# Attackers Weaponize Google Ads and Claude.ai to Deliver macOS Malware in Sophisticated Malvertising Campaign
Security researchers have uncovered an active malware distribution campaign that exploits legitimate advertising and Claude.ai's shared chat feature to trick macOS users into downloading credentials-stealing malware.
## The Threat: Malvertising Meets Social Engineering
Cybersecurity researchers have identified an ongoing malvertising campaign that represents a disturbing convergence of ad platform exploitation and social engineering. The attack chain begins deceptively: users searching for "Claude mac download" encounter what appear to be legitimate sponsored results pointing to claude.ai—Anthropic's actual domain. However, rather than landing on installation instructions, these clicks lead to malicious Claude.ai shared chats designed to masquerade as official setup guides.
Security engineer Berk Albayrak from Trendyol Group first spotted the campaign and shared his findings publicly on LinkedIn. During verification of his report, independent researchers at BleepingComputer discovered a second variant of the same attack operating through entirely separate infrastructure, suggesting this is not an isolated incident but an active, evolving campaign.
## How the Attack Works: A Multi-Layer Deception
The social engineering mechanics of this campaign are remarkably polished. The malicious Claude.ai chats present themselves as official "Claude Code on Mac" installation guides, complete with false attribution to "Apple Support." This borrowed authority, combined with the legitimate-looking domain, creates significant friction in the average user's threat detection instincts.
The payload delivery follows a classic approach:
Step 1: Initial Compromise
Step 2: First-Stage Loader
Step 3: Victim Profiling (in at least one variant)
- External IP address
- Hostname
- Operating system version
- Keyboard locale and input sources
Step 4: Second-Stage Payload Execution
osascript## Technical Details: The Malware's Capabilities
The campaign delivers variants of MacSync, a known macOS information stealer with capabilities designed to harvest sensitive user data:
| Component | Function |
|-----------|----------|
| Credential harvesting | Extracts saved passwords from web browsers |
| Cookie exfiltration | Captures browser session cookies for account hijacking |
| Keychain access | Retrieves stored macOS system credentials and SSH keys |
| Data encryption | Packages stolen data for transmission to attacker servers |
| Evasion techniques | Runs in memory; minimal disk footprint |
One variant identified by Albayrak appears optimized for aggressive data theft, skipping profiling steps entirely and going straight to credential harvesting. The other variant, discovered by BleepingComputer, implements more sophisticated targeting logic, including a Russian/CIS-region keyboard detection mechanism. If the infected machine has Russian or CIS-region keyboard input sources configured, the malware exits silently without executing its payload—a curious choice that suggests either geographic targeting decisions or an attempt to avoid infecting systems in particular regions.
## The Campaign's Sophistication: Infrastructure and Targeting
What distinguishes this campaign from run-of-the-mill malware distribution is its structural sophistication:
Legitimate Platform Abuse
claude.ai rather than a lookalike domain, the campaign eliminates a common warning signal users rely onInfrastructure Diversity
customroofingcontractors[.]com, bernasibutuwqu2[.]com, and briskinternet[.]comShared Chat Weaponization
## Implications for macOS Users and Organizations
This campaign highlights several critical risks:
Individual Risk Factors
Organizational Exposure
Supply Chain Considerations
## Defense Recommendations
For Individual Users:
For Organizations:
For Researchers and Platform Providers:
---
## HackWire Analysis
This campaign represents a meaningful inflection point in macOS malware distribution. For years, the majority of malware targeting macOS relied on either technical exploits (zero-days or patched vulnerabilities) or obvious social engineering (executable files, suspicious domains). This campaign sidesteps both by leveraging the legitimacy of established platforms and the inherent trust users place in well-known brands.
What makes this particularly significant is the selectivity built into the attack. The Russian/CIS keyboard detection suggests this campaign is not indiscriminate. Attackers are profiling systems, gathering IP geolocation data, and making targeting decisions—behavior consistent with high-value operations rather than spray-and-pray malware distribution. This indicates either a sophisticated threat actor with resources to operate selectively, or proof-of-concept behavior that precedes broader exploitation.
The broader pattern here mirrors trends we've seen in other domains: as defenders improve at spotting obviously malicious indicators (bad domains, file-based execution, suspicious email senders), attackers escalate to exploiting the very trust infrastructure that legitimate users depend on. Google Ads, Anthropic's shared chats, macOS's osascript engine—these are all components of the legitimate web and operating system ecosystem. Their abuse represents a category of threat that purely technical controls struggle to address.
For defenders, this should trigger two concrete responses: First, mandate that employees and users verify software sources through official websites rather than search results or ads, and never execute code without understanding what it does. Second, assume that in-memory execution mechanisms like osascript and similar scripting engines will be increasingly weaponized, and implement controls to restrict or monitor their use at the organizational level.
The timing matters as well. As Claude and similar AI tools become integral to developer workflows, they become naturally occurring in corporate environments. This campaign exploits that normalization—a Claude.ai chat reference in web traffic may be dismissed as routine rather than flagged as suspicious. Expect similar attacks against other developer-facing platforms.
— HackWire Editorial
---
## Related Coverage