Malware News Hackers Abuse Google Ads and Claude.ai Shared Chats to Distribute macOS Malware

lokamoka820

Level 45
Thread author
Verified
Top Poster
Well-known
Mar 1, 2024
3,423
3
11,497
4,369
Banana Republic
Attackers are currently running a malvertising campaign that uses Google Ads and legitimate shared chats on Claude.ai to spread macOS infostealer malware. The campaign was identified by Berk Albayrak, a security engineer at Trendyol Group, with BleepingComputer independently confirming a second active version using different infrastructure.

Users searching for "Claude mac download" might see sponsored Google search results directing them to Claude.ai, with the URL appearing legitimate. These links lead to publicly shared Claude chats that appear as official "Claude Code on Mac" installation guides supposedly from Apple Support. The chats instruct users to open Terminal and paste a command, which then silently downloads and executes malware.

At the time of reporting, two separate Claude shared chats involved in this attack were accessible publicly, each using different domains and payloads but sharing an identical social engineering approach.
 
Bleeping computer has more screenshots:


including Claude.ai MALWARE shared chat:

1778534542651.jpeg