Briefing

Hackers abuse Google ads, Claude.ai chats to push Mac malware

security
by Ax Sharma · Claude Anthropic

Block malicious Claude.ai shared chat links in Google Ads and monitor for terminal command instructions.

What to do now

Block malicious Claude.ai shared chat links in Google Ads and monitor for terminal command instructions.

Summary

Attackers are exploiting Google Ads and Claude.ai shared chats to distribute macOS malware in a malvertising campaign that targets users searching for "Claude mac download". The malicious shared chats present themselves as official "Claude Code on Mac" installation guides, but instruct users to paste a terminal command that silently downloads and runs a base64‑encoded shell script. The script fetches a second‑stage loader that runs entirely in memory, leaving little trace on disk, and checks for Russian or CIS keyboard layouts before collecting the victim's external IP, hostname, OS version, and keyboard locale for exfiltration. One variant of the payload harvests browser credentials, cookies, and macOS Keychain contents, while the other variant skips profiling and directly exfiltrates data. Both chats use distinct domains—customroofingcontractors.com and bernasibutuwqu2.com—yet the destination URL in the ad points to the legitimate claude.ai domain, making the attack harder to spot. The campaign mirrors earlier attacks that weaponized AI platform shared chats to target ChatGPT and Grok users. Users are advised to navigate directly to claude.ai for downloading the native Claude app and to treat any terminal command instructions with caution. The malicious instructions are hosted on the authentic Anthropic domain, not a spoofed site, underscoring the need for vigilance in AI‑driven ad ecosystems.

Key changes

  • Attackers use Google Ads for "Claude mac download" to serve malicious Claude.ai shared chats.
  • Shared chats instruct users to paste a terminal command that downloads a base64‑encoded shell script.
  • The script fetches a second‑stage loader that runs entirely in memory, leaving little disk trace.
  • The payload checks for Russian/CIS keyboard layout and collects IP, hostname, OS version, and locale before exfiltration.
  • One variant harvests browser credentials, cookies, and Keychain data; the other skips profiling and directly exfiltrates data.
  • The campaign uses two distinct domains: customroofingcontractors.com and bernasibutuwqu2.com.
  • The malicious instructions are hosted on the legitimate claude.ai domain, not a spoofed site.
  • Previous similar campaigns targeted ChatGPT and Grok users via AI platform shared chats.

Affects

ads-customers

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting