Threat actors are using a social engineering technique called InstallFix, which leverages fake installation guides for popular command-line interface (CLI) tools like Claude Code. These guides, promoted through malvertising on Google Ads, trick users into executing malicious commands that download and install the Amatera Stealer, an information-stealing malware.
Reconnaissance
Targeted Advertising for Malicious Installers
likely
Attackers create cloned installation pages for popular CLI tools and promote them through malvertising campaigns on Google Ads, targeting search queries related to these tools.
Defender cut points
Blocking ads from untrusted sourcesUser education on verifying search results