Threat actors are running a ClickFix-style social-engineering campaign that abuses Google sponsored search results to funnel macOS users to malicious content hosted on legitimate platforms, including Anthropic Claude public artifacts (claude.ai) and Medium pages impersonating trusted sources (e.g., Apple Support). The lures target common search queries such as “online DNS resolver,” “macOS CLI disk space analyzer,” and “HomeBrew,” then instruct victims to paste and run Terminal commands that decode/execute payloads (e.g., echo "..." | base64 -D | zsh or curl ... | zsh). Researchers (Moonlock Lab/MacPaw and AdGuard) reported that the malicious Claude artifact accumulated ~12,300 to 15,600 views, indicating significant exposure (reported as 10,000+ and 15,000+ potential victims across coverage).
The payloads deliver macOS information-stealing malware, including MacSync, which collects data such as Keychain credentials, browser data, and cryptocurrency wallet files. Reported tradecraft includes downloading and executing a shell script, using an AppleScript component for theft, staging stolen data into /tmp/osalogging.zip, and exfiltrating via HTTP POST to attacker infrastructure (e.g., a2abotnet[.]com/gate, with C2 paths like a2abotnet[.]com/dynamic). The malware attempts to blend in by spoofing legitimate macOS browser User-Agent strings and includes retry logic for large/chunked uploads, then removes staging artifacts to reduce forensic traces.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-16, a GitHub Gist published indicators of compromise tied to a macOS-focused ClickFix infostealer campaign themed around GitHub. The IOC set included numerous suspicious domains and an IP address, revealing infrastructure likely used to stage, relay, or deliver malware through Mac-focused social-engineering lures.
On 2026-05-11, a malicious Google advertisement shown for Homebrew searches redirected users to a fake Claude download page that used ClickFix-style instructions to make victims paste a command into Terminal. During execution, the malware requested the user's password and macOS permissions including Finder and folder access, and researchers captured related network traffic for analysis.
By 2026-05-10, researchers reported an active malvertising campaign in which Google Ads for Claude downloads led users to legitimate Claude.ai shared chats containing social-engineering instructions to paste malicious Terminal commands. BleepingComputer also identified a second malicious Claude shared chat using separate infrastructure, while one observed variant deployed MacSync and included victim profiling and CIS-region keyboard checks.
On 2026-04-22, researchers documented a malicious Google ad that redirected users to a fake Claude download page at cladesktop.gitlab.io, where a ClickFix-style flow delivered a password-protected ZIP containing a Mach-O arm64 malware sample saved as /tmp/helper. The infection chain used newly registered infrastructure including arkypc.com for payload delivery and communicated with a command-and-control server at 45.94.47.204:80.
Investigators observed that at least one malicious Claude guide had accumulated significant exposure, with reported view counts ranging from more than 10,000 to over 15,000. This indicated the campaign had reached a large pool of potential macOS victims through promoted search results and trusted hosting platforms.
Analysis by Moonlock Lab and AdGuard found the Claude Artifact and Medium impersonation variants likely came from the same threat actor because both retrieved second-stage payloads from the same command-and-control infrastructure. Researchers also noted the campaign fit a broader pattern of threat actors abusing public AI-sharing features previously seen with ChatGPT and Grok.
Victims who executed the copied shell commands downloaded a loader that installed the MacSync infostealer. The malware used AppleScript and other built-in macOS tools to steal Keychain data, browser information, and cryptocurrency wallet data, package it into /tmp/osalogging.zip, and exfiltrate it to attacker infrastructure including a2abotnet[.]com/gate.
A financially motivated campaign began using Google Ads and SEO-poisoned search results to lure macOS users to fake support or how-to pages. The pages abused trusted platforms including Anthropic Claude Artifacts and Medium to socially engineer victims into pasting malicious Terminal commands.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
gist.github.com
Open sourcecybersecuritynews.com
Open sourcemalware-traffic-analysis.net
Open sourceghacks.net
Open sourcehackread.com
Open sourcerescana.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.