LIVE · cybersecurity feed
Live wire
phishing

Smashing Security podcast #480: This is the AI service you should never sign up to

Would you like access to Anthropic's Claude at 90% off the normal price? All you have to do is redirect your traffic to a mysterious service called "Poison Claude". Only problem is that it's run by fraudsters... Meanwhile, a phishing-as-a-service platform called "Greatness" has come up with something rather nasty: a phishing attack that doesn't need a fake website, a suspicious URL, or your passwo

zeroday.news ·

A new phishing-as-a-service (PaaS) platform named "Greatness" has emerged, offering a sophisticated attack vector that bypasses traditional password theft and fake website tactics. This platform leverages a legitimate Microsoft login page to gain full access to a victim's emails, files, and potentially their entire organizational infrastructure. The attack relies on a moment of misplaced trust from the user, rather than the typical indicators of a phishing attempt like suspicious URLs.

Concurrently, a fraudulent service dubbed "Poison Claude" is preying on users seeking discounted access to Anthropic's Claude AI. This service promises a 90% reduction in the normal price for Claude access, but requires users to redirect their traffic through its mysterious platform. This scheme is identified as a clear fraud, designed to exploit users eager for cost savings on AI services.

The Greatness phishing attack represents an evolution in social engineering, moving beyond the need for attackers to host their own malicious sites or trick users into entering credentials on fake pages. By utilizing a genuine Microsoft login, the attackers aim to instill a false sense of security, making it harder for victims to identify the compromise before it's too late. The specifics of how Greatness achieves its objectives without a suspicious URL or password theft were not detailed, but the outcome is full access to the victim's digital assets.

The "Poison Claude" scam highlights a different facet of cybercrime, targeting the growing user base of AI services. The promise of a significant discount, specifically 90% off Anthropic's Claude, is the bait. Users are then directed to route their traffic through the "Poison Claude" service, which is operated by fraudsters. The exact mechanism of compromise or data exfiltration through this traffic redirection was not specified, but the service is unequivocally identified as fraudulent.

Both incidents underscore the ongoing adaptability of cybercriminals. While Greatness focuses on bypassing established security awareness around phishing URLs and fake login pages, "Poison Claude" exploits the financial incentive of discounted AI access. These developments emphasize the need for users and organizations to remain vigilant against evolving attack methodologies, even when traditional warning signs are absent.

The "Poison Claude" scheme serves as a reminder that offers that seem too good to be true, especially those involving significant discounts on popular services, often conceal malicious intent. Users are advised to verify the legitimacy of any third-party service claiming to offer discounted access to established platforms like Anthropic's Claude directly with the official vendor.

The Greatness PaaS platform, by eliminating the need for a fake website or suspicious URL, presents a more insidious threat. It suggests that users should be wary even when interacting with seemingly legitimate login pages, and that the context and method of access are crucial. The full implications of an attacker gaining "full access to your emails, your files, and your entire organisation" through such a method are severe, potentially leading to data breaches, corporate espionage, and further network compromise.

phishingai
ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Windows 11’s strongest security defenses can be bypassed without a screwdriver

Researchers from the University of Birmingham and Durham University have found a way to knock down some of the toughest protections in Windows 11 without physically opening or modifying the target machine. The attack assumes the attacker has already gained privileged access to the system. A chip that never checks who’s asking The attack, named “Download More RAM,” targets a small configuration chi

ai

Hazmat: Open-source containment for AI agents

Hazmat is an open-source tool that runs AI coding agents inside a separate account on your own machine. It wraps the harnesses people use: Claude Code, Codex, OpenCode, Cursor Agent, and several more, plus any script you write yourself. An agent launched the ordinary way runs as you, which means it can read anything you can read. That includes SSH keys, cloud credentials, and the pile of configura

nation-state

Product showcase: ScamNet looks for warning signs in suspicious calls and shady links

ScamNet: Anti-Scam Suite is a consumer security app from Synaptrex Technologies that helps users detect and block scams involving phone calls, text messages, websites, and other suspicious content. The app is available for iPhone, iPad, and Mac, with features varying by platform. Call protection is available on iPhone, while tools such as Visual Intelligence are supported on iPhone and iPad. The a

vulnerability

Microsoft blames AI for delayed Exchange update, can’t say when it will arrive

Dealing with machine-made bug backlog makes it hard to find a moment to deliver promised subscription service

breach

Chinese AI company Zhipu claims its new is a better bug-finder than Anthropic, OpenAI

PLUS: HCL, TCS, admit data breaches; Google, Apple, India bans some rideshare tips; and more!

breach

SafePal data breach impacts 39,798 customers, stolen info for sale

Cryptocurrency hardware wallet provider SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data. [...]