logo

Hackers Use Google Ads and Claude AI Chats to Steal macOS Credentials and Crypto Wallets

ID: 8083d1b3-8812-5603-9d72-8e152e1e09e6

STIX ID: report--8083d1b3-8812-5603-9d72-8e152e1e09e6

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-07-16

Date Updated: 2026-07-16

Author: Divya

...
...

**MacSync Stealer campaign abusing Google Ads and Claude shared chats:** Threat actors ran ads that redirected users to attacker-controlled Claude shared chats instructing victims to paste Terminal commands (ClickFix), delivering a multi-stage macOS info-stealer that exfiltrates Keychain data, browser credentials, cloud keys, SSH/AWS/Kubernetes configs, wallet data, and files; persistence, obfuscation, and HTTP PUT exfiltration are used, and multiple IOCs (domains, file artifacts, persistence changes) are provided for detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.