• ABOUT US
  • Advertise With Us
  • Contact US
  • Edit Calendar
IT Magazine for Channel Partners in India | SMEChannels
Advertisement
  • Home
  • News
    • AI & ML
    • Cloud Computing
    • Cyber Security
    • Server & Storage
    • Networking
  • Hardware News
    • Printers & Peripherals
    • Software
  • Events & Webinars
    • Channel Accelerator Awards 2025
    • Channel Accelerator Awards 2024
    • MSP India Summit 2024
    • MSP India Summit 2023
    • Channel Accelerator Awards 2023
    • SME Channels Summit & Awards 2022
    • SME Channels Summit & Awards 2021
    • WEBINAR
    • SME AWARDS 2020
  • Corporate News
  • Interview
  • Executives Movement
  • Partner Corner
No Result
View All Result
  • Home
  • News
    • AI & ML
    • Cloud Computing
    • Cyber Security
    • Server & Storage
    • Networking
  • Hardware News
    • Printers & Peripherals
    • Software
  • Events & Webinars
    • Channel Accelerator Awards 2025
    • Channel Accelerator Awards 2024
    • MSP India Summit 2024
    • MSP India Summit 2023
    • Channel Accelerator Awards 2023
    • SME Channels Summit & Awards 2022
    • SME Channels Summit & Awards 2021
    • WEBINAR
    • SME AWARDS 2020
  • Corporate News
  • Interview
  • Executives Movement
  • Partner Corner
No Result
View All Result
IT Magazine for Channel Partners in India | SMEChannels
No Result
View All Result
Home Cyber Security

Kaspersky discovers infostealers mimicking Claude Code, OpenClaw and other AI developer tools

SME Channels by SME Channels
March 25, 2026
in Cyber Security, Cybersecurity, News
Kaspersky discovers infostealers mimicking Claude Code, OpenClaw and other AI developer tools

The new malicious campaign, targeted at developers looking for installation instructions for Claude Code and other popular AI tools, tricks them into installing malware which harvests sensitive information including credentials, crypto wallet data, browser sessions, and other confidential files

In March 2026, Kaspersky Threat Research has identified a new malicious campaign targeted at developers looking for installation instructions for Claude Code, a development agent created by Anthropic. When searching for “Claude Code download”, sponsored advertisements appear at the top of the search results. One of these ads redirects users to a malicious webpage that closely imitates the official installation documentation for Claude Code. As a result, users are tricked into installing malware which harvests sensitive information including credentials, crypto wallet data, browser sessions, and other confidential files. Similar malicious campaigns mimic other popular AI tools, including OpenClaw.

A fraudulent ad example

The fake documentation page is visually identical to the legitimate one and is hosted on the website-building and hosting platform Squarespace. Because the page precisely copies the original instructions, users may not notice the difference when copying and executing installation commands.

2
A fraudulent Claude page

However, instead of installing the developer tool, the commands deliver malware to the victim’s system. Depending on the operating system, the malicious commands deploy different infostealers:

  • Windows systems receive Amatera, an information-stealing malware that collects data from user directories, web browsers, and cryptocurrency wallets before sending the stolen information to a remote server. Amatera has previously been observed in campaigns using the ClickFix distribution technique and is operated under a Malware-as-a-Service (MaaS) model.
  • macOS systems receive AMOS, another infostealer previously documented in several malware campaigns targeting Apple devices. It has been describedby Kaspersky before.

“The campaign poses significant risks because AI development tools such as Claude Code and OpenClaw are widely used not only by hobbyists and automation enthusiasts but also by professional developers working in large organizations.”

– Vladimir Gursky, cybersecurity expert at Kaspersky

Kaspersky researchers also identified similar malicious campaigns targeting other popular AI tools, including OpenClaw and Doubao. Using the same approach, attackers registered multiple domains and distributed files containing the Amatera infostealer while disguising them as legitimate downloads for these tools.

“The campaign poses significant risks because AI development tools such as Claude Code and OpenClaw are widely used not only by hobbyists and automation enthusiasts but also by professional developers working in large organizations. If infected, victims may unknowingly expose source code from active projects, confidential corporate data, authentication credentials, and private accounts. This makes such campaigns particularly dangerous for businesses whose developers rely on AI-assisted coding tools,” comments Vladimir Gursky, cybersecurity expert at Kaspersky.

In December 2025 Kaspersky detected that attackers spread a macOS infostealer using Google Ads. A specially generated chat interface designed to resemble a ChatGPT tutorial pretended to guide users through installing the Atlas Browser. The malicious instructions appeared to be hosted on a legitimate site associated with OpenAI, helping attackers gain users’ trust.

To stay protected, Kaspersky recommends:

  • Carefully verify download links and ensure they point to official project websites.
  • Review any command-line instructions before executing them, especially if copied from external sources.
  • Avoid following guides you did not specifically request or do not fully understand.
  • Use reliable endpoint security solutions capable of detecting and blocking infostealers and malicious downloads.
Previous Post

Arinox.ai & Altos Computing Join Forces to Bring India’s First Deployable Private AI-In-A-Box To Market At Scale

Next Post

Supertron Electronics Undertakes Impactful CSR Initiatives

Related Posts

CrowdStrike
Cyber Security

CrowdStrike Celebrates JAPAC’s Cybersecurity Trailblazers Driving AI-Led Transformation

April 22, 2026
Rémy Marot, Staff Research Engineer at Tenable
Cyber Security

Tenable Research Uncovers Remote Code Execution Vulnerability in Microsoft GitHub Repository

April 22, 2026
Anthone Lange
News

Sonata Software Achieves AWS Migration and Modernization Competency Status

April 22, 2026
Jon Fox, vice president of channels and alliances, CrowdStrike Japan and Asia Pacific
Cyber Security

CrowdStrike Accelerates SMB Cybersecurity Transformation Across JAPAC with Expanded Distributor-Led Services

April 21, 2026
Atul Mehta, Senior Director and General Manager - India Channels at Dell Technologies
News

DELL’S BIG INDIA BET: WHY AI, ECOSYSTEM DEPTH, AND ‘PARTNER FIRST’ WILL DRIVE ITS NEXT GROWTH CURVE

April 21, 2026
Jaya Krishna, Chief Business Officer, Redacto
Executives Movement

Redacto Appoints Jaya Krishna as Chief Business Officer to Scale Enterprise Adoption Ahead of DPDP Enforcement

April 21, 2026

Print Magazine

About Us

SMEChannels is a leading IT Channel magazine, which represents the voice of more than 32,000 partners in India. The focus is to work towards the growth of the entire channel ecosystem. Therefore, the magazine covers all the topics that are relevant to the partner ecosystem. Broadly we cover technologies that go as solutions and services. Therefore, the topics we cover include cloud computing, big data & analytics, security, surveillance, mobility, enterprise applications, data center, 3D printing, robotics, machine learning, IOT, etc.

Contact Us

For Editorial:
Sanjay Mohapatra, Group Editor
Email : sanjay@accentinfomedia.com
Phone No. +91 99100 97969
Manash Ranjan Debata, Editor
Email : manash@accentinfomedia.com

For Print and Online Advertisement :

Rhythm
Email :info@accentinfomedia.com
Phone No. +917042031678

For Events and Webinar:
Sanjib Mohapatra, Director
Email : sanjib@accentinfomedia.com

Usefull Links

  • ABOUT US
  • Advertise With Us
  • Contact US
  • Edit Calendar
  • ABOUT US
  • Advertise With Us
  • Contact US
  • Edit Calendar

@2026 Powered By SMEChannels Theme By Accent Info Media

No Result
View All Result
  • Home
  • News
    • AI & ML
    • Cloud Computing
    • Cyber Security
    • Server & Storage
    • Networking
  • Hardware News
    • Printers & Peripherals
    • Software
  • Events & Webinars
    • Channel Accelerator Awards 2025
    • Channel Accelerator Awards 2024
    • MSP India Summit 2024
    • MSP India Summit 2023
    • Channel Accelerator Awards 2023
    • SME Channels Summit & Awards 2022
    • SME Channels Summit & Awards 2021
    • WEBINAR
    • SME AWARDS 2020
  • Corporate News
  • Interview
  • Executives Movement
  • Partner Corner

@2026 Powered By SMEChannels Theme By Accent Info Media