logo

Google Ads and Claude AI Abused to Spread MacSync Malware via ClickFix

ID: 44e9e1fa-b587-59ce-bd06-6f09517579a3

STIX ID: report--44e9e1fa-b587-59ce-bd06-6f09517579a3

Feed Name: HackRead

Threat Score
72/100

Date Published: 2026-02-16

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

**Executive Summary:** Researchers at Moonlock Lab discovered an active campaign that hijacked verified Google Ads to promote fake macOS guides which instruct users to paste terminal commands; executing the commands installs the MacSync infostealer that exfiltrates Keychain, browser credentials, and crypto keys to a central C2 server.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.