logo

macOS Malware Leverages Google Ads and Legitimate Claude.ai Shared Chats to Deliver Malware

ID: b9ed3b9a-98ff-51b9-8700-b9c49e209d56

STIX ID: report--b9ed3b9a-98ff-51b9-8700-b9c49e209d56

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-05-11

Date Updated: 2026-05-14

Author: Abinaya

...
...

### Executive Summary: Attackers are running a malvertising campaign that leverages paid Google Ads and deceptive Claude AI-themed landing pages hosted on trusted platforms (Google Sites, Framer, claude.ai shared chats) to trick macOS users into executing a MacSync "Clickfix" payload. The campaign redirects victims through rotating domains and IPs (examples include sites.google.com/view/cloud-version-08, claud e-desktop-app.framer.ai, 2.26.75.112/Hokojol, pieoneer.org) to deliver a macOS information stealer that exfiltrates browser credentials, cryptocurrency wallet data, and session tokens; defenders are advised to block known IOCs, monitor macOS endpoint telemetry for unusual script execution from browsers, and educate users to avoid sponsored download ads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.