MacSync Stealer v1.1.2 ("claude1"): Malicious Google Ad Impersonates Claude Code Installer to Hijack macOS Systems — Threadlinqs Intelligence
As of 2026-07-01, MacSync Stealer v1.1.2 ("claude1"): Malicious Google Ad Impersonates Claude Code Installer to Hijack macOS Systems is a high-severity malware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 19 indicators of compromise.
Threat ID: TL-2026-1042 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
A sponsored Google ad ranking above legitimate results for "claude code mac install" redirects victims to a fake Google Sites page mimicking Anthropic branding, which instructs users to paste a
On 2026-07-01, Beelzebub Labs (via its Caronte threat-intelligence platform) disclosed a ClickFix-style malvertising campaign impersonating the Claude Code CLI installer for macOS. Victims searching "claude code mac install" on Google are served a sponsored ad ranking above Anthropic's legitimate documentation; clicking it leads to a fake install page hosted on the trusted sites.google.com domain, spoofing Anthropic branding and install instructions. The page instructs the victim to copy and paste a single Terminal command containing a base64- and gzip-encoded, randomized-variable-name zsh dropper. On execution, the dropper silently redirects output, fetches and stages the payload in a curl-and-execute chain, and displays a spoofed macOS System Preferences-style password dialog to socially engineer the victim into entering their local account password, which is then used to unlock the macOS Keychain and other OS-protected secret stores that a browser-only stealer could not otherwise reach. The delivered payload is MacSync Stealer v1.1.2, tagged internally with the build string "claude1", identifying this as a distinct, purpose-built campaign variant of the broader MacSync Stealer malware-as-a-service (MaaS) family that has previously been distributed via ClickFix lures impersonating ChatGPT Atlas, Mac cleanup utilities, and code-signed Swift installers since at least November 2025. Once credentials are harvested, MacSync Stealer enumerates and exfiltrates saved passwords from 14+ Chromium-based browsers and Firefox/Gecko variants, targets 80+ browser-based cryptocurrency wallet extensions and 20+ desktop wallet applications, and collects SSH private keys, AWS and Kubernetes configuration files, Telegram Desktop session data, Safari browsing history, Apple Notes content, and general Desktop/Documents/Downloads files matching sensitive patterns (PDFs, configs, key material). Harvested data is packaged into an archive and uploaded to attacker infrastructure in unencrypted 10-megabyte chunks; a design flaw causes the archive to become corrupted and unreadable to the attacker if the upload is interrupted, and the malware additionally blocks itself with a fake error dialog that pauses execution entirely until the victim clicks through it, giving defenders and victims a brief window to abort exfiltration via force-quit, lid-close, or restart before the dialog is dismissed. Beyond credential theft, MacSync Stealer performs a persistent hijack of installed Ledger hardware-wallet software: it downloads a modified version of the Ledger Live Electron application, swaps it in place of the legitimate binary, and re-signs the trojanized bundle to bypass macOS Gatekeeper/code-signing integrity checks. The trojanized build contains an injected instruction (annotated with a Russian-language code comment, suggesting Russian-speaking operators or reused Russian-authored tooling) that, after a 5-second delay on next launch, triggers a spoofed "wallet recovery" flow designed to phish the victim's hardware-wallet seed phrase directly into attacker hands — a much higher-value, longer-persistence compromise than a one-time credential dump. Files staged by the dropper use a `.daily` extension and hash-derived filenames, consistent with the operator rotating payloads on (at minimum) a daily cadence to evade static-hash-based detection and takedown. Google removed the malicious ad within 24 hours of notification for policy violation, but Beelzebub Labs and other researchers (Gridinsoft, 7AI, Jamf Threat Labs, CloudSEK, Microsoft, SANS ISC, The Hacker News) have tracked the broader MacSync Stealer ClickFix family rotating lure brands (ChatGPT, Homebrew, Claude Code), lure domains, and payload stages continuously since Q4 2025, indicating an active, evolving MaaS operation rather than a single-use campaign. No CVE applies; this is a pure social-engineering/malvertising delivery chain rather than an exploited software vulnerability.
Weaknesses (CWE)
CWE-451, CWE-494, CWE-1021
Target sectors: technology, software development, cryptocurrency, general consumer
Target regions: North America, Europe, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 19 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1583, T1586, T1585, T1189, T1566, T1204, T1059, T1059, T1140, T1027