Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
credential-stealer-activitysearch-ad-manipulationphishing-campaign-intelligenceidentity-impersonation-fraud

Fake AI Agent Downloads Spread Mac Infostealers via Google Ads and Claude Chats

Updated 18d agoFirst seen May 23, 20269 sources

Attackers are targeting macOS users with fake AI tool downloads promoted through Google Ads and public Claude.ai shared chats. Victims searching for terms such as “Claude mac download” are shown sponsored results that appear to reference the legitimate claude.ai domain, but the links redirect to shared chats containing bogus installation instructions. The lures present themselves as official guidance for running Claude-related tools on Mac, sometimes even masquerading as Apple Support content, and tell users to paste commands into Terminal that instead fetch and execute malware.

Researchers said the campaign is active and uses rotating malicious chat pages and infrastructure to evade disruption. Observed payloads include Mac-focused infostealers with behavior consistent with AMOS and Amatera/MacSync-style theft, including collection of browser credentials, cookies, and Keychain data. The activity reflects a broader trend of threat actors disguising malware as AI agents and developer tools to exploit demand for generative AI software on macOS systems.

Share:
Fake AI Agent Downloads Spread Mac Infostealers via Google Ads and Claude Chats
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
May 28, 202626d ago

Push Security identifies LLMShare campaign abusing ChatGPT share links

Push Security identified a malware campaign dubbed LLMShare that used sponsored Google ads and legitimate ChatGPT share links on OpenAI domains to funnel users to a fake download site at openew[.]app. The campaign delivered infostealer malware to Windows and macOS users, including Odyssey Stealer on macOS, while using trusted domains and anti-analysis checks to evade detection.

Hackers are now using ChatGPT share links to deliver malware - Neowin
May 25, 202629d ago

SANS analyzes fake Claude page linked to possible ACR Stealer infection

SANS ISC documented a fake Claude download page discovered via malicious Google ads that tailored infection instructions by operating system and, in the analyzed case, delivered a Windows infection chain. The activity was observed on 2026-05-25 and involved fairpoint29.com, a ZIP from primemetricsa.com, a PowerShell script from a creativecommunityinfo.art subdomain, and post-infection traffic suggesting ACR Stealer.

Possible ACR Stealer From Page Impersonating Claude
May 24, 202630d ago

Researcher identifies Google Ads and Claude chat malware campaign targeting Mac users

Security researcher Berk Albayrak identified an active campaign in which attackers used sponsored Google search results and public Claude.ai shared chats to trick Mac users into pasting malicious Terminal commands. The commands downloaded malware with MacSync-style infostealer behavior, including theft of browser credentials, cookies, and Keychain data.

Mar 12, 20263mo ago

Kaspersky reports AMOS and Amatera disguised as AI agents

Kaspersky published research on infostealers including Atomic macOS Stealer (AMOS) and Amatera being distributed under the guise of AI-related tools or agents, documenting the broader malware trend targeting users seeking AI software.

Mar 10, 20263mo ago

Pillar documents fake Claude Code pages delivering Amatera stealer

Pillar published research describing fake Claude Code pages used to distribute the Amatera infostealer to macOS users. The report identified a specific lure theme centered on Claude Code, adding technical detail on how Amatera was being delivered.

InstallFix: Fake Claude Code Pages Deliver Amatera Stealer
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

7 LINKEDOpen in app
Malware
1 linked
Affected products
3 linked
MacosTerminalClaude
Organizations
3 linked
AnthropicAppleGoogle
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Fake AI Agent Downloads Spread Mac Infostealers via Google Ads and Claude Chats | Mallory