{"id":10674,"date":"2026-02-15T10:03:33","date_gmt":"2026-02-15T10:03:33","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/02\/15\/threat-actors-exploit-claude-artifacts-and-google-ads-to-target-macos-users\/"},"modified":"2026-02-15T10:03:33","modified_gmt":"2026-02-15T10:03:33","slug":"threat-actors-exploit-claude-artifacts-and-google-ads-to-target-macos-users","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/02\/15\/threat-actors-exploit-claude-artifacts-and-google-ads-to-target-macos-users\/","title":{"rendered":"Threat Actors Exploit Claude Artifacts and Google Ads to Target macOS Users"},"content":{"rendered":"<p>    Threat Actors Exploit Claude Artifacts and Google Ads to Target macOS Users<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated malware campaign targeting macOS users through Google-sponsored search results and legitimate platforms, including<a href=\"https:\/\/cybersecuritynews.com\/anthropic-unveils-claude-for-healthcare\/\" target=\"_blank\" rel=\"noreferrer noopener\"> Anthropic\u2019s Claude AI<\/a> and Medium. <\/p>\n<p>The campaign has already reached over 15,000 potential victims through two distinct attack variants that exploit users\u2019 trust in established online services.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"615\" src=\"https:\/\/i0.wp.com\/cybersecuritynews.com\/wp-content\/uploads\/2026\/02\/image-23-1024x615.png?resize=1024%2C615&#038;ssl=1\" alt=\"15,000 potential victims (Source: Twitter)\" class=\"wp-image-142633\" srcset=\"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/02\/image-23-1024x615.png 1024w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/02\/image-23-300x180.png 300w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/02\/image-23-768x461.png 768w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/02\/image-23-1536x923.png 1536w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/02\/image-23-2048x1230.png 2048w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/02\/image-23-699x420.png 699w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/02\/image-23-696x418.png 696w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/02\/image-23-1068x642.png 1068w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/02\/image-23-1920x1153.png 1920w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/02\/image-23-150x90.png 150w\" sizes=\"(max-width: 1024px) 100vw, 1024px\"><figcaption class=\"wp-element-caption\">15,000 potential victims (Source: Twitter)<\/figcaption><\/figure>\n<p>The first attack vector leverages Google Ads to promote a malicious Claude AI artifact disguised as a legitimate macOS security guide. <\/p>\n<p>When users search for \u201cOnline dns resolver,\u201d they encounter a sponsored link directing them to a public Claude artifact titled \u201cmacOS Secure Command Execution.\u201d <\/p>\n<p>This fake guide instructs users to paste a base64-encoded command into their Terminal application. The command decodes and executes a malicious shell script that downloads the <a href=\"https:\/\/cybersecuritynews.com\/macsync-macos-infostealer-leverage-clickfix-style-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">MacSync information stealer malware<\/a>.<\/p>\n<p>Once executed, the malware establishes communication with its command-and-control server at a2abotnet[.]com\/dynamic using a hardcoded authentication token and API key. <\/p>\n<p>To evade detection, the malware spoofs legitimate macOS browser User-Agent strings, making its network traffic appear as normal web browsing activity. <\/p>\n<p>The payload fetches an AppleScript component that performs the actual data theft operations, targeting sensitive information such as keychain credentials, browser data, and cryptocurrency wallet files.<\/p>\n<p><a href=\"https:\/\/x.com\/moonlock_lab\/status\/2021695674006352237\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Cybersecurity researchers at Moonlock Lab<\/a>, the stolen data gets compressed into \/tmp\/osalogging.zip before exfiltration to a2abotnet[.]com\/gate via HTTP POST requests. <\/p>\n<p>The malware includes sophisticated retry mechanisms for handling large data transfers, including chunked uploads with up to 8 retry attempts and exponential backoff. After successful data transmission, the malware removes staging files to cover its tracks.<\/p>\n<p>The second attack variant targets users searching for \u201cmacos cli disk space analyzer\u201d through a Medium article published at apple-mac-disk-space.medium[.]com. <\/p>\n<p>This article impersonates Apple\u2019s official Support Team and employs the same <a href=\"https:\/\/cybersecuritynews.com\/new-clickfix-attack-wave-targeting-windows-systems\/\" target=\"_blank\" rel=\"noreferrer noopener\">ClickFix social engineering technique<\/a>. However, this variant uses double-layered encoding and a different hosting infrastructure. <\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"754\" src=\"https:\/\/i0.wp.com\/cybersecuritynews.com\/wp-content\/uploads\/2026\/02\/image-24-1024x754.png?resize=1024%2C754&#038;ssl=1\" alt=\"Few layers of obfuscation for a single curl one-liner ( Source: Twitter)\" class=\"wp-image-142634\" srcset=\"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/02\/image-24-1024x754.png 1024w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/02\/image-24-300x221.png 300w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/02\/image-24-768x566.png 768w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/02\/image-24-1536x1132.png 1536w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/02\/image-24-570x420.png 570w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/02\/image-24-80x60.png 80w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/02\/image-24-696x513.png 696w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/02\/image-24-1068x787.png 1068w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/02\/image-24-1920x1415.png 1920w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/02\/image-24-150x111.png 150w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/02\/image-24.png 1953w\" sizes=\"(max-width: 1024px) 100vw, 1024px\"><figcaption class=\"wp-element-caption\">Few layers of obfuscation for a single curl one-liner ( Source: Twitter)<\/figcaption><\/figure>\n<p>The malicious command uses string concatenation tricks (cur\u201d\u201dl instead of curl) to bypass simple pattern-matching detection systems and YARA rules.<\/p>\n<p>Both variants demonstrate the growing trend of threat actors abusing legitimate platforms and trusted services to distribute malware. <\/p>\n<p>The use of Google Ads for malware delivery highlights the critical importance of verifying sources even when they appear in sponsored search results. <\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"311\" src=\"https:\/\/i0.wp.com\/cybersecuritynews.com\/wp-content\/uploads\/2026\/02\/image-26-1024x311.png?resize=1024%2C311&#038;ssl=1\" alt=\"Malicious URL (Source: Twiiter)\" class=\"wp-image-142636\" srcset=\"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/02\/image-26-1024x311.png 1024w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/02\/image-26-300x91.png 300w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/02\/image-26-768x233.png 768w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/02\/image-26-1536x466.png 1536w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/02\/image-26-2048x622.png 2048w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/02\/image-26-1384x420.png 1384w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/02\/image-26-696x211.png 696w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/02\/image-26-1068x324.png 1068w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/02\/image-26-1920x583.png 1920w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/02\/image-26-150x46.png 150w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\"><figcaption class=\"wp-element-caption\">Malicious URL (Source: Twiiter)<\/figcaption><\/figure>\n<p>Users should exercise extreme caution when copying and executing terminal commands from any online source, regardless of how legitimate the platform appears.<\/p>\n<p>MacOS users are advised to avoid executing terminal commands from unfamiliar sources. They should verify the authenticity of support articles claiming to be from Apple or other trusted vendors. <\/p>\n<p>Organizations should implement<a href=\"https:\/\/cybersecuritynews.com\/best-edr-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\"> endpoint detection solutions <\/a>capable of monitoring suspicious terminal activity and network connections to unknown command-and-control servers.<\/p>\n<p><strong>IOC Table<\/strong><\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\">Indicator Type<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Indicator<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Description<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Domain<\/td>\n<td>a2abotnet[.]com<\/td>\n<td>Command and control server<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>raxelpak[.]com<\/td>\n<td>Payload hosting domain<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>apple-mac-disk-space.medium[.]com<\/td>\n<td>Fake Apple support article<\/td>\n<\/tr>\n<tr>\n<td>File Path<\/td>\n<td>\/tmp\/osalogging.zip<\/td>\n<td>Staging file for stolen data<\/td>\n<\/tr>\n<tr>\n<td>Malware<\/td>\n<td>MacSync<\/td>\n<td>Information stealer targeting macOS<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/threat-actors-exploit-claude-artifacts-and-google-ads\/\">Threat Actors Exploit Claude Artifacts and Google Ads to Target macOS Users<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Dhivya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/threat-actors-exploit-claude-artifacts-and-google-ads\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Threat Actors Exploit Claude Artifacts and Google Ads to Target macOS Users A sophisticated malware campaign targeting macOS users through Google-sponsored search results and legitimate platforms, including Anthropic\u2019s Claude AI and Medium. The campaign has already reached over 15,000 potential victims through two distinct attack variants that exploit users\u2019 trust in established online services. 15,000 [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,258,131],"tags":[130],"class_list":["post-10674","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-malware","category-vulnerability","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10674"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=10674"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10674\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=10674"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=10674"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=10674"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}