# Attackers Weaponize Google Ads and Claude.ai to Deliver macOS Malware in Sophisticated Malvertising Campaign


Security researchers have uncovered an active malware distribution campaign that exploits legitimate advertising and Claude.ai's shared chat feature to trick macOS users into downloading credentials-stealing malware.


## The Threat: Malvertising Meets Social Engineering


Cybersecurity researchers have identified an ongoing malvertising campaign that represents a disturbing convergence of ad platform exploitation and social engineering. The attack chain begins deceptively: users searching for "Claude mac download" encounter what appear to be legitimate sponsored results pointing to claude.ai—Anthropic's actual domain. However, rather than landing on installation instructions, these clicks lead to malicious Claude.ai shared chats designed to masquerade as official setup guides.


Security engineer Berk Albayrak from Trendyol Group first spotted the campaign and shared his findings publicly on LinkedIn. During verification of his report, independent researchers at BleepingComputer discovered a second variant of the same attack operating through entirely separate infrastructure, suggesting this is not an isolated incident but an active, evolving campaign.


## How the Attack Works: A Multi-Layer Deception


The social engineering mechanics of this campaign are remarkably polished. The malicious Claude.ai chats present themselves as official "Claude Code on Mac" installation guides, complete with false attribution to "Apple Support." This borrowed authority, combined with the legitimate-looking domain, creates significant friction in the average user's threat detection instincts.


The payload delivery follows a classic approach:


Step 1: Initial Compromise

  • User copies and pastes a seemingly innocent command into Terminal
  • The command executes a base64-encoded shell script

  • Step 2: First-Stage Loader

  • The decoded script downloads a gzip-compressed shell script from attacker-controlled servers
  • This first stage executes entirely in memory, leaving minimal forensic traces on disk

  • Step 3: Victim Profiling (in at least one variant)

  • The loader collects system information:
  • - External IP address

    - Hostname

    - Operating system version

    - Keyboard locale and input sources

  • This data is exfiltrated before proceeding, suggesting attackers are selective about targets

  • Step 4: Second-Stage Payload Execution

  • A second-stage payload is retrieved and executed via osascript
  • This macOS scripting engine provides remote code execution without traditional binary installation

  • ## Technical Details: The Malware's Capabilities


    The campaign delivers variants of MacSync, a known macOS information stealer with capabilities designed to harvest sensitive user data:


    | Component | Function |

    |-----------|----------|

    | Credential harvesting | Extracts saved passwords from web browsers |

    | Cookie exfiltration | Captures browser session cookies for account hijacking |

    | Keychain access | Retrieves stored macOS system credentials and SSH keys |

    | Data encryption | Packages stolen data for transmission to attacker servers |

    | Evasion techniques | Runs in memory; minimal disk footprint |


    One variant identified by Albayrak appears optimized for aggressive data theft, skipping profiling steps entirely and going straight to credential harvesting. The other variant, discovered by BleepingComputer, implements more sophisticated targeting logic, including a Russian/CIS-region keyboard detection mechanism. If the infected machine has Russian or CIS-region keyboard input sources configured, the malware exits silently without executing its payload—a curious choice that suggests either geographic targeting decisions or an attempt to avoid infecting systems in particular regions.


    ## The Campaign's Sophistication: Infrastructure and Targeting


    What distinguishes this campaign from run-of-the-mill malware distribution is its structural sophistication:


    Legitimate Platform Abuse

  • The attackers exploit Google Ads, one of the internet's most trusted advertising platforms
  • By pointing ads to claude.ai rather than a lookalike domain, the campaign eliminates a common warning signal users rely on
  • This represents a significant escalation from typical malvertising, which usually relies on misspelled or near-identical domains

  • Infrastructure Diversity

  • Multiple attack variants operate through separate command-and-control infrastructure
  • Domains observed include customroofingcontractors[.]com, bernasibutuwqu2[.]com, and briskinternet[.]com
  • This separation suggests either multiple threat actors, different campaigns under a single organization, or deliberate compartmentalization for resilience

  • Shared Chat Weaponization

  • Claude.ai's shared chat feature—designed for legitimate collaboration—is repurposed as a delivery mechanism
  • The shared chats remain publicly accessible, making this an ongoing active threat
  • By leveraging Anthropic's infrastructure, attackers gain legitimacy and reduce infrastructure costs

  • ## Implications for macOS Users and Organizations


    This campaign highlights several critical risks:


    Individual Risk Factors

  • macOS users searching for legitimate software are at heightened risk
  • The attack exploits trust in both Google's advertising and Anthropic's brand
  • Copy-paste commands from ostensibly legitimate sources pose hidden dangers
  • Safari, Chrome, and other browsers storing credentials are all potential targets

  • Organizational Exposure

  • Employees working from personal Macs may inadvertently compromise corporate credentials
  • Harvested browser cookies could enable account hijacking on business services
  • SSH keys stored in Keychain could provide lateral movement into infrastructure
  • The selective targeting logic suggests attackers may be profiling systems for specific vulnerability or value characteristics

  • Supply Chain Considerations

  • The use of legitimate advertising and chat platforms demonstrates attackers' willingness to invest in sophisticated delivery methods
  • Organizations cannot rely solely on domain reputation or platform legitimacy as security indicators

  • ## Defense Recommendations


    For Individual Users:

  • Avoid copy-pasting commands from web sources into Terminal without understanding their function
  • Verify installation sources by visiting official websites directly rather than through search results
  • Review Google Ad results carefully, even if they point to legitimate domains
  • Monitor Keychain access using macOS Security settings and restrict Keychain permissions for individual applications
  • Use a password manager instead of relying on browser credential storage

  • For Organizations:

  • Deploy endpoint detection and response (EDR) solutions capable of detecting in-memory execution via osascript
  • Implement application allowlisting to restrict which scripts can execute through osascript
  • Monitor for unusual Claude.ai chat access in employee web traffic
  • Conduct security awareness training specifically addressing malvertising and command injection risks
  • Review credentials exposed by users in affected regions—assume compromise and mandate credential rotation
  • Use multi-factor authentication on critical business accounts to limit damage from stolen credentials

  • For Researchers and Platform Providers:

  • Continue monitoring for abuse of legitimate platforms in malware distribution
  • Implement stricter controls on shared chat features to detect and remove malicious content
  • Coordinate with advertising platforms on rapid removal of malvertising campaigns

  • ---


    ## HackWire Analysis


    This campaign represents a meaningful inflection point in macOS malware distribution. For years, the majority of malware targeting macOS relied on either technical exploits (zero-days or patched vulnerabilities) or obvious social engineering (executable files, suspicious domains). This campaign sidesteps both by leveraging the legitimacy of established platforms and the inherent trust users place in well-known brands.


    What makes this particularly significant is the selectivity built into the attack. The Russian/CIS keyboard detection suggests this campaign is not indiscriminate. Attackers are profiling systems, gathering IP geolocation data, and making targeting decisions—behavior consistent with high-value operations rather than spray-and-pray malware distribution. This indicates either a sophisticated threat actor with resources to operate selectively, or proof-of-concept behavior that precedes broader exploitation.


    The broader pattern here mirrors trends we've seen in other domains: as defenders improve at spotting obviously malicious indicators (bad domains, file-based execution, suspicious email senders), attackers escalate to exploiting the very trust infrastructure that legitimate users depend on. Google Ads, Anthropic's shared chats, macOS's osascript engine—these are all components of the legitimate web and operating system ecosystem. Their abuse represents a category of threat that purely technical controls struggle to address.


    For defenders, this should trigger two concrete responses: First, mandate that employees and users verify software sources through official websites rather than search results or ads, and never execute code without understanding what it does. Second, assume that in-memory execution mechanisms like osascript and similar scripting engines will be increasingly weaponized, and implement controls to restrict or monitor their use at the organizational level.


    The timing matters as well. As Claude and similar AI tools become integral to developer workflows, they become naturally occurring in corporate environments. This campaign exploits that normalization—a Claude.ai chat reference in web traffic may be dismissed as routine rather than flagged as suspicious. Expect similar attacks against other developer-facing platforms.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Malware](https://www.hackwire.news/category/malware) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)