Security researchers at Malwarebytes have identified a phishing scheme that lures users with a fake Claude Max giveaway. The attack displays a counterfeit Google sign-in window designed to capture users' credentials when they attempt to claim the offer.
The method relies on the "browser-in-the-browser" technique, where a fake browser window is rendered inside a real one. This approach is not new: researchers have tracked it since 2022, and Palo Alto Networks' Unit 42 reported on it as recently as June. The new campaign shows that threat actors continue to reuse and refine the tactic.
Users should be wary of unsolicited giveaways, especially those that prompt them to sign in with a third-party account. To stay safe, it is best to navigate directly to official websites and verify any sign-in dialog before entering credentials.