• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
TechTrendFeed
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
TechTrendFeed
No Result
View All Result

Pretend Claude Code Installer Delivers MacSync macOS Infostealer By Google Advertisements

Admin by Admin
July 28, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


A extremely convincing malvertising marketing campaign is focusing on macOS customers trying to find “tips on how to set up Claude Code on Mac,” delivering the MacSync infostealer by a trusted-looking workflow that abuses professional infrastructure relatively than exploiting software program vulnerabilities.

The assault highlights a rising shift towards trust-based compromise, the place attackers weaponize genuine platforms resembling Google Advertisements and claude.ai to bypass conventional person scrutiny.

The advert hyperlinks to a real claude.ai area, reinforcing legitimacy by appropriate branding and placement alongside Anthropic’s official set up documentation.

Nonetheless, the malicious advert redirects customers to a claude.ai/share web page that mimics an set up information attributed to “Apple Help,” making a layered belief phantasm utilizing each an actual area and a recognizable model.

In contrast to conventional phishing, the touchdown web page will not be a spoof. It’s a professional Claude share hyperlink containing attacker-controlled content material.

Embedded throughout the information is a modified set up command that leverages Base64 encoding and shell command substitution to obscure its true conduct.

The command construction silently decodes a hidden string earlier than executing curl, stopping customers from seeing the precise obtain endpoint throughout informal inspection.

Using the “-k” flag in curl disables TLS certificates validation, additional indicating malicious intent. This method permits the command to look benign whereas masking vital indicators till execution.

Infrastructure evaluation exhibits hybridcustomhomes[.]com working as a part of a broader command-and-control ecosystem.

Endpoints resembling /dynamic?txd= operate as beaconing channels, whereas /gate gives secondary C2 communication. Further paths linked to Ledger Stay trojanization counsel cryptocurrency-focused focusing on.

SubStack Researchers mentioned that, the marketing campaign begins with a sponsored Google advert labeled “Claude Code Mac,” prominently displayed above natural outcomes.

The area itself is an aged asset repurposed for malicious use, a tactic more and more favored for evading reputation-based detection.

Related domains, together with houstongaragedoorinstallers[.]com and mansfieldpediatrics[.]com, comply with the identical naming conference and infrastructure patterns, indicating a scalable deployment mannequin.

The fake Claude Code Google ad (Source : SubStack).
The pretend Claude Code Google advert (Supply : SubStack).

A number of claude.ai/share URLs tied to the identical Google Advertisements marketing campaign ID counsel redundancy designed to keep up persistence even when particular person lures are eliminated.

Pretend Claude Code Installer

Correlation with CrowdStrike Intelligence confirms the exercise aligns with recognized MacSync campaigns, together with matching payload hashes and Cloudflare-fronted IP addresses 104.21.40[.]24 and 172.67.174[.]150.

MacSync itself is a high-impact macOS infostealer targeted on credential and session theft. It targets macOS Keychain information, browser cookies, SSH keys, cloud credentials, Kubernetes configurations, and developer tokens.

It additionally extracts Telegram session information and helps exfiltration from over 80 cryptocurrency wallets.

A legitimate Claude page (Source : SubStack).
A professional Claude web page (Supply : SubStack).

Notably, it might probably trojanize Ledger Stay functions, enabling long-term compromise even after preliminary an infection is eliminated.

Persistence is achieved through a LaunchAgent masquerading as a Google Keystone updater positioned at ~/Library/LaunchAgents/com.google.keystone.agent.plist, with staging artifacts noticed in non permanent directories.

The effectiveness of this marketing campaign lies in its skill to fulfill commonplace safety checks. The area is professional, the interface is genuine, and the workflow mirrors regular developer conduct.

Even guide command inspection fails as a result of the vital vacation spot is encoded.

This demonstrates that area validation alone is now not adequate, notably when attackers leverage trusted platforms as supply vectors.

This incident underscores the necessity for deeper verification practices, together with decoding obfuscated instructions and validating all outbound connections earlier than execution.

As attackers proceed to refine social-engineering strategies inside professional ecosystems, safety consciousness should evolve past surface-level indicators to incorporate behavioral and contextual evaluation.

What Options Ought to AI SOC Have in 2026? A Full Guidelines : Obtain the AI SOC Options Guidelines

Tags: AdsClaudeCodeDeliversFakeGoogleInfoStealerInstallermacOSMacSync
Admin

Admin

Next Post
PayPal leaves the door open to a better takeover supply following earnings beat

PayPal leaves the door open to a better takeover supply following earnings beat

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Trending.

OpenAI Warns GPT-5.6 File Deletions Stem From Full Entry Mode

OpenAI Warns GPT-5.6 File Deletions Stem From Full Entry Mode

July 17, 2026
These 5 Easy Methods Helped Me Construct a Smarter House

These 5 Easy Methods Helped Me Construct a Smarter House

July 19, 2025
Tomba! 2: The Evil Swine Return Particular Version Evaluation

Tomba! 2: The Evil Swine Return Particular Version Evaluation

December 15, 2025
Ex-Activision Boss Bobby Kotick Needs To Purchase TikTok

Ex-Activision Boss Bobby Kotick Needs To Purchase TikTok

May 18, 2025
Day 10 — Understanding Ensemble Strategies: Random Forest vs. Gradient Boosting | by Jovite Jeffrin A | Aug, 2025

Day 10 — Understanding Ensemble Strategies: Random Forest vs. Gradient Boosting | by Jovite Jeffrin A | Aug, 2025

August 7, 2025

TechTrendFeed

Welcome to TechTrendFeed, your go-to source for the latest news and insights from the world of technology. Our mission is to bring you the most relevant and up-to-date information on everything tech-related, from machine learning and artificial intelligence to cybersecurity, gaming, and the exciting world of smart home technology and IoT.

Categories

  • Cybersecurity
  • Gaming
  • Machine Learning
  • Smart Home & IoT
  • Software
  • Tech News

Recent News

FireAvert joins Works with Dwelling Assistant

FireAvert joins Works with Dwelling Assistant

July 28, 2026
The Grade A Refurb Nintendo Change 2 Mario Kart World Console Bundle Simply Dropped to $419 at Woot

The Grade A Refurb Nintendo Change 2 Mario Kart World Console Bundle Simply Dropped to $419 at Woot

July 28, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://techtrendfeed.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT

© 2025 https://techtrendfeed.com/ - All Rights Reserved