Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Near-Total Liquid Heat Capture Keeps AI Racks Cool

    September 22, 2026

    I Built AI Clones of My Coworkers. Things Got Weird

    September 22, 2026

    How we made the first comprehensive map of deaths along the US border’s “virtual wall”

    September 22, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Near-Total Liquid Heat Capture Keeps AI Racks Cool
    • I Built AI Clones of My Coworkers. Things Got Weird
    • How we made the first comprehensive map of deaths along the US border’s “virtual wall”
    • 4 ways to address the failures we found along the US border’s “virtual wall”
    • US and China Discuss Alerting Each Other to AI National Security Threats
    • The US spent billions on border surveillance. Why can’t it catch people before they die?
    • AI, Tariffs, Rare Minerals: What to Expect From Trump’s Upcoming Summit With Xi Jinping
    • She died at the San Diego border. A surveillance camera was in plain sight
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»Hackers abuse Google ads, Claude.ai chats to push Mac malware
    Cybersecurity

    Hackers abuse Google ads, Claude.ai chats to push Mac malware

    kirklandc008@gmail.comBy kirklandc008@gmail.comMay 10, 2026No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Claude Chat
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Attackers are abusing Google Ads and legitimate Claude.ai shared chats in an active malvertising campaign.

    Users searching for “Claude mac download” may come across sponsored search results that list claude.ai as the target website, but lead to instructions that install malware on their Mac.

    Google’s sponsored search result for ‘claude download mac’

    (BleepingComputer)

    Shared Claude Chats weaponized to target macOS users

    The campaign was spotted by Berk Albayrak, a security engineer at Trendyol Group, who shared his findings on LinkedIn.

    Researcher alerts of ongoing malvertising campaign

    Albayrak identified a Claude.ai shared chat that presents itself as an official “Claude Code on Mac” installation guide, attributed to “Apple Support.”

    The chat walks users through opening Terminal and pasting a command, which silently downloads and runs malware on their Mac.

    While attempting to verify Albayrak’s findings, BleepingComputer landed on a second shared Claude chat carrying out the same attack through entirely separate infrastructure.

    The two chats follow an identical structure and social engineering approach but use different domains and payloads. Both chats were publicly accessible at the time of writing:

    Shared Claude Chat with malicious instructions

    (BleepingComputer)

    What does the macOS malware do?

    The base64 instructions shown in the shared Claude chat download an encoded shell script from domains such as:

    • In variant seen by Albayrak [VirusTotal]: hxxp://customroofingcontractors[.]com/curl/b42a0ed9d1ecb72e42d6034502c304845d98805481d99cea4e259359f9ab206e
    • In variant seen by BleepingComputer [VirusTotal]: hxxps://bernasibutuwqu2[.]com/debug/loader.sh?build=a39427f9d5bfda11277f1a58c89b7c2d

    The ‘loader.sh’ (served by the second link above) is another set of Gunzip-compressed shell instructions:

    Base64 code retrieves first stage ‘loader.sh’ payload

    (BleepingComputer)

    This compressed shell script runs entirely in memory, leaving little obvious trace on disk.

    BleepingComputer observed the server serving a uniquely obfuscated version of the payload on each request (a technique known as polymorphic delivery), making it harder for security tools to flag the download based on a known hash or signature.

    The variant BleepingComputer identified starts by checking whether the machine has Russian or CIS-region keyboard input sources configured. If it does, the script exits without doing anything, sending a quiet cis_blocked status ping to the attacker’s server on its way out. Only machines that pass this check get the next stage:

    Shell script runs macOS malware (BleepingComputer)

    Before proceeding further, the script also collects the victim’s external IP address, hostname, OS version, and keyboard locale, sending all of it back to the attacker. This kind of victim profiling before payload delivery suggests the operators are being selective about who they target.

    The script then pulls down a second-stage payload and runs it through osascript, macOS’s built-in scripting engine. This gives the attacker remote code execution without ever dropping a traditional application or binary.

    The variant identified by Albayrak, however, appears to skip the profiling steps. It goes straight to execution.

    It harvests browser credentials, cookies, and macOS Keychain contents, packages them up, and exfiltrates them to the attacker’s server. Albayrak identified this as a variant of the MacSync macOS infostealer:

    Albayrak’s variant skips user fingerprinting step

    (BleepingComputer)

    The briskinternet[.]com domain shown above in the variant identified by Albayrak appeared to be down at the time of writing.

    When the legitimate URL is the threat

    Malvertising has become a recurring delivery mechanism for malware.

    BleepingComputer has previously reported on similar campaigns targeting users searching for software like GIMP, where a convincing Google ad would list a legitimate-looking domain but take visitors to a lookalike phishing site instead.

    This campaign flips that, as there is no fake domain to spot.

    Both Google ads seen here point to Anthropic’s real domain, claude.ai, since the attackers are hosting their malicious instructions inside Claude’s own shared chat feature. The destination URL in the ad is genuine.

    It is not, however, the first time that attackers have abused AI platform shared chats this way. In December, BleepingComputer reported a similar campaign targeting ChatGPT and Grok users.

    Users should navigate directly to claude.ai for downloading the native Claude app, rather than clicking sponsored search results. The legitimate Claude Code CLI is available through Anthropic’s official documentation and does not require pasting commands from a chat interface.

    It is good practice to generally treat any instructions asking you to paste terminal commands with caution, regardless of where those instructions appear to come from.

    BleepingComputer reached out to Anthropic and Google for comment prior to publishing.

    AI chained four zero-days into one exploit that bypassed both renderer and OS sandboxes. A wave of new exploits is coming.

    At the Autonomous Validation Summit (May 12 & 14), see how autonomous, context-rich validation finds what’s exploitable, proves controls hold, and closes the remediation loop.

    Claim Your Spot

    abuse ads chats Claude.ai Google hackers Mac malware push
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    Got an Android Phone? Google Thinks You’ll Probably Want a Googlebook Laptop

    September 21, 2026

    San Francisco Orders Meta to Stop ‘Allowing’ AI Child Abuse Ads

    September 10, 2026

    Inside Meta’s Push to Put Robots to Work in Data Centers

    August 28, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    The best VPN routers of 2026: Expert tested and reviewed

    June 14, 20263 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • Near-Total Liquid Heat Capture Keeps AI Racks Cool
    • I Built AI Clones of My Coworkers. Things Got Weird
    • How we made the first comprehensive map of deaths along the US border’s “virtual wall”
    • 4 ways to address the failures we found along the US border’s “virtual wall”
    • US and China Discuss Alerting Each Other to AI National Security Threats

    Near-Total Liquid Heat Capture Keeps AI Racks Cool

    September 22, 2026

    I Built AI Clones of My Coworkers. Things Got Weird

    September 22, 2026

    How we made the first comprehensive map of deaths along the US border’s “virtual wall”

    September 22, 2026

    4 ways to address the failures we found along the US border’s “virtual wall”

    September 22, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.