Attackers are targeting macOS users with fake AI tool downloads promoted through Google Ads and public Claude.ai shared chats. Victims searching for terms such as “Claude mac download” are shown sponsored results that appear to reference the legitimate claude.ai domain, but the links redirect to shared chats containing bogus installation instructions. The lures present themselves as official guidance for running Claude-related tools on Mac, sometimes even masquerading as Apple Support content, and tell users to paste commands into Terminal that instead fetch and execute malware.
Researchers said the campaign is active and uses rotating malicious chat pages and infrastructure to evade disruption. Observed payloads include Mac-focused infostealers with behavior consistent with AMOS and Amatera/MacSync-style theft, including collection of browser credentials, cookies, and Keychain data. The activity reflects a broader trend of threat actors disguising malware as AI agents and developer tools to exploit demand for generative AI software on macOS systems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Push Security identified a malware campaign dubbed LLMShare that used sponsored Google ads and legitimate ChatGPT share links on OpenAI domains to funnel users to a fake download site at openew[.]app. The campaign delivered infostealer malware to Windows and macOS users, including Odyssey Stealer on macOS, while using trusted domains and anti-analysis checks to evade detection.
SANS ISC documented a fake Claude download page discovered via malicious Google ads that tailored infection instructions by operating system and, in the analyzed case, delivered a Windows infection chain. The activity was observed on 2026-05-25 and involved fairpoint29.com, a ZIP from primemetricsa.com, a PowerShell script from a creativecommunityinfo.art subdomain, and post-infection traffic suggesting ACR Stealer.
Security researcher Berk Albayrak identified an active campaign in which attackers used sponsored Google search results and public Claude.ai shared chats to trick Mac users into pasting malicious Terminal commands. The commands downloaded malware with MacSync-style infostealer behavior, including theft of browser credentials, cookies, and Keychain data.
Kaspersky published research on infostealers including Atomic macOS Stealer (AMOS) and Amatera being distributed under the guise of AI-related tools or agents, documenting the broader malware trend targeting users seeking AI software.
Pillar published research describing fake Claude Code pages used to distribute the Amatera infostealer to macOS users. The report identified a specific lure theme centered on Claude Code, adding technical detail on how Amatera was being delivered.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcescworld.com
Open sourceghacks.net
Open sourcepushsecurity.com
Open sourceneowin.net
Open sourceisc.sans.edu
Open sourcecysecurity.news
Open sourcekaspersky.co.uk
Open sourcepillar.security
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.