Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Origin Confirms Data Breach Exposing 900,000 Customer Records
July 28, 2026
Critical Apache Shiro RCE Vulnerability Under Active Exploitation
July 28, 2026
Google Ads Push MacSync Infostealer via Fake Claude Install Guides
July 28, 2026
Home/Threats/Google Ads Push MacSync Infostealer via Fake Claude Install Guides
Threats

Google Ads Push MacSync Infostealer via Fake Claude Install Guides

Key Takeaways A new campaign leverages deceptive Google Ads to distribute the MacSync infostealer to macOS users. The attack chain begins with fake Claude Code installation guides, leading...

Emy Elsamnoudy
Emy Elsamnoudy
July 28, 2026 3 Min Read
3 0

Key Takeaways

  • A new campaign leverages deceptive Google Ads to distribute the MacSync infostealer to macOS users.
  • The attack chain begins with fake Claude Code installation guides, leading unsuspecting developers to execute malicious terminal commands.
  • MacSync is a potent infostealer designed to pilfer sensitive data including browser credentials, session cookies, SSH keys, cloud tokens, and cryptocurrency wallet information.
  • The threat actor utilizes Base64 encoding to obfuscate malicious commands and employs multiple Claude share-page lures under a single Google Ads campaign, making detection and mitigation challenging.
  • Compromised systems require extensive remediation beyond basic antivirus cleanup, including credential rotation, session revocation, and system re-imaging.

A sophisticated campaign is exploiting Google Ads to spread the MacSync infostealer, targeting macOS users with convincing, yet fraudulent, installation guides for Claude Code. This attack transforms a routine search for developer tools into a significant risk of credential theft and broader account compromise.

Table Of Content

  • Key Takeaways
  • Fake Claude Code Install Guide
  • Credential Theft and Recovery

The attack sequence begins when a user searches for assistance with Claude Code installation and inadvertently clicks on a sponsored Google search result. This initial click directs victims to a page that closely mimics Claude’s legitimate website, offering little indication that the installation guide is malicious. Users are then prompted to copy and execute a terminal command, believing it to be part of the standard installation process.

Analysts at Deriv AI said in a report that the command’s true download location is concealed using Base64 encoding, a tactic designed to evade immediate detection. Once decoded and executed, this command downloads and installs MacSync, a formidable infostealer capable of exfiltrating a wide array of sensitive data. This includes passwords, browser session tokens, developer credentials, and cryptocurrency wallet data.

Deriv AI highlighted the particular concern that this campaign does not rely on browser vulnerabilities, phishing emails, or compromised vendor websites. Instead, it capitalizes on the trust users place in search engine results, familiar brand imagery, and the common practice of selecting the top search result. This approach leverages established user behaviors to facilitate the malware’s distribution.

Fake Claude Code Install Guide

The malicious Google Ad prominently featured a Claude-themed headline and displayed the authentic claude.ai domain, enhancing its legitimacy. Upon clicking, users were led to a genuine Claude share page, deceptively presented as an installation guide and further bolstered by a false attribution to “Apple Support.” These elements collectively created a strong illusion of trustworthiness for the unsuspecting victim.

The installation command provided on the fraudulent guide did not transparently reveal the server it would connect to. Instead, it utilized Base64 text combined with shell command substitution, which decodes the malicious destination only at the point of execution. This technique is frequently observed in encoded Base64 malware commands, making quick visual inspection ineffective.

Upon decoding, the command connects to infrastructure entirely unrelated to the legitimate Claude software vendor. It also employs curl’s -k option, which instructs curl to bypass SSL/TLS certificate validation. Researchers discovered that this same hostile infrastructure supports not only the delivery of the MacSync payload but also command-and-control (C2) communications and the exfiltration of stolen cryptocurrency wallet data.

The threat actors behind this operation have deployed multiple fake Claude share-page lures under the umbrella of a single Google Ads campaign. This strategic redundancy means that simply removing one malicious advertisement or landing page may not be enough to dismantle the entire campaign, echoing patterns seen in other Google Ads installer attacks that exploit trust in search results for popular software.

Credential Theft and Recovery

MacSync is designed to harvest a broad spectrum of sensitive information from macOS systems. This includes data from the macOS Keychain, stored browser passwords, active session cookies, SSH keys, cloud service credentials, Kubernetes configurations, and various developer tokens. The theft of session cookies is particularly dangerous as it enables attackers to hijack active user sessions, bypassing multi-factor authentication (MFA) mechanisms.

For developers, the ramifications of a MacSync infection can extend far beyond a single compromised device. Gained access could potentially expose critical assets such as source code repositories, cloud environments, package publishing accounts, and deployment pipelines. This highlights a growing trend where <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/645e9c6f-b2c8-49b4-8257-b44f6e68b25b/Fake-Claude-Code-Install-Guide-Uses-Google-Ads-to-Deliver-MacSync-Infostealer.pdf?AWSAccessKeyId=ASIA2F3EMEYE2FNWBFQL&Signature=1rVP5SwLfj3tpslotN%2B4f%2FjVZoQ%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEJ3%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIQCRMn4f6RLnooPMZt8RhRG9yX66q9FLZEnNlnOg%2FedZGgIgWKKI1s9lVrkAioQdwOtmZCXi3zQtxfgGzMcShwEd1zIq8wQIZhABGgw2OTk3NTMzMDk3MDUiDMGDvOB%2B9UbvA5MkJirQBCAZxIJo%2FOmm6i%2BrR74LAG%2B%2BjXvf1q4cIQXOO4o%2F8xcrkqssAf8FrOfnMVBh%2Fevl3Xk%2ByiPAitNjfaJBltJnZi%2FlEPhKwL3ejBJJ9SB9QW%2FdkQbGQtQCtY8MrrJ5

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitMalwarephishingSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Kratos Phishing Kits Target Microsoft 365 Users

Next Post

Critical Apache Shiro RCE Vulnerability Under Active Exploitation

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
AI-Assisted Research Finds Linux Kernel Zero-Day for Root Escalation
July 28, 2026
GhostNet: Chinese Cyber Espionage Network Linked to PLA Attacks
July 28, 2026
Tengu Mirai Botnet Reboots IoT Devices, Resists Termination Attempts
July 28, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us