Google Ads and Claude AI Abused to Spread MacSync Malware via ClickFix
ID: 44e9e1fa-b587-59ce-bd06-6f09517579a3
STIX ID: report--44e9e1fa-b587-59ce-bd06-6f09517579a3
Feed Name: HackRead
Threat Score
**Executive Summary:** Researchers at Moonlock Lab discovered an active campaign that hijacked verified Google Ads to promote fake macOS guides which instruct users to paste terminal commands; executing the commands installs the MacSync infostealer that exfiltrates Keychain, browser credentials, and crypto keys to a central C2 server.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
