
Dragging a sign-in popup past the edge of your browser window is, right now, one of the most useful security tricks you can know. If the window stops at the page boundary instead of floating freely across your screen, you’re looking at a fake. That single test is the clearest signal that a phishing campaign targeting Claude AI users desperately hopes you never try.
Security researchers at Malwarebytes have reported a phishing campaign built around a fake Claude Max subscription giveaway. The landing page claims Anthropic is celebrating 100 million users by handing out 10,000 free subscriptions to its most expensive plan. The design copies real Anthropic branding, links to genuine Anthropic pages in the footer, and features fake five-star reviews. A slot counter claims fewer than 750 spots remain. Reload the page, and the number resets. It’s theater, and carefully built theater at that.
What makes this attack different from a standard phishing attempt is how deliberately low-friction it is. The site promises no payment details are needed, which is exactly what lowers people’s guard. When you try to claim the offer, Apple and other login options display a pre-written error message. Google is the only button that works. Click it, and the site doesn’t open a real popup. Instead it uses a technique called browser-in-a-browser, drawing a fake login window directly inside your active tab. That window has a padlock icon, a correctly spelled Google URL, and it can be dragged around the page. Type your credentials into it, and they go straight to the attackers.
Analysis of the site’s code found comments written in Russian, describing targets as victims and documenting technical fixes, including a method to pre-fetch background colors so fake dark-mode windows don’t flicker white during loading. This is not a rushed, one-off build. Someone put real effort into making it hold together under casual inspection.
The stakes here are high. A Google account is a master key. Handing it over means attackers get access to Gmail, Drive, account recovery options, and, because many users sign into Claude through Google single sign-on, real AI accounts too. Paid AI subscriptions trade on dark web forums precisely because high-usage allowances cost money.
Spotting these attacks comes down to a few habits:
- Try dragging the login popup past your browser’s edge. A real popup moves freely across your whole monitor. A fake one stops at the page boundary.
- Trust your password manager. It reads the real domain in the top address bar, not the drawn fake one. If it won’t auto-fill, treat the page as hostile.
- Check the actual address bar at the top of your browser throughout the process. It will still show the scam domain.
- Be suspicious when a site tells you that Apple or other login options are temporarily unavailable, leaving only one route.
If you’ve already entered credentials in a suspicious popup, change your Google password immediately on Google’s official site, sign out of all active sessions, and review third-party app permissions. The campaign is a reminder that the most effective phishing attacks today don’t rely on malware or urgency alone. They rely on looking just plausible enough that users don’t stop to question the window they’re typing into.