Claude.ai Shared Chats Abused to Host ClickFix Social Engineering
Key Takeaways Threat actors leveraged Claude.ai’s shared chat feature to host malicious ClickFix social engineering instructions. The campaign, identified by TrendAI Research, involved 106...
Key Takeaways
- Threat actors leveraged Claude.ai’s shared chat feature to host malicious ClickFix social engineering instructions.
- The campaign, identified by TrendAI Research, involved 106 unique malicious hostnames over seven weeks, initially using GitLab Pages before pivoting to Claude.ai.
- Victims were tricked into executing PowerShell or terminal commands, leading to the deployment of the MacSync infostealer on macOS systems.
- The MacSync malware exfiltrates sensitive data like browser credentials, cookies, SSH keys, and cryptocurrency wallet information.
- Anthropic, the developer of Claude.ai, has taken action to remove malicious content and implement additional safeguards.
AI Platforms Exploited in Sophisticated ClickFix Social Engineering Campaign
In a concerning development, cybercriminals have been observed exploiting trusted artificial intelligence (AI) platforms, specifically Claude.ai’s shared chat feature, to facilitate advanced social engineering attacks. This new campaign, dubbed “ClickFix,” leverages the credibility of legitimate AI services to trick users into executing malicious commands.
Table Of Content
According to research from TrendAI, the attackers orchestrated 106 distinct malicious hostnames across six waves of attacks over a seven-week period. This operation involved constant rotation of infrastructure and the refinement of AI-themed lures to maximize their effectiveness against unsuspecting users.
This campaign represents a significant tactical shift for ClickFix operations, moving away from traditional malicious hosting environments to exploit the inherent trust associated with platforms like Claude.ai.
Evolution of the Attack Chain
Initially, the campaign utilized GitLab Pages, hosting over 90 malicious subdomains under the legitimate *.gitlab.io domain. These pages were designed to impersonate popular AI development tools, including Claude AI, ChatGPT Codex, Perplexity, Cursor IDE, and JetBrains.
To reach their targets, threat actors employed Google Ads, specifically targeting individuals actively searching for these developer tools. This strategy increased the likelihood of engaging technically proficient users who would be more inclined to interact with purported software installation or fix instructions.
ClickFix attacks fundamentally rely on deceiving users into manually executing harmful commands. In this particular campaign, victims were instructed to copy and paste specific terminal or PowerShell commands under the guise of installing or repairing software.
Claude Shared Chats Abused for ClickFix Attacks
The attackers’ technique bypasses many conventional security measures because the user, unknowingly, directly executes the malicious payload. A significant escalation in the campaign occurred in May 2026, when threat actors pivoted to exploiting Claude.ai’s shared chat functionality.
Instead of directing victims to suspicious or unknown domains, the malicious advertisements redirected users to legitimate Claude.ai shared chat URLs. These pages appeared entirely trustworthy, effectively circumventing browser warnings, URL inspection tools, and standard Safe Browsing protections.
Upon landing on these seemingly benign pages, victims encountered fabricated support conversations, often impersonating entities such as Apple Support or various development teams. These deceptive chats provided step-by-step instructions for opening a terminal or PowerShell window and executing a specific command. This command typically contained a base64-encoded script that, once decoded, would retrieve a second-stage payload from attacker-controlled infrastructure.
MacSync Infostealer Deployment
Subsequent analysis revealed that the ultimate payload delivered was the MacSync infostealer, specifically designed to target macOS systems. This potent malware is capable of collecting a wide array of sensitive data, including browser credentials, cookies, SSH keys, and cryptocurrency wallet information, which it then exfiltrates to servers controlled by the attackers.
Interestingly, the MacSync malware incorporates a check for Russian keyboard layouts, suggesting an intent to avoid infecting systems within CIS (Commonwealth of Independent States) regions.
Geographic Targeting and Campaign Scope
The campaign’s geographic targeting was heavily concentrated in the Asia-Pacific region, accounting for over 67 percent of all observed victims. Taiwan alone represented more than 30 percent of the traffic, followed by Japan and Singapore. Later iterations of the campaign expanded targeting to include countries such as India, France, and Italy, indicating ongoing optimization of ad targeting strategies.
TrendAI researchers initially observed at least 45 malicious Claude.ai shared chat instances, a number that increased to over 60 in subsequent waves. This strategic shift to trusted infrastructure significantly reduces traditional detection signals, placing a greater emphasis on user vigilance as the primary defense mechanism.
Following responsible disclosure by TrendAI, Anthropic, the developer of Claude.ai, took swift action. This included banning the malicious accounts, removing the harmful shared chats, and implementing additional safeguards to prevent future abuse of the shared chat feature.
Security experts caution that this campaign underscores a growing trend where attackers weaponize legitimate and trusted platforms to evade detection. As AI tools become increasingly integrated into daily workflows, particularly for developers, the likelihood of such abuse is expected to rise.
What You Should Do
- Educate Users: Implement comprehensive training programs to educate employees about ClickFix-style attacks, emphasizing the dangers of executing commands from unverified sources.
- Monitor Command Execution: Deploy and configure Endpoint Detection and Response (EDR) solutions to monitor for unusual or unauthorized command execution on user workstations.
- Verify URLs: Always scrutinize URLs before clicking, even if they appear to originate from a trusted platform. Look for subtle discrepancies or unexpected redirects.
- Avoid Software Installation from Ads: Advise users to avoid installing software directly from search engine advertisements. Always navigate to the official vendor website for downloads.
- Never Execute Untrusted Commands: Emphasize that users should never copy and paste terminal or PowerShell commands provided by untrusted sources, even if they appear within a legitimate-looking chat interface.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.