Member · Claude Partner Network · Alexandria, Egypt
High Severity Active Campaign Published: 21 May 2026 ELM-SA-2026-001

Fake "Claude for Windows" malware campaign on Facebook

A paid advertising campaign on Meta (Facebook) is impersonating Anthropic and the Claude brand to distribute a malicious Windows installer. The ad routes victims to a typosquat domain and delivers a file designed to steal credentials, browser sessions, cryptocurrency wallets, and developer account access.

✓ Official. Legitimate. Verified.
The only legitimate Claude for Windows installer is at: https://claude.ai/download

Indicators of Compromise (IOCs)

IOC Type Value Notes
Domain (malicious)clude-promo-offer[.]comTyposquat of claude.com — missing "a"
File deliveredinstaller.exeWindows PE executable — do not run
Ad sponsor nameBlockFlowNo relationship with Anthropic
Meta pixel ID1360099919291289Tracking pixel embedded in ad
Meta campaign ID120246120865360573From UTM parameters
Ad display URLCLAUDE.COMShown in ad — misleading
Actual click URLclude-promo-offer[.]comVisible in browser status bar on hover
First observed21 May 2026, ~22:00 EESTElmahrosa observation, Egypt
Target regionMENADelivered to Egypt-based Facebook accounts
⚠ Do not

Do not visit clude-promo-offer.com. Do not download or execute installer.exe from this domain. If you have already downloaded the file: do not open it. Delete it immediately and empty the Recycle Bin.

If you have already downloaded the file

  1. 01Do not open the file. Delete it from your Downloads folder. Empty the Recycle Bin.
  2. 02Disconnect from the internet if you opened the file, to prevent credential exfiltration.
  3. 03Run a full scan with Windows Defender → Full scan. Then a second-opinion scan with Malwarebytes Free.
  4. 04Change passwords from a clean separate device: Anthropic Portal, all Gmail accounts, GitHub, Hostinger, LinkedIn, any crypto wallet.
  5. 05Revoke active sessions in Gmail, GitHub, and Anthropic Console.

How to verify a Claude download is legitimate

The only legitimate Claude-branded downloads are hosted on Anthropic-controlled domains:

Reporting similar threats

Share this advisory

Published by: Ayman Seif, Founder & CEO, Elmahrosa International
Advisory ID: ELM-SA-2026-001  |  Date: 21 May 2026  |  Status: Active
Contact: ayman@elmahrosa.org  |  Trust Center

Elmahrosa International is a member of the Anthropic Claude Partner Network. This advisory is published independently in the interest of the broader AI-user community in MENA and East Africa. This document may be freely reproduced with attribution.