# The Week Attackers Weaponized Trust: From Claude Chats to Windows DNS, the Ecosystem Got Messier


Quiet weeks don't exist in cybersecurity. But last week wasn't quiet in the way that matters — it wasn't a single critical zero-day or nation-state campaign dominating headlines. Instead, it was a slow-burn demonstration of how attackers now treat the entire technology stack as an attack surface. Microsoft, Google, Apple, Anthropic, npm. Each trusted company. Each exploited.


The patterns emerging from this week's threat landscape reveal something darker than any individual vulnerability: trusted platforms have become the primary delivery mechanism for commodity threats. And defenders are still building their arsenals for a different war.


## The Threat: Trust as a Liability


Over the past seven days, researchers documented at least 25 distinct threat campaigns, but the story isn't in the volume—it's in the architecture. Attackers aren't breaking into systems anymore. They're using the front door that legitimate vendors left open.


Three campaigns show this inversion clearly:


  • SearchJack: 23 Chrome extensions posing as productivity tools, news readers, and satellite imagery utilities, together affecting approximately 758,000 users while systematically rerouting all search queries through monetization brokers.
  • Meow AppleScript Stealer: A Russian-speaking operation using fake malware-scanning websites (ClickFix lures) to trick macOS users into executing a single curl command—the entire attack payload lives in memory.
  • Claude Chat Abuse: Shared chat links on Anthropic's Claude platform weaponized to deliver ClickFix pages and malware directly from a trusted AI company's domain.

  • ## Background and Context: The Ecosystem Under Siege


    The week began with Microsoft's announcement that DNS-over-HTTPS (DoH) is now generally available on Windows Server 2025—a legitimate security improvement. But the timing underscores a larger problem: while vendors ship encryption and trust mechanisms, attackers are already past the perimeter.


    SearchJack Extensions demonstrates this most clearly. These aren't malware droppers or info-stealers in the traditional sense. Each extension advertises a legitimate use case: map readers, news aggregators, productivity suites. Users install them willingly. The monetization happens transparently (to the operator) in the background—every search query flows through third-party brokers before users ever see a result.


    This is economically rational for both the operators and the affiliate networks. Estimates suggest the campaign spans at least eight distinct monetization brokers. At 758,000 affected users, even a 1-2% click-through rate on injected ads or sponsored links generates substantial revenue.


    But as researcher Jean-Marie R. noted: "While this might look like simple adware, it is a real security risk." The operators control the web traffic. Switching from affiliate revenue to phishing link injection requires zero code updates. The attack surface simply redirects.


    Meow, meanwhile, represents the fileless attack category reaching maturity. The entire infection chain—from initial social engineering through credential harvesting to persistent C2—never touches disk. The attack sequence:


    1. Victim visits a fake malware-scanning website (ClickFix lure)

    2. Social engineering prompt directs victim to copy/paste a curl command

    3. curl fetches a gzip-compressed stager from attacker infrastructure

    4. Second stage (the Meow AppleScript) pipes directly into osascript memory

    5. Fake system dialog harvests credentials, browser data, session cookies, keychain contents

    6. Legitimate cryptocurrency wallet applications get trojanzied for persistence

    7. C2 channel opens for arbitrary payload execution


    The entire chain is deliberately designed to leave no static artifacts on disk until persistence is established. Endpoint detection and response (EDR) systems tuned for file-based detection see nothing.


    The victims? Primarily technology, media, and business services sectors across Asia, North America, and Oceania—regions with both high cryptocurrency adoption and users sophisticated enough to click on fake malware scanners.


    ## Technical Details: How Attackers Are Weaponizing Trusted Platforms


    ### SearchJack's Browser Extension Monetization


    The 23 extensions function through a three-stage traffic redirection model:


    | Stage | Mechanism | Detection Difficulty |

    |-------|-----------|---------------------|

    | Installation | Deceptive Chrome Store listing (legitimate advertised purpose) | High (passes store vetting) |

    | Execution | Hook browser's default search engine, inject monetization middleware | High (appears as feature) |

    | Monetization | Route searches through 8+ affiliate brokers before delivering results | Medium (visible in network logs if analyzed) |


    The privacy violation is immediate and continuous: every search query is logged by third parties. The security risk is structural: once operators control the traffic path, they can inject anything.


    ### Meow's Fileless AppleScript Architecture


    Victim Social Engineering
        ↓
    curl command execution (no file writes)
        ↓
    gzip-compressed stager download (memory-only)
        ↓
    AppleScript payload piped to osascript (in-memory execution)
        ↓
    Fake system dialog (looks legitimate on macOS)
        ↓
    Credential harvesting + Wallet trojanziation
        ↓
    Persistent C2 channel

    The attack's sophistication lies not in complexity but in elimination of traditional forensic artifacts. No .dmg file. No executable. No LaunchAgent in ~/.LaunchAgents. Just in-memory execution of legitimate macOS utilities running attacker-controlled code.


    ### Claude Shared Chats as Delivery URLs


    The misuse of Anthropic's Claude shared chat feature represents a particularly concerning trend: attackers using legitimate SaaS platforms' domain authority to bypass URL reputation filters.


    A Claude shared chat link appears as:

    claude.ai/share/[token]

    This URL has:

  • High domain reputation (claudeai.com/claude.ai)
  • HTTPS encryption by default
  • User trust built into the Claude brand

  • Attackers created shared chats containing ClickFix lures, then distributed these links via phishing campaigns. Security tools that check URL reputation against the domain (not the page content) may flag it as safe. Browsers show a padlock for a trusted vendor.


    The attacker gains Claude's reputation as a delivery mechanism without modifying Claude's systems.


    ## Implications for Organizations


    Three critical implications emerge:


    ### 1. Browser Extensions Are No Longer a Contained Threat

    SearchJack's 758,000 users represent the largest browser extension monetization campaign documented. The economic model is working. Similar operations will follow. Organizations cannot rely on Chrome Web Store curation or user awareness to prevent installation.


    Control point: Mandate extension allowlists via Chrome Enterprise policies. Audit installed extensions weekly. Block obscure or single-purpose extensions.


    ### 2. Fileless Attacks on macOS Are Becoming Standard Operating Procedure

    Meow demonstrates that sophisticated actors no longer need to write files to disk. AppleScript, bash, and legitimate system utilities provide sufficient execution capability. Traditional EDR/SIEM tools tuned for file-based detection will miss these attacks entirely.


    Control point: Monitor osascript and bash command execution at the process level. Review browser history and keychain access logs. Implement behavioral detection for unusual credential access patterns.


    ### 3. Trusted Platforms Are Now Part of the Attack Surface

    Anthropic didn't fail to secure Claude chats—the feature works as designed. But attackers weaponized it anyway. Microsoft shipped DoH for security. Attackers will find ways around it. Trust is no longer a security property; it's an attack vector.


    Control point: Assume every major platform (email, chat, SaaS, payment, cloud) will be used to deliver attacks. Monitor outbound traffic from these platforms, not inbound. Review link previews before clicking, especially from forwarded or shared content.


    ## Recommendations


    For Enterprise Security Teams:


  • This week: Audit installed Chrome extensions. Cross-reference against allowlist policies. Block those not explicitly authorized.
  • This month: Implement process-level monitoring for osascript and bash execution with unusual credential or browser data access patterns.
  • This quarter: Model assume-breach scenarios where attackers gain access to Claude, Slack, email, or other trusted SaaS platforms. Test detection and response times.

  • For Endpoint Users:


  • Disable browser extensions unless explicitly needed. Install only from publishers you recognize.
  • macOS users: Be extremely suspicious of fake malware-scanning websites. Never paste unknown curl commands into Terminal.
  • Don't trust URL reputation checks for domain-only scanning. Preview links before clicking.

  • ## HackWire Analysis


    This week illustrates a mature shift in attack economics: attackers no longer exploit product flaws; they monetize product adoption. SearchJack doesn't break Chrome—it uses Chrome's extension system exactly as designed. Meow doesn't exploit a macOS vulnerability—it uses AppleScript as intended. Claude chat abuse doesn't compromise Anthropic's security—it borrows their domain reputation.


    The pattern repeats across the ecosystem because the economics work. A 758,000-user browser extension campaign generating affiliate revenue is sustainable. Fileless attacks that leave no forensic traces are scalable. Legitimate platform abuse avoids the detection overhead of traditional malware.


    This isn't a flaw in Microsoft, Google, Apple, or Anthropic's engineering. It's a flaw in the assumption that trust is a security property. It isn't. Trust is a credential that attackers steal. The vendors ship it; the bad guys use it.


    The defensive implication: organizations must shift from "secure the perimeter" to "monitor trusted channels." Assume every major platform will be used to deliver attacks. The question is no longer "will attackers abuse legitimate platforms?" It's "which trusted platform will they abuse next, and how fast can you detect it?"


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Malware](https://www.hackwire.news/category/malware) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)