logo

Windows and macOS Malware Spreads via Fake “Claude Code” Google Ads

ID: f8135e98-b9f7-52d9-9cd7-d04383f89c96

STIX ID: report--f8135e98-b9f7-52d9-9cd7-d04383f89c96

Feed Name: Bitdefender Labs

Threat Score
70/100

Date Published: 2026-03-11

Date Updated: 2026-04-27

Author: Ionut Alexandru BALTARIU

...
...

Bitdefender researchers uncovered a malicious Google Ads campaign that impersonated Claude Code and directed users to a fake Squarespace documentation page that instructs Windows and macOS users to run terminal commands; executing those commands delivered mshta-based info‑stealers on Windows and a Mach‑O backdoor on macOS. The report presents technical analysis of the payloads (including anti‑VM/sandbox checks and remote shell functionality), multiple IOCs (file hashes and malicious URLs), attribution evidence suggesting a compromised advertiser account, and user protection recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.