Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
credential-stealer-activitysearch-ad-manipulationphishing-campaign-intelligencecommand-and-control-method

ClickFix Campaign Abuses Claude Artifacts and Google Ads to Deliver macOS Infostealers

Updated 1mo agoFirst seen Feb 14, 202611 sources

Threat actors are running a ClickFix-style social-engineering campaign that abuses Google sponsored search results to funnel macOS users to malicious content hosted on legitimate platforms, including Anthropic Claude public artifacts (claude.ai) and Medium pages impersonating trusted sources (e.g., Apple Support). The lures target common search queries such as “online DNS resolver,” “macOS CLI disk space analyzer,” and “HomeBrew,” then instruct victims to paste and run Terminal commands that decode/execute payloads (e.g., echo "..." | base64 -D | zsh or curl ... | zsh). Researchers (Moonlock Lab/MacPaw and AdGuard) reported that the malicious Claude artifact accumulated ~12,300 to 15,600 views, indicating significant exposure (reported as 10,000+ and 15,000+ potential victims across coverage).

The payloads deliver macOS information-stealing malware, including MacSync, which collects data such as Keychain credentials, browser data, and cryptocurrency wallet files. Reported tradecraft includes downloading and executing a shell script, using an AppleScript component for theft, staging stolen data into /tmp/osalogging.zip, and exfiltrating via HTTP POST to attacker infrastructure (e.g., a2abotnet[.]com/gate, with C2 paths like a2abotnet[.]com/dynamic). The malware attempts to blend in by spoofing legitimate macOS browser User-Agent strings and includes retry logic for large/chunked uploads, then removes staging artifacts to reduce forensic traces.

Share:
ClickFix Campaign Abuses Claude Artifacts and Google Ads to Deliver macOS Infostealers
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
May 16, 20261mo ago

GitHub Gist publishes IOCs for GitHub-themed macOS ClickFix campaign

On 2026-05-16, a GitHub Gist published indicators of compromise tied to a macOS-focused ClickFix infostealer campaign themed around GitHub. The IOC set included numerous suspicious domains and an IP address, revealing infrastructure likely used to stage, relay, or deliver malware through Mac-focused social-engineering lures.

MacOS_Github_Themed_Clickfix_16052026 · GitHub
May 11, 20261mo ago

Google ad for Homebrew leads to fake Claude ClickFix infection

On 2026-05-11, a malicious Google advertisement shown for Homebrew searches redirected users to a fake Claude download page that used ClickFix-style instructions to make victims paste a command into Terminal. During execution, the malware requested the user's password and macOS permissions including Finder and folder access, and researchers captured related network traffic for analysis.

Malware-Traffic-Analysis.net - 2026-05-11: Google ad for Homebrew leads to macOS malware infection
May 10, 20261mo ago

Google Ads route users to malicious Claude shared chats on claude.ai

By 2026-05-10, researchers reported an active malvertising campaign in which Google Ads for Claude downloads led users to legitimate Claude.ai shared chats containing social-engineering instructions to paste malicious Terminal commands. BleepingComputer also identified a second malicious Claude shared chat using separate infrastructure, while one observed variant deployed MacSync and included victim profiling and CIS-region keyboard checks.

Hackers abuse Google ads, Claude.ai chats to push Mac malware
Apr 22, 20262mo ago

Fake Claude download ad delivers new macOS ClickFix payload

On 2026-04-22, researchers documented a malicious Google ad that redirected users to a fake Claude download page at cladesktop.gitlab.io, where a ClickFix-style flow delivered a password-protected ZIP containing a Mach-O arm64 malware sample saved as /tmp/helper. The infection chain used newly registered infrastructure including arkypc.com for payload delivery and communicated with a command-and-control server at 45.94.47.204:80.

Malware-Traffic-Analysis.net - 2026-04-22: Malicious ad leads to ClickFix-style page for macOS malware
Feb 13, 20264mo ago

Researchers report campaign reach exceeded 15,000 views

Investigators observed that at least one malicious Claude guide had accumulated significant exposure, with reported view counts ranging from more than 10,000 to over 15,000. This indicated the campaign had reached a large pool of potential macOS victims through promoted search results and trusted hosting platforms.

Researchers link multiple campaign variants to the same actor

Analysis by Moonlock Lab and AdGuard found the Claude Artifact and Medium impersonation variants likely came from the same threat actor because both retrieved second-stage payloads from the same command-and-control infrastructure. Researchers also noted the campaign fit a broader pattern of threat actors abusing public AI-sharing features previously seen with ChatGPT and Grok.

MacSync infostealer delivered through Claude and Medium lures

Victims who executed the copied shell commands downloaded a loader that installed the MacSync infostealer. The malware used AppleScript and other built-in macOS tools to steal Keychain data, browser information, and cryptocurrency wallet data, package it into /tmp/osalogging.zip, and exfiltrate it to attacker infrastructure including a2abotnet[.]com/gate.

Threat actors launch ClickFix campaign targeting macOS users

A financially motivated campaign began using Google Ads and SEO-poisoned search results to lure macOS users to fake support or how-to pages. The pages abused trusted platforms including Anthropic Claude Artifacts and Medium to socially engineer victims into pasting malicious Terminal commands.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

39 LINKEDOpen in app
Affected products
18 linked
MacosClaudeTerminalGoogle SitesMacosChatgptTerminalApplescriptWiresharkChatgptGoogle SearchClaude Code CliClaude CodeApple SupportGimpAdguardGoogle SearchFinder
Organizations
18 linked
AnthropicGoogleAppleFramerMediumMacpawBleepingComputerAdguardTrendyol GroupGitLabKasperskyOpenaiHackread.comxAIRescanaMoonlock LabEarth RangersT S Q SA
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

ClickFix Campaign Abuses Claude Artifacts and Google Ads to Deliver macOS Infostealers | Mallory