Threat Actors Exploit Claude Artifacts and Google Ads to Target macOS Users
ID: 38d63424-de08-59cf-8edf-0a76e187ca6e
STIX ID: report--38d63424-de08-59cf-8edf-0a76e187ca6e
Feed Name: cybersecurityNews.com
A sophisticated campaign is abusing legitimate platforms (Google Ads, Anthropic’s Claude artifacts, and a spoofed Medium article) to trick macOS users into running obfuscated terminal commands that install the MacSync information stealer. The malware harvests keychain, browser data, and crypto wallet files, stages data at /tmp/osalogging.zip, and exfiltrates to a2abotnet.com with retry and cleanup mechanisms; the report includes domains (a2abotnet.com, raxelpak.com, apple-mac-disk-space.medium.com) and recommends caution when executing terminal commands and deploying endpoint detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
