HomeSecurityHackers abuse Google Ads and Claude.ai chats for Mac attacks

Hackers abuse Google Ads and Claude.ai chats for Mac attacks

A particularly disturbing cyberattack campaign is underway, with perpetrators exploiting two seemingly trustworthy digital tools: Google ’s sponsored ads and Anthropic Claude.ai ’s publicly accessible shared chats . This new tactic marks a dangerous evolution in the space malvertising , as attackers no longer need to create fake websites to trick their victims.

Google Ads Claude.ai chats Mac attacks

Users who perform searches such as “Claude mac download” may encounter sponsored results that display claude.ai as the official destination, but ultimately lead to instructions for installing malware on macOS devices.

The discovery of the attack and the new deception model

The campaign was discovered by security engineer Berk Albayrak, who revealed his findings after analyzing a suspicious shared chat. The chat was presented as an official installation guide for “Claude Code on Mac,” with a false reference to Apple.

See also: GPUGate malware: Exploiting GitHub and Google Ads for attacks

The social engineering method used is extremely convincing. Users are asked to open the macOS Terminal and paste a command that supposedly installs the necessary tool. In reality, the command triggers the download and silent execution of malware.

What is particularly worrying is that multiple independent versions of the same attack were identified, with different infrastructure, domains and payloads, which indicates an organized and evolving operation.

Hackers abuse Google Ads and Claude.ai chats for Mac attacks

How malware works on macOS

The attack utilizes shell scripts that execute entirely in the device's memory, leaving no visible files on disk. This is a technique that makes it significantly more difficult to detect by traditional antivirus tools.

Even more worrying is the use of polymorphic payload delivery, where each request to the malicious server returns slightly modified malicious code. This avoids detection through known signatures or hashes.

In many cases, the malware performs a preliminary system scan. It looks for whether the device is using Russian or other CIS keyboard settings and, if detected, immediately stops it from functioning. This practice is often associated with cybercrime groups that avoid targeting specific geographic regions.

See also: Phishing campaign targets ManageWP users via Google Ads

At the same time, critical data is collected such as:

• External IP address
• Device hostname
• macOS version
• Keyboard locale settings

The data is sent to the attackers' server before the second stage is activated.

Credential theft and Keychain access

In more aggressive variants, the malware bypasses the profiling phase and proceeds directly to extract sensitive information.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Its goal is to collect stored browser credentials, session cookies, and data from macOS Keychain, the platform's central password storage system.

Experts believe that this is a variant of the well-known MacSync, an infostealer that has been linked to extensive operations to steal cloud accounts, crypto wallets, and corporate credentials.

Hackers abuse Google Ads and Claude.ai chats for Mac attacks

Why this scam is more dangerous than classic phishing attacks

What makes the campaign extremely effective is that it does not use a fake domain. The URL displayed in the ads is the authentic claude.ai, which invalidates one of the most basic verification mechanisms that users implement.

See also: Ivanti EPMM: Hackers exploit RCE vulnerability

This demonstrates that attackers are shifting their strategy: from spoofing websites to abusing legitimate platforms and trusted environments.

Similar techniques were recently recorded in campaigns targeting OpenAI ChatGPT and xAI Grok, showing how AI platforms are becoming a new arena for cybercriminals.

How can users be protected?

Experts recommend increased vigilance. The safest practice is to pages application download and avoid clicking on sponsored search results.

It is equally critical to treat any instructions that ask you to paste commands into Terminal with suspicion. In today's threat landscape, even a legitimate URL is no longer a guarantee of security.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS