logo

Claude LLM artifacts abused to push Mac infostealers in ClickFix attack

ID: e937612c-1a76-556b-a382-99681da78b1e

STIX ID: report--e937612c-1a76-556b-a382-99681da78b1e

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2026-02-13

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Researchers observed threat actors promoting malicious Claude artifacts and impersonated pages via Google Ads to trick macOS users into pasting shell commands that download and execute a MacSync infostealer loader; the malware collects keychain, browser and crypto wallet data and exfiltrates it to a2abotnet.com/gate. The campaign has multiple variants, thousands of recorded views (12k–15.6k+), shared C2 infrastructure, and includes clear IOCs and commands users are instructed to run.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.