Wednesday , June 3 2026
Claude.ai

Hackers misuse Claude.ai and Google ads chats to spread Mac malware

As AI is advancing unpredictably cyber criminals also change their attack pattern which make challenge for cyber resilience. Attackers are abusing Google Ads and legitimate Claude.ai shared chats in an active advertising campaign.

Users looking for “Claude mac download” might find ads that show claude.ai as the site to visit. However, these can actually lead to steps that put malware on their Mac.

1-Click GitHub Token Flaw Allows Attackers Steal Users’ OAuth Tokens

A serious security flaw in Visual Studio Code’s webview lets attackers take GitHub OAuth tokens. This includes read/write access to...
Read More
1-Click GitHub Token Flaw Allows Attackers Steal Users’ OAuth Tokens

TP-Link Router Flaw Enables Remote Command Execution Attacks

TP-Link has revealed a serious security problem in its Archer BE450 and Archer BE7200 Wi-Fi routers. This flaw could let...
Read More
TP-Link Router Flaw Enables Remote Command Execution Attacks

ALERT
Google patches one exploited Android zero-day and 124 issues

Google has shared the June 2026 Android security updates to fix 124 flaws, including one zero-day issue used in special...
Read More
ALERT  Google patches one exploited Android zero-day and 124 issues

CISA warns two-year-old Oracle Vuln as actively exploited in attacks

CISA has given a new warning about a serious Oracle WebLogic Server flaw, named CVE-2024-21182, and added it to its...
Read More
CISA warns two-year-old Oracle Vuln as actively exploited in attacks

Hackers Use Meta’s AI Bot to Take Over Instagram Accounts

Many Instagram users lost access to their accounts because attackers tricked Meta's AI support tools into thinking they were the...
Read More
Hackers Use Meta’s AI Bot to Take Over Instagram Accounts

Anthropic confirms Claude Mythos-class models will be public

Anthropic has said it will release Mythos-class models to the public. They had to delay this because of security concerns...
Read More
Anthropic confirms Claude Mythos-class models will be public

Threat Actors Fake FIFA Sites to Steal Personal Info

The FBI warned people in a Public Service Announcement Alert I-052726-PSA on May 27, 2026, that bad actors are running...
Read More
Threat Actors Fake FIFA Sites to Steal Personal Info

CISA gives feds 4 days to fix cPanel plugin vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has told U.S. federal agencies to secure their servers in four days....
Read More
CISA gives feds 4 days to fix cPanel plugin vulnerability

ALERT
FortiClient EMS Code Execution Flaw Exploited to Deploy Malware

A recent phishing attack aimed at FortiClient Endpoint Management Server (EMS) has used trusted admin systems to quietly install a...
Read More
ALERT  FortiClient EMS Code Execution Flaw Exploited to Deploy Malware

Anthropic Unveils Free Security Plugin for Claude Code Terminal to Detect Flaws

Anthropic has released a tool that acts like a careful assistant in your terminal. This new security plugin for Claude...
Read More
Anthropic Unveils Free Security Plugin for Claude Code Terminal to Detect Flaws
                  Google’s sponsored search result for ‘claude download mac’ (BleepingComputer)

Shared Claude Chats weaponized to target macOS users

The campaign was discovered by Berk Albayrak, a security expert at Trendyol Group, who posted his findings on LinkedIn.

Albayrak found a chat from Claude.ai that claims to be an official guide for “Claude Code on Mac,” saying it’s from “Apple Support.” The chat shows users how to open Terminal and paste a command, which secretly downloads and runs malware on their Mac.

                                     Researcher alerts of ongoing advertising campaign

Bleeping Computer reported, to verify Albayrak’s findings, they landed on a second shared Claude chat carrying out the same attack through entirely separate infrastructure.

The two chats follow an identical structure and social engineering approach but use different domains and payloads. Both chats were publicly accessible at the time of writing:

                        Shared Claude Chat with malicious instructions  (BleepingComputer)

What does the macOS malware do?

The base64 instructions shown in the shared Claude chat download an encoded shell script from domains such as:

In variant seen by Albayrak [VirusTotal]: hxxp://customroofingcontractors[.]com/curl/b42a0ed9d1ecb72e42d6034502c304845d98805481d99cea4e259359f9ab206e

In variant seen by BleepingComputer [VirusTotal]: hxxps://bernasibutuwqu2[.]com/debug/loader.sh?build=a39427f9d5bfda11277f1a58c89b7c2d’

The ‘loader.sh’ (served by the second link above) is another set of Gunzip-compressed shell instructions:

                                   Base64 code retrieves first stage ‘loader.sh’ payload (BleepingComputer)

This script runs completely in memory, leaving little clear evidence on the disk.

BleepingComputer saw that the server sent a different hidden version of the payload for each request. This method is called polymorphic delivery. It makes it more difficult for security tools to detect the download using a known hash or signature.

The variant BleepingComputer identified starts by checking whether the machine has Russian or CIS-region keyboard input sources configured. If it does, the script exits without doing anything, sending a quiet cis_blocked status ping to the attacker’s server on its way out. Only machines that pass this check get the next stage:

                                          Shell script runs macOS malware (BleepingComputer)

Before going on, the script gathers the victim’s external IP address, hostname, OS version, and keyboard settings, then sends this information to the attacker. This profiling of the victim before sending the payload shows that the attackers are careful about who they choose to target.

The script downloads a second-stage payload and runs it using osascript, which is macOS’s built-in scripting tool. This allows the attacker to run code from far away without needing to install a usual app or binary.

The type found by Albayrak seems to skip profiling steps. It goes right to execution. It collects browser usernames and passwords, cookies, and macOS Keychain data, puts them together, and sends them to the attacker’s server. Albayrak found out this is a type of the MacSync macOS infostealer:

                            Albayrak’s variant skips user fingerprinting step (BleepingComputer)

The briskinternet[.]com domain shown above in the variant identified by Albayrak appeared to be down at the time of writing. Click here to read full report.

Check Also

Terra Security

CVE-2026-25724
Terra Security researchers discovered Flaws in Anthropic’s Claude Code 

Terra Security shared results from recent tests that showed flaws in AI apps, agents, and …