logo

ClaudeFix Campaign Abuses Shared Claude Chats to Deliver MacSync Stealer

ID: 7deaa469-c3db-511a-9fa8-cd8e51b2f8b2

STIX ID: report--7deaa469-c3db-511a-9fa8-cd8e51b2f8b2

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-07-16

Date Updated: 2026-07-16

Author: Tamilselvan

...
...

Zscaler observed an active campaign called "ClaudeFix" that abuses shared Anthropic Claude chats and malicious Google ads to trick macOS users into pasting Base64-encoded curl commands that install MacSync Stealer; the stealer performs multi-stage execution (zsh → AppleScript), harvests keychains, browser credentials, crypto wallet data and other sensitive files, exfiltrates data in chunked HTTP PUTs, and uses persistence via ~/.zshrc — IoCs and detection names are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.