Tools AI Risk Radar ai-incident-0058
Incident record
Bought search ads steered Mac users to weaponised shared Claude chats and a pasted Terminal command
- Severity
- High
- Status
- Contained
- Type
- Deepfake/Fraud
- Target
- Mac users searching for Claude; browser credentials, the macOS keychain, crypto wallets, SSH and cloud credentials
- Actor
- criminal
What happened
Zscaler published research on a campaign it calls ClaudeFix: threat actors bought Google Search ads on terms such as 'claude', 'claude ai' and 'claude mac', in English and Chinese, that led to weaponised shared chats hosted on the legitimate claude.ai domain and labelled as shared by 'Apple Support'. The chats instructed Mac users to paste a base64-encoded curl command into Terminal, and the chain delivered MacSync Stealer, which takes browser credentials, the macOS keychain, crypto wallets and extensions, SSH, AWS and Kubernetes credentials, and seed and key files.
Zscaler saw the campaign in its own customer traffic between 12 and 19 June 2026, across 22 campaign IDs, and lists 208 hosting domains in its indicators. Trend Micro, which published on the same shared-chat abuse a month earlier on 17 June 2026, tracked the wider campaign from 8 April 2026 and dates the pivot onto claude.ai shared chats to 6 May, with at least 45 share links used in the first wave on the platform and at least 61 in the second. Trend Micro says that after it notified Anthropic, the company investigated, banned the accounts responsible, disabled the malicious shared conversations, and is putting further abuse mitigations in place for the shared chat feature. Trend Micro measured the victims as heavily concentrated in Asia-Pacific, 67.4 per cent of confirmed victim traffic, with Taiwan alone at 772 counts, or 30.5 per cent. Huntress separately published research on 6 August 2026 into a related wallet-draining macOS ClickFix stealer carrying a DRAIN function that empties identified wallets, with infrastructure on the sanctioned Russian host Aeza Group. No verified loss totals have been published for any of the campaigns.
Sources
- Zscaler: ClaudeFix, shared Claude chats meet ClickFix (15 July 2026)www.zscaler.com/blogs/security-research/claudefix-shared-cla…
- Trend Micro: threat actors abuse claude.ai shared chat for a ClickFix malvertising campaign (17 June 2026)www.trendmicro.com/en_us/research/26/f/claudeai-shared-chat-…
- Huntress: Mac crypto-draining malware (6 August 2026)www.huntress.com/blog/mac-crypto-draining-malware
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026