Google Ads Push MacSync Infostealer via Fake Claude Install Guides
Key Takeaways A new campaign leverages deceptive Google Ads to distribute the MacSync infostealer to macOS users. The attack chain begins with fake Claude Code installation guides, leading...
Key Takeaways
- A new campaign leverages deceptive Google Ads to distribute the MacSync infostealer to macOS users.
- The attack chain begins with fake Claude Code installation guides, leading unsuspecting developers to execute malicious terminal commands.
- MacSync is a potent infostealer designed to pilfer sensitive data including browser credentials, session cookies, SSH keys, cloud tokens, and cryptocurrency wallet information.
- The threat actor utilizes Base64 encoding to obfuscate malicious commands and employs multiple Claude share-page lures under a single Google Ads campaign, making detection and mitigation challenging.
- Compromised systems require extensive remediation beyond basic antivirus cleanup, including credential rotation, session revocation, and system re-imaging.
A sophisticated campaign is exploiting Google Ads to spread the MacSync infostealer, targeting macOS users with convincing, yet fraudulent, installation guides for Claude Code. This attack transforms a routine search for developer tools into a significant risk of credential theft and broader account compromise.
Table Of Content
The attack sequence begins when a user searches for assistance with Claude Code installation and inadvertently clicks on a sponsored Google search result. This initial click directs victims to a page that closely mimics Claude’s legitimate website, offering little indication that the installation guide is malicious. Users are then prompted to copy and execute a terminal command, believing it to be part of the standard installation process.
Analysts at Deriv AI said in a report that the command’s true download location is concealed using Base64 encoding, a tactic designed to evade immediate detection. Once decoded and executed, this command downloads and installs MacSync, a formidable infostealer capable of exfiltrating a wide array of sensitive data. This includes passwords, browser session tokens, developer credentials, and cryptocurrency wallet data.
Deriv AI highlighted the particular concern that this campaign does not rely on browser vulnerabilities, phishing emails, or compromised vendor websites. Instead, it capitalizes on the trust users place in search engine results, familiar brand imagery, and the common practice of selecting the top search result. This approach leverages established user behaviors to facilitate the malware’s distribution.
Fake Claude Code Install Guide
The malicious Google Ad prominently featured a Claude-themed headline and displayed the authentic claude.ai domain, enhancing its legitimacy. Upon clicking, users were led to a genuine Claude share page, deceptively presented as an installation guide and further bolstered by a false attribution to “Apple Support.” These elements collectively created a strong illusion of trustworthiness for the unsuspecting victim.
The installation command provided on the fraudulent guide did not transparently reveal the server it would connect to. Instead, it utilized Base64 text combined with shell command substitution, which decodes the malicious destination only at the point of execution. This technique is frequently observed in encoded Base64 malware commands, making quick visual inspection ineffective.
Upon decoding, the command connects to infrastructure entirely unrelated to the legitimate Claude software vendor. It also employs curl’s -k option, which instructs curl to bypass SSL/TLS certificate validation. Researchers discovered that this same hostile infrastructure supports not only the delivery of the MacSync payload but also command-and-control (C2) communications and the exfiltration of stolen cryptocurrency wallet data.
The threat actors behind this operation have deployed multiple fake Claude share-page lures under the umbrella of a single Google Ads campaign. This strategic redundancy means that simply removing one malicious advertisement or landing page may not be enough to dismantle the entire campaign, echoing patterns seen in other Google Ads installer attacks that exploit trust in search results for popular software.
Credential Theft and Recovery
MacSync is designed to harvest a broad spectrum of sensitive information from macOS systems. This includes data from the macOS Keychain, stored browser passwords, active session cookies, SSH keys, cloud service credentials, Kubernetes configurations, and various developer tokens. The theft of session cookies is particularly dangerous as it enables attackers to hijack active user sessions, bypassing multi-factor authentication (MFA) mechanisms.
For developers, the ramifications of a MacSync infection can extend far beyond a single compromised device. Gained access could potentially expose critical assets such as source code repositories, cloud environments, package publishing accounts, and deployment pipelines. This highlights a growing trend where <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/645e9c6f-b2c8-49b4-8257-b44f6e68b25b/Fake-Claude-Code-Install-Guide-Uses-Google-Ads-to-Deliver-MacSync-Infostealer.pdf?AWSAccessKeyId=ASIA2F3EMEYE2FNWBFQL&Signature=1rVP5SwLfj3tpslotN%2B4f%2FjVZoQ%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEJ3%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIQCRMn4f6RLnooPMZt8RhRG9yX66q9FLZEnNlnOg%2FedZGgIgWKKI1s9lVrkAioQdwOtmZCXi3zQtxfgGzMcShwEd1zIq8wQIZhABGgw2OTk3NTMzMDk3MDUiDMGDvOB%2B9UbvA5MkJirQBCAZxIJo%2FOmm6i%2BrR74LAG%2B%2BjXvf1q4cIQXOO4o%2F8xcrkqssAf8FrOfnMVBh%2Fevl3Xk%2ByiPAitNjfaJBltJnZi%2FlEPhKwL3ejBJJ9SB9QW%2FdkQbGQtQCtY8MrrJ5
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.