Hackers Abuse Claude.ai Shared Chat Feature to Host the ClickFix Social Engineering Instructions
ID: 0f9410fb-3d25-5336-93db-56fbb3216660
STIX ID: report--0f9410fb-3d25-5336-93db-56fbb3216660
Feed Name: cybersecurityNews.com
TrendAI/TrendMicro observed a multi-wave ClickFix campaign that leveraged trusted infrastructure—initially GitLab Pages and later Claude.ai shared chats—to host convincing fake support chats and malvertising via Google Ads that instructed victims to paste base64-encoded terminal/PowerShell commands; those commands delivered the MacSync infostealer against macOS, exfiltrating credentials, SSH keys and crypto wallet data. The operation rotated through 106 malicious hostnames, heavily targeted Asia‑Pacific (notably Taiwan), and was partially mitigated after responsible disclosure led Anthropic to remove malicious shared chats.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
