Hackers abuse Google ads, Claude.ai chats to push Mac malware
AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

Prime Big Deal Days · Oct 6–7Offer from Amazon

Get the latest gadgets delivered free — and shop member deals

  • Fast, free delivery on millions of items
  • Access to Prime Big Deal Days deals on October 6–7
  • Prime Video, Amazon Music and more included
Start your free Prime trial Free trial for eligible customers · Cancel anytime
As an affiliate, we earn on qualifying purchases.

Hackers are using Google Ads and legitimate Claude.ai shared chats to push Mac malware through a malvertising campaign. Researchers have confirmed malicious chat content and delivery methods, but the full scope remains unclear.

Cybercriminals are actively exploiting Google Ads and the shared chat feature of Claude.ai to distribute malware to Mac users, with researchers confirming malicious campaigns involving weaponized chats and malicious links.

Security engineer Berk Albayrak from Trendyol Group identified a shared Claude.ai chat that impersonates an ‘Apple Support’ guide, instructing users to open Terminal and run commands that silently download and execute malware on their Macs. BleepingComputer independently verified a second malicious chat with similar tactics, hosted on different domains and infrastructure.

The malware payloads, retrieved via base64-encoded shell scripts, are highly obfuscated and polymorphic, making detection difficult. One variant performs victim profiling by checking for Russian or CIS-region keyboard settings, then exfiltrates system information and credentials, including browser cookies and Keychain data. Another variant directly harvests sensitive data without profiling, resembling known macOS infostealers like MacSync.

Both campaigns rely on Google Ads that appear to promote legitimate links to claude.ai, but redirect users to malicious instructions hosted within shared chats. Researchers warn that these attacks leverage the trust in AI platforms and legitimate advertising to deceive users into executing harmful commands.

Why It Matters

This campaign highlights the evolving tactics of cybercriminals exploiting AI platforms and advertising channels to target Mac users. The use of shared AI chats for malware delivery represents a new vector that bypasses traditional security measures, increasing the risk of data theft and system compromise. The incident underscores the importance of caution when following terminal instructions from unverified sources and the need for vigilance in digital advertising and AI platform security.

Amazon

Mac malware protection software

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Background

Malvertising campaigns have previously targeted users searching for software like GIMP or ChatGPT, often using fake domains or phishing sites. This campaign is notable for abusing legitimate AI platform features and Google Ads, which are typically trusted by users. The technique of weaponizing shared AI chats is relatively new, with prior reports of similar abuse involving ChatGPT and Grok. Researchers advise users to download official apps directly from verified sources rather than following suspicious links or chat instructions.

“We found shared Claude chats that serve as attack vectors for malware, with instructions that appear legitimate but actually compromise Mac users.”

— Berk Albayrak, security engineer at Trendyol Group

“Both campaigns used Google Ads pointing to legitimate Claude.ai domains but hosted malicious instructions within shared chats, illustrating a sophisticated abuse of trusted platforms.”

— BleepingComputer

Amazon

macOS antivirus tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

What Remains Unclear

It remains unclear how widespread the campaign is, whether other AI platforms are being similarly abused, or if additional variants of the malware are in circulation. The full scope and attribution of the attackers are still under investigation.

Amazon

cybersecurity for Mac

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

What’s Next

Security researchers and platform providers are expected to analyze the malware further, develop detection signatures, and strengthen defenses. Users are advised to avoid clicking on suspicious ads and to download software only from official sources. Ongoing monitoring will reveal whether the campaign expands or evolves.

Amazon

Mac data recovery software

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

How can I protect myself from this malware campaign?

Always download software from official sources, avoid clicking on suspicious ads, and be cautious when following terminal commands from unverified chats or websites. Keep your macOS and security software up to date.

No, only specific ads promoting ‘Claude download Mac’ or similar keywords are involved. Users should verify the destination URL before clicking and avoid following instructions from untrusted chats.

Is this attack limited to Mac users?

Currently, the campaign appears targeted at Mac users, especially those searching for Claude.ai Mac downloads. There is no confirmed evidence of Windows or Linux targeting in this campaign.

What should I do if I suspect I’ve been compromised?

Disconnect from the internet, run a full security scan with updated antivirus tools, change compromised passwords, and avoid executing unknown terminal commands. Report the incident to security professionals if necessary.

FALL

Fall Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

Container Security: Protecting Docker and Kubernetes Systems

Meta Description: Maintaining robust container security for Docker and Kubernetes requires layered strategies that you won’t want to miss exploring further.

HDD Firmware Hacking

A recent investigation reveals how hackers are modifying HDD firmware to exploit vulnerabilities, raising security concerns for storage devices.

The newest Instagram “exploit” is the goofiest I’ve seen

A recent Instagram vulnerability allows attackers to hijack accounts using a surprisingly simple support process, raising security concerns.

The Bottleneck Moved: Inside Anthropic’s Expansion of Project Glasswing

Anthropic’s Project Glasswing is expanding to over 150 organizations, shifting focus from finding vulnerabilities to fixing them, particularly in critical infrastructure.