Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Hackers Steal Salesforce CRM Data via Klue Breached Integration
June 18, 2026
Firefox 152 Flaws Allow Remote Code Multiple Vulnerabilities
June 18, 2026
Hackers Abuse Claude.ai Shared Chat for Feature Host
June 18, 2026
Home/CyberSecurity News/Hackers Abuse Claude.ai Shared Chat for Feature Host
CyberSecurity News

Hackers Abuse Claude.ai Shared Chat for Feature Host

Trusted artificial intelligence (AI) platforms are increasingly becoming a vector for sophisticated social engineering attacks. Hackers, for instance, recently abused Claude.ai’s shared chat feature...

Sarah simpson
Sarah simpson
June 18, 2026 3 Min Read
2 0

Trusted artificial intelligence (AI) platforms are increasingly becoming a vector for sophisticated social engineering attacks. Hackers, for instance, recently abused Claude.ai’s shared chat feature to host malicious ClickFix instructions in a new campaign.

According to TrendAI Research, attackers deployed 106 unique malicious hostnames across six campaign waves within seven weeks, continuously rotating infrastructure and testing different AI-themed lures to maximize effectiveness.

The operation marks a significant evolution in ClickFix tactics, shifting from traditional malicious hosting to trusted platforms like Claude.ai.

The campaign initially relied on GitLab Pages, using over 90 malicious subdomains hosted under the trusted *. gitlab.io domain.

These pages impersonated popular AI developer tools, including Claude AI, ChatGPT Codex, Perplexity, Cursor IDE, and JetBrains.

By leveraging Google Ads, threat actors targeted users actively searching for these tools, increasing the likelihood of interaction from technically skilled individuals.

ClickFix attacks rely on tricking users into manually executing malicious commands. In this campaign, victims were instructed to copy and paste terminal or PowerShell commands under the pretense of installing or fixing software.

Claude Shared Chats Abused for ClickFix Attacks

This technique bypasses many traditional security controls because the user unknowingly executes the payload. The campaign escalated significantly in May 2026, when attackers pivoted to abusing Claude.ai’s shared chat feature.

Claude Malvertising Campaign Infection Chain (Source : trendmicro)
Claude Malvertising Campaign Infection Chain (Source: TrendMicro)

Instead of directing victims to suspicious domains, malicious ads redirected users to legitimate Claude.ai shared chat URLs. These pages appeared trustworthy, effectively bypassing browser warnings, URL inspection, and Safe Browsing protections.

Once on the page, victims encountered fake support conversations impersonating entities such as Apple Support or development teams.

These chats provided step-by-step instructions for opening a terminal and executing a command. The command typically included a base64-encoded script that, once decoded, fetched a second-stage payload.

Top 20 Countries Targeted by the Campaign  (Source : trendmicro)
Top 20 Countries Targeted by the Campaign (Source: TrendMicro)

Analysis revealed that the payload delivered the MacSync infostealer, which targets macOS systems. The malware collects browser credentials, cookies, SSH keys, and cryptocurrency wallet data, then exfiltrates them to attacker-controlled servers.

Notably, the malware includes a check for Russian keyboard layouts, likely to avoid infecting systems in CIS regions.

The campaign’s geographic targeting was heavily concentrated in the Asia-Pacific region, which accounted for over 67 percent of victims.

“Running Claude Code on Mac” - A Shared Chat Posing as Apple Support (Source : trendmicro)
“Running Claude Code on Mac” – A Shared Chat Posing as Apple Support (Source: TrendMicro)

Taiwan alone represented more than 30 percent of observed traffic, followed by Japan and Singapore. Later waves expanded targeting to countries including India, France, and Italy, indicating ongoing optimization of ad targeting strategies.

TrendAI researchers observed at least 45 malicious Claude.ai shared chat instances in early stages, increasing to over 60 in later waves.

This shift to trusted infrastructure removes many traditional detection signals, leaving user awareness as the primary defense.

Top 10 Countries by Confirmed Victim Interactions (Source : trendmicro)
Top 10 Countries by Confirmed Victim Interactions (Source: TrendMicro)

Following responsible disclosure, Anthropic took action by banning the malicious accounts, removing harmful shared chats, and implementing additional safeguards to prevent abuse of the feature.

Security experts warn that this campaign highlights a broader trend where attackers weaponize legitimate platforms to evade detection. As AI tools become more embedded in developer workflows, such abuse is expected to increase.

Organizations are advised to educate users about ClickFix-style attacks, monitor unusual command execution, and deploy endpoint detection solutions.

Users should avoid installing software via search ads, verify URLs carefully, and never execute commands from untrusted sources.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitHackerMalwareSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Hackers Can Leverage SQL Server 2025 AI Features to Exfiltrate

Next Post

Firefox 152 Flaws Allow Remote Code Multiple Vulnerabilities

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Hackers Exploit Microsoft Fondue.exe to Side- Abuse Side-Load
June 18, 2026
Critical Cisco ISE Flaw Enables Remote Code Execution
June 18, 2026
F5 Patches NGINX Vulnerability That Enables Code Execution and DoS
June 18, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us