TechBooky AI Assistant
TechBooky AI Assistant
👋 Welcome to TechBooky AI Assistant

I can help with:
🔎 Tech News
🤖 AI Topics
💻 Gadgets
☁️ Cloud
✍️ Guest Posts
📢 Advertising
🔗 Backlinks
📩 Newsletter
  • AI Search
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise With TechBooky
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Security

Attackers & Hackers Use Google Ads & Claude.AI Chats To Spread Mac Malware

Akinola Ajibola by Akinola Ajibola
May 11, 2026
in Security
Share on FacebookShare on Twitter
Share this story

Send it to someone who should read it.

f Facebook X X in LinkedIn wa WhatsApp tg Telegram @ Email
In Brief
  • There have been several users searching for “Claude Mac download” who may have encountered sponsored results that display claude.ai as the intended destination but instead direct...
  • Security researchers found that the attack chains target developers and AI enthusiasts directly, avoiding typical domain verification safety checks.  As shared, Claude Chats turned into weapons...
  • Albayrak had discovered that a shared chat on Claude.ai was posing as an official “Claude Code on Mac” installation guide that had been attributed to “Apple...

There have been several users searching for “Claude Mac download” who may have encountered sponsored results that display claude.ai as the intended destination but instead direct them to instructions advising them to install malware on their Macs.

Security researchers found that the attack chains target developers and AI enthusiasts directly, avoiding typical domain verification safety checks. 

As shared, Claude Chats turned into weapons against macOS users, whose operation was uncovered by Berk Albayrak, a security engineer at Trendyol Group, who detailed his findings on LinkedIn.

Albayrak had discovered that a shared chat on Claude.ai was posing as an official “Claude Code on Mac” installation guide that had been attributed to “Apple Support.” The chat walks some users through opening Terminal and pasting a command that quietly downloads and runs malware on their Mac.

While attempting to verify Albayrak’s findings, members of a press team had found out that a second shared Claude chat was executing the same attack using entirely different infrastructure. And both chats follow an identical structure and social engineering approach but utilize different domains and payloads. At the time of writing, both chats remained publicly accessible.

How does the macOS malware work?

The Base64 instructions had shown in the shared Claude chat download an encoded shell script from domains such as

  • In the variant observed by Albayrak [VirusTotal]: 

hxxp://customroofingcontractors[.]com/curl/b42a0ed9d1ecb72e42d6034502c304845d98805481d99cea4e259359f9ab206e

  • In the variant observed by members of the press [VirusTotal]: 

hxxps://bernasibutuwqu2[.]com/debug/loader.sh?build=a39427f9d5bfda11277f1a58c89b7c2d

The ‘loader.sh’ file that was delivered via the second link above is said to contain another set of gunzip-compressed shell instructions. This compressed script runs entirely in memory, leaving little obvious trace on the user’s system disk.

Members of the press observed that the server delivered a unique and unclear version of the payload with each request, a method known as polymorphic delivery, making it harder for security tools to flag the download based on a known hash or signature.

The variant identified by members of the press begins by checking whether the machine has keyboard input sources set to Russian or from CIS countries. If so, the script exits without taking action while it quietly sends a “cis_blocked” status ping to the attacker or hacker’s server. However, only systems that pass through this check can proceed to the next stage.

Also worth reading
Mirage Kitten Malware Shows Cyber-Espionage Pressure Across Africa And MEA Hackers use Microsoft Teams to spread Matanbuchus malware Anthropic $1.5B Copyright Settlement Gets Final Approval Anthropic And Meta Reportedly Discuss US$10bn AI Compute Deal New Malware Deployed By Chinese APT To Retain Access To Hacked Systems FBI Warns of Handala Hackers Using Telegram for Malware

Before continuing, the script is said to also collect the user’s external IP address, hostname, OS version, and keyboard locale, sending all of this data back to the attacker. This profiling before payload delivery suggests the operators have been strategically selected for their targets.

Further to this, the script also downloads a second-stage payload and executes it using osascript, macOS’s native scripting engine. This grants the attacker remote access to code execution without ever needing to drop a traditional application or binary file.

However, the variant, which was identified by Albayrak, appears to skip the profiling steps and goes straight into the execution phase. It gathers browser information such as credentials, cookies, and macOS Keychain contents; packages them up; and tends to send them to the attacker’s server. Albayrak identified this as a variant of the MacSync macOS infostealer.

The briskinternet[.]com domain seen in the Albayrak variant appeared to be offline as of the press documenting this.

Malvertising has become a recurring method for distributing malware.

Also, the members of the press had previously covered similar campaigns targeting users searching for software like GIMP, where a convincing Google ad would display a legitimate-looking domain but redirect visitors to a lookalike phishing site.

This campaign flips that model, as there is no fake domain to detect. Both Google ads seen here point to Anthropic’s real domain, claude.ai, because the attackers are hosting their malicious instructions inside Claude’s own shared chat feature. The destination URL in the ad is genuine.

This is not the first time attackers have abused AI platform-shared chats in this way. In December, the press also had reported on a similar campaign targeting ChatGPT and Grok users.

Earlier this year, threat actors ran an identical campaign aimed at macOS developers searching for Homebrew, a popular package manager. However, targeting Claude casts a much wider net, reaching non-technical users who may simply be curious about AI and are less likely to scrutinize a terminal command before running it.

Users should navigate directly to claude.ai to download the native Claude app, rather than clicking sponsored search results. The legitimate Claude Code CLI is available through Anthropic’s official documentation and does not require pasting commands from a chat interface.

As a general rule, users should treat any instructions that ask them to paste terminal commands with caution, no matter where those instructions appear to come from.

The press also reached out to Anthropic and Google for comment prior to publication.

To mitigate the threats so far, users should skip sponsored results by never clicking on Google search ads for software installation and instead navigate manually to the official domain, such as typing claude.ai directly. 

Additionally, users should be able to verify the URL path: even if a domain is legitimate, check whether the full link points to a user-generated asset like “/share/” or an external landing page such as a Squarespace subdomain. It is also critical to ban untrusted terminal execution by avoiding running unexpected curl or base64 pipe-to-shell commands provided by AI prompts or unofficial troubleshooting pages. 

Finally, system administrators should implement network restrictions, including wildcard blocks on identified attacker domains such as *.official-version[.]com and a2abotnet[.]com.

Related Reading

More contextual TechBooky stories selected from tags, categories and article context.

  • claude code1
    Leaked & Exploited Claude Code Distributes…
  • claude_bmhd
    Anthropic’s Claude AI Suffers Global Outage,…
  • claude marketplace
    Anthropic unveils Claude Marketplace to centralize…
  • anthropic1
    Anthropic’s Claude Gains Computer Control
  • claude-mac-app
    Claude Memory Rolls Out to Free Tier as Anthropic…
  • claude chatgpt
    Claude Beats ChatGPT On Google Play, Reaching 1M Daily Users
  • 2-1758799815688
    Microsoft Integrates Anthropic’s Claude AI Into Copilot
  • Claude-Code
    Claude Code Source Leak Hints at ‘Proactive’ Mode…
Keep Reading Smarter

Search TechBooky with AI

Use TechBooky's AI Search to explore the context behind this story and related coverage across the site.

Try AI Search
More On This Topic
Security
Follow TechBooky

Follow TechBooky for more technology stories and newsroom updates.

f Facebook X X in LinkedIn ig Instagram wa WhatsApp

Tags: Albayrakclaude aigoogle adsmalware
Akinola Ajibola

Akinola Ajibola

Search TechBooky
Open TechBooky AI Search Try the AI Assistant

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • Lenovo’s Record Quarter Shows AI Is Rewriting The PC Giant’s Story August 13, 2026
  • Cisco’s AI Orders Show Networking Is Now Part Of The Compute Boom August 13, 2026
  • Cerebras Raises 2026 Targets As AI Chip Demand Keeps Building August 13, 2026
  • Grok 4.6 Puts xAI Back In The Frontier Model Race August 13, 2026
  • Cognition’s $40B Target Shows AI Coding Is Still The Hottest Bet August 12, 2026
  • Tencent’s AI Spending Surge Shows China Has The Same Compute Problem August 12, 2026
  • Former Qwen Lead Launches Pragmatik Labs For China’s Agent Race August 12, 2026
  • Pixel Watch 5 Adds Breathing Emergency Detection As Google Pushes Health August 12, 2026
  • Pixel 11 Pro Fold Gets Brighter Screens And Real Dust Protection August 12, 2026
  • Pixel Tag Finally Gives Android A Real AirTag Rival August 12, 2026
  • Google’s Pixel 11 AI Features Show Gemini Moving Beyond Chat August 12, 2026
  • Foxconn’s AI Server Boom Is Now Bigger Than Its Apple Story August 12, 2026

Browse Archives

August 2026
M T W T F S S
 12
3456789
10111213141516
17181920212223
24252627282930
31  
« Jul    

Quick Links

  • About TechBooky
  • Advertise With TechBooky
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • AI Search
  • About TechBooky
  • Advertise With TechBooky
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.