logo

Hackers abuse Google ads, Claude.ai chats to push Mac malware

ID: be4602e2-2b74-5ce3-a831-945384268204

STIX ID: report--be4602e2-2b74-5ce3-a831-945384268204

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-05-10

Date Updated: 2026-05-11

Author: Ax Sharma

...
...

Attackers are running an active malvertising campaign that uses Google Ads pointing to legitimate claude.ai shared chats containing malicious installation instructions. Victims who paste the provided Terminal commands download polymorphic, in-memory shell scripts that either profile the host (blocking CIS locales) or immediately execute a second-stage payload; one observed variant exfiltrates browser credentials, cookies, and macOS Keychain contents and has been identified as a MacSync infostealer variant. The campaign was observed and reported by security researchers and BleepingComputer, and leverages legitimate AI shared-chat hosting to evade simple domain-based detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.