Hackers Abuse Google Ads and Claude.ai Shared Chats to Distribute macOS Malware
#1
Information 
Quote:Attackers are currently running a malvertising campaign that uses Google Ads and legitimate shared chats on Claude.ai to spread macOS infostealer malware. The campaign was identified by Berk Albayrak, a security engineer at Trendyol Group, with BleepingComputer independently confirming a second active version using different infrastructure.

Users searching for "Claude mac download" might see sponsored Google search results directing them to Claude.ai, with the URL appearing legitimate. These links lead to publicly shared Claude chats that appear as official "Claude Code on Mac" installation guides supposedly from Apple Support. The chats instruct users to open Terminal and paste a command, which then silently downloads and executes malware.

At the time of reporting, two separate Claude shared chats involved in this attack were accessible publicly, each using different domains and payloads but sharing an identical social engineering approach.

How the Claude.ai Malvertising Attack Works

The command being pasted downloads a shell script that is encoded in base64 from domains controlled by attackers. One version, flagged by BleepingComputer, fetches a script called loader.sh from bernasibutuwqu2[.]com, while another, identified by Albayrak, uses customroofingcontractors[.]com.

This loader runs entirely in memory, which means it leaves minimal traces on the disk. The server delivers a uniquely obfuscated version of the payload for each request, a technique known as polymorphic delivery. This approach makes signature-based detection much more difficult.

Continue Reading...
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Kaspersky\VPN\KSOS 21.26 (MR26) & KES 1...
harlan4096 — 07:05
Audacity 3.7.8
Audacity 3.7.8 ...harlan4096 — 07:02
Google Chrome 149.0.7827.114/.115
Google Chrome 149....harlan4096 — 07:00
Microsoft Windows 11 Low Latency Profile...
Windows 11 June up...harlan4096 — 06:52
Microsoft: Windows 11 KB5094126, KB50939...
Windows June 2026 ...harlan4096 — 06:29

[-]
Birthdays
Today's Birthdays
avatar (40)Julioagopy
avatar (50)aolaupitt2558
Upcoming Birthdays
avatar (39)Tedscolo
avatar (46)brakasig
avatar (45)JamesReshy
avatar (47)Francisemefe
avatar (40)leoniDup
avatar (39)Patrizaancem
avatar (39)biobdam
avatar (40)storoBox
avatar (48)kinotHeemn
avatar (39)Ceballos1976
avatar (40)efynu
avatar (32)horancos

[-]
Online Staff
There are no staff members currently online.

>