ClaudeFix Campaign Abuses Shared Claude Chats to Deliver MacSync Stealer
ID: 7deaa469-c3db-511a-9fa8-cd8e51b2f8b2
STIX ID: report--7deaa469-c3db-511a-9fa8-cd8e51b2f8b2
Feed Name: Cyber Press
Threat Score
Zscaler observed an active campaign called "ClaudeFix" that abuses shared Anthropic Claude chats and malicious Google ads to trick macOS users into pasting Base64-encoded curl commands that install MacSync Stealer; the stealer performs multi-stage execution (zsh → AppleScript), harvests keychains, browser credentials, crypto wallet data and other sensitive files, exfiltrates data in chunked HTTP PUTs, and uses persistence via ~/.zshrc — IoCs and detection names are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
