Mac Users Warned Over Fake Claude Install Instructions
ID: 2205d982-9ea5-5335-8e5c-ce05e45f0aee
STIX ID: report--2205d982-9ea5-5335-8e5c-ce05e45f0aee
Feed Name: TechRepublic Security
Mac users searching for Claude are being targeted by an active campaign that uses Google Ads and Claude shared-chat content to present fake installation instructions; when victims paste the provided Terminal commands they can download and run multi-stage malware (including a MacSync infostealer) that steals browser credentials, cookies, and Keychain data and employs in-memory obfuscation to evade detection — users should only follow official documentation and avoid running commands from chats or ad-driven pages.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
