Hackers Use Google Ads and Claude AI Chats to Steal macOS Credentials and Crypto Wallets
ID: 8083d1b3-8812-5603-9d72-8e152e1e09e6
STIX ID: report--8083d1b3-8812-5603-9d72-8e152e1e09e6
Feed Name: GBHackers
**MacSync Stealer campaign abusing Google Ads and Claude shared chats:** Threat actors ran ads that redirected users to attacker-controlled Claude shared chats instructing victims to paste Terminal commands (ClickFix), delivering a multi-stage macOS info-stealer that exfiltrates Keychain data, browser credentials, cloud keys, SSH/AWS/Kubernetes configs, wallet data, and files; persistence, obfuscation, and HTTP PUT exfiltration are used, and multiple IOCs (domains, file artifacts, persistence changes) are provided for detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
