchers found a draggable fake Google sign-in drawn inside web pages that lets attackers access email, Drive and linked AI accounts.

Overview

  • Malwarebytes published details on September 23, 2026, of a phishing page that promises a free Claude Max upgrade and captures Google credentials through a fake in-page sign-in.
  • The scam uses a ‘browser-in-the-browser’ trick that draws a draggable, padlock-bearing Google window inside the page so the site’s address bar still shows the scam domain.
  • The page forces victims toward Google sign-in by breaking other login options and shows a fake countdown and slot counter that are generated in the visitor’s browser.
  • Analysis shows the malicious UI loads from a third-party sign-in widget with a single line of external code and Russian comments, indicating a maintained, reusable tool that lowers attacker effort.
  • Practical defenses include trying to drag the popup off the page, trusting your password manager to block autofill, checking the real browser address bar, and changing your Google password and revoking sessions if you signed in.