HackRead reports that information-stealing MacSync malware has been deployed through the exploitation of Google Ads and bogus Claude AI guides as part of a new ClickFix attack campaign.Threat actors leveraged compromised Google Ads accounts from Canadian children's charity Earth Rangers and Colombian watch retailer TSQ SA to host a Claude AI artifact or a Medium article that would appear on top of search results when macOS users query about common technical terms, according to Moonlock Lab researchers. Both the Claude AI artifact, which has been seen more than 15,600 times, and the Medium article, which impersonates the Apple Support Team, lure targets into copying and pasting code into their Terminal that would ultimately result in the clandestine injection of the MacSync infostealer.MacSync targets not only macOS devices' Keychain but also their crypto wallet private keys and browser-stored logins, which are then exfiltrated through a ZIP file. Such a threat should prompt users to be wary of pasting commands into Terminal.
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
Related Terms
AdwareYou can skip this ad in 5 seconds




