Free upgrades to expensive AI tools always sound tempting. Well, cybercriminals know exactly how to leverage that excitement. Security experts at Malwarebytes recently uncovered a clever phishing campaign targeting tech enthusiasts with the promise of a free month of Claude Max, but the site doesn’t want your credit card number—it aims straight for your Google login credentials.
The landing page claims Anthropic is celebrating 100 million users by giving away 10,000 free subscriptions to its highest-tier plan. To make the page look completely legitimate, the creators copied genuine branding, added fake five-star reviews, and linked the footer directly to real Anthropic pages. A ticking slot counter claims fewer than 750 spots remain, though the number simply resets every time you reload the browser tab.
The sneaky browser-in-a-browser trick
Unlike typical scams that demand card numbers or force malware downloads, this trap keeps things suspiciously low-friction. The site explicitly promises that no payment details are needed, which instantly lowers people’s guard.
When you attempt to claim the upgrade, the site steers you into a narrow path. Alternative login methods like Apple display a pre-written error message, leaving Google as the only working button. Clicking it doesn’t open a new popup window. Instead, the site uses a “browser-in-a-browser” technique to draw a fake popup directly inside your active tab.
This fake window includes a padlock icon, a correctly spelled Google URL, and can even be dragged around the page. Type your credentials into it, and you hand your master key over to the attackers.
Why stealing your Google account pays off
Handing over a Google login gives attackers immediate access to your Gmail, Drive files, and account recovery options. Furthermore, because many users access Claude via Google single sign-on, losing your Google credentials gives hackers access to your real AI profiles. Paid AI accounts are valuable commodities on dark web forums because high-usage allowances cost real money.
Analysis of the code reveals that this isn’t a one-off build. Comments in the script written in Russian describe the target as the victim and explain technical fixes, like fetching background colors in advance to keep dark-mode fake windows from flickering white during loading.
Simple ways to spot fake browser windows
Catching these drawn-on browser popups takes only a few seconds once you know what to check:
- Drag the window off-screen: Try moving the sign-in popup past the physical edge of your web browser. A real popup window moves anywhere on your monitor, while a fake drawn window stops dead at the webpage border.
- Trust your password manager: Password managers look at the real domain in your primary address bar. If your password manager refuses to auto-fill your Google login, treat the page as malicious.
- Check the real top address bar: Pay attention to the main browser address bar at the top of your screen, which will continue showing the scam domain throughout the process.
- Watch out for single login routes: Be suspicious whenever a site claims secondary login options like Apple are temporarily unavailable.
If you’ve entered your credentials in a suspicious popup, you should change your Google password immediately from Google’s official site, sign out of all other active sessions in your browser, and check your app permissions.