AI Security

The Rise of Poison Claude and Advanced Phishing-as-a-Service

FORTSECURE GLOBAL· 2026-08-14🛰 Graham Cluley
#Phishing#Social Engineering#AI Security#MFA Bypass

Cybercriminals are now leveraging the AI hype to distribute 'Poison Claude,' a fake service that intercepts traffic, alongside new phishing techniques that bypass traditional login protections.

The cybersecurity landscape is rapidly shifting as attackers find ways to exploit the modern craze for artificial intelligence. In a recent analysis by cybersecurity experts at the Smashing Security podcast, a new threat dubbed 'Poison Claude' has emerged. This service attracts users by offering access to Anthropic’s powerful Claude AI model at a 90% discount. However, the catch is significant: users must redirect their traffic through a mysterious, fraudulent service. This allows the operators to monitor all interactions and harvest sensitive data, effectively turning a useful tool into a surveillance device. This marks a new era where social engineering is specifically tailored to those seeking low-cost access to premium AI technology.\n\n## The Evolution of Phishing-as-a-Service\nBeyond AI scams, the 'Greatness' phishing-as-a-service platform has introduced a concerning new methodology for stealing credentials. Unlike traditional phishing, which relies on convincingly fake websites or suspicious URLs, Greatness utilizes actual Microsoft login pages. By acting as a sophisticated middleman, the platform captures the user's interaction with the real service. This allows attackers to bypass certain multi-factor authentication (MFA) methods by capturing the resulting session tokens. Because the user is looking at a legitimate login screen, the level of misplaced trust is exceptionally high, making this one of the more dangerous phishing techniques in current circulation.\n\n## Practical Recommendations for Security\nTo protect against these evolving threats, FORTSECURE GLOBAL recommends that organizations strictly enforce the use of official AI service endpoints. Employees should be warned against third-party AI 'proxies' that promise unrealistic discounts. Furthermore, businesses should move toward more robust MFA solutions, such as FIDO2-compliant hardware keys, which are resistant to the session-hijacking techniques employed by platforms like Greatness. Regular security awareness training must also be updated to include these specific scenarios where the phishing page appears to be 100% legitimate because it is actually hosting the real service in a frame or proxy arrangement.


แหล่งที่มา: Graham Cluley เผยแพร่ครั้งแรก: Wed, 12 Aug 2026 23:12:28 +0000 บทความต้นฉบับ: อ่านต้นฉบับ

Source Attribution

แหล่งที่มา: Graham Cluley

เผยแพร่ครั้งแรก: Wed, 12 Aug 2026 23:12:28 +0000

บทความต้นฉบับ: https://grahamcluley.com/smashing-security-podcast-480/

อ่านบทความต้นฉบับ ↗

* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์

← กลับไปหน้า Blog