{"id":17172,"date":"2026-07-28T15:22:56","date_gmt":"2026-07-28T15:22:56","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=17172"},"modified":"2026-07-28T15:22:56","modified_gmt":"2026-07-28T15:22:56","slug":"pretend-claude-code-installer-delivers-macsync-macos-infostealer-by-google-advertisements","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=17172","title":{"rendered":"Pretend Claude Code Installer Delivers MacSync macOS Infostealer By Google Advertisements"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p class=\"wp-block-paragraph\">A extremely convincing malvertising marketing campaign is focusing on macOS customers trying to find \u201ctips on how to set up Claude Code on Mac,\u201d delivering the MacSync infostealer by a trusted-looking workflow that abuses professional infrastructure relatively than exploiting software program vulnerabilities. <\/p>\n<p class=\"wp-block-paragraph\">The assault highlights a rising shift towards trust-based compromise, the place attackers weaponize genuine platforms resembling Google Advertisements and claude.ai to bypass conventional person scrutiny. <\/p>\n<p class=\"wp-block-paragraph\">The advert hyperlinks to a real claude.ai area, reinforcing legitimacy by appropriate branding and placement alongside Anthropic\u2019s official set up documentation. <\/p>\n<p class=\"wp-block-paragraph\">Nonetheless, the malicious advert redirects customers to a claude.ai\/share web page that mimics an set up information attributed to \u201cApple Help,\u201d making a layered belief phantasm utilizing each an actual area and a recognizable model.<\/p>\n<p class=\"wp-block-paragraph\">In contrast to conventional phishing, the touchdown web page will not be a spoof. It&#8217;s a professional Claude share hyperlink containing attacker-controlled content material. <\/p>\n<p class=\"wp-block-paragraph\">Embedded throughout the information is a modified set up command that leverages Base64 encoding and shell command substitution to obscure its true conduct. <\/p>\n<p class=\"wp-block-paragraph\">The command construction silently decodes a hidden string earlier than executing curl, stopping customers from seeing the precise obtain endpoint throughout informal inspection.<\/p>\n<p class=\"wp-block-paragraph\">Using the \u201c-k\u201d flag in curl disables TLS certificates validation, additional indicating malicious intent. This method permits the command to look benign whereas masking vital indicators till execution.<\/p>\n<p class=\"wp-block-paragraph\">Infrastructure evaluation exhibits hybridcustomhomes[.]com working as a part of a broader command-and-control ecosystem. <\/p>\n<p class=\"wp-block-paragraph\">Endpoints resembling \/dynamic?txd= operate as beaconing channels, whereas \/gate gives secondary C2 communication. Further paths linked to Ledger Stay trojanization counsel cryptocurrency-focused focusing on. <\/p>\n<p class=\"wp-block-paragraph\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/derivai.substack.com\/p\/fake-claude-code-installer-macsync-malware\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">SubStack Researchers mentioned that<\/a>, the marketing campaign begins with a sponsored Google advert labeled \u201cClaude Code Mac,\u201d prominently displayed above natural outcomes.<\/p>\n<p class=\"wp-block-paragraph\">The area itself is an aged asset repurposed for malicious use, a tactic more and more favored for evading reputation-based detection. <\/p>\n<p class=\"wp-block-paragraph\">Related domains, together with houstongaragedoorinstallers[.]com and mansfieldpediatrics[.]com, comply with the identical naming conference and infrastructure patterns, indicating a scalable deployment mannequin.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/substackcdn.com\/image\/fetch\/$s_!_eTK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep\/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F751d3a24-83c5-40ea-955c-eac14d41bc0c_1402x1122.png\" alt=\"The fake Claude Code Google ad (Source : SubStack).\"\/><figcaption class=\"wp-element-caption\">The pretend Claude Code Google advert (Supply : SubStack).<\/figcaption><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">A number of claude.ai\/share URLs tied to the identical <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/tax-scam-google-ads\/\" data-type=\"post\" data-id=\"181147\" target=\"_blank\" rel=\"noreferrer noopener\">Google Advertisements marketing campaign <\/a>ID counsel redundancy designed to keep up persistence even when particular person lures are eliminated.<\/p>\n<h2 id=\"h-fake-claude-code-installer\" class=\"wp-block-heading\"><strong>Pretend Claude Code Installer <\/strong><\/h2>\n<p class=\"wp-block-paragraph\">Correlation with CrowdStrike Intelligence confirms the exercise aligns with recognized MacSync campaigns, together with matching payload hashes and Cloudflare-fronted IP addresses 104.21.40[.]24 and 172.67.174[.]150. <\/p>\n<p class=\"wp-block-paragraph\">MacSync itself is a <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/macsync-macos\/\" data-type=\"post\" data-id=\"175905\" target=\"_blank\" rel=\"noreferrer noopener\">high-impact macOS infostealer<\/a> targeted on credential and session theft. It targets macOS Keychain information, browser cookies, SSH keys, cloud credentials, Kubernetes configurations, and developer tokens. <\/p>\n<p class=\"wp-block-paragraph\">It additionally extracts Telegram session information and helps exfiltration from over 80 cryptocurrency wallets. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/substackcdn.com\/image\/fetch\/$s_!cE53!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep\/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2dbe652-d420-422b-bfa7-9d71e30a46df_2048x1134.png\" alt=\"A legitimate Claude page (Source : SubStack).\"\/><figcaption class=\"wp-element-caption\">A professional Claude web page (Supply : SubStack).<\/figcaption><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">Notably, it might probably trojanize Ledger Stay functions, enabling long-term compromise even after preliminary an infection is eliminated. <\/p>\n<p class=\"wp-block-paragraph\">Persistence is achieved through a LaunchAgent masquerading as a Google Keystone updater positioned at ~\/Library\/LaunchAgents\/com.google.keystone.agent.plist, with staging artifacts noticed in non permanent directories.<\/p>\n<p class=\"wp-block-paragraph\">The effectiveness of this marketing campaign lies in its skill to fulfill commonplace safety checks. The area is professional, the interface is genuine, and the workflow mirrors regular developer conduct. <\/p>\n<p class=\"wp-block-paragraph\">Even guide command inspection fails as a result of the vital vacation spot is encoded. <\/p>\n<p class=\"wp-block-paragraph\">This demonstrates that area validation alone is now not adequate, notably when attackers leverage trusted platforms as supply vectors.<\/p>\n<p class=\"wp-block-paragraph\">This incident underscores the necessity for deeper verification practices, together with decoding obfuscated instructions and validating all outbound connections earlier than execution. <\/p>\n<p class=\"wp-block-paragraph\">As attackers proceed to refine social-engineering strategies inside professional ecosystems, safety consciousness should evolve past surface-level indicators to incorporate behavioral and contextual evaluation.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(135deg,rgb(238,238,238) 100%,rgb(169,184,195) 100%)\"><strong><strong>What Options Ought to AI SOC Have in 2026? A Full Guidelines<\/strong><\/strong>\u00a0<strong>:\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/underdefense.com\/what-features-should-ai-soc-have-in-2026-a-complete-checklist\/?utm_source=cybersecuritynews.com&amp;utm_medium=online_media&amp;utm_campaign=csn_linkedin_newsletter_ai_soc_features_checklist_july_2026\" target=\"_blank\" rel=\"noreferrer noopener\"\/><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/underdefense.com\/what-features-should-ai-soc-have-in-2026-a-complete-checklist\/?utm_source=cybersecuritynews.com&amp;utm_medium=online_media&amp;utm_campaign=csn_linkedin_newsletter_ai_soc_features_checklist_july_2026\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>Obtain the AI SOC Options Guidelines<\/strong><\/a><\/strong><\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>A extremely convincing malvertising marketing campaign is focusing on macOS customers trying to find \u201ctips on how to set up Claude Code on Mac,\u201d delivering the MacSync infostealer by a trusted-looking workflow that abuses professional infrastructure relatively than exploiting software program vulnerabilities. The assault highlights a rising shift towards trust-based compromise, the place attackers weaponize [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":17174,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[1348,458,977,4611,67,81,3108,6760,2858,7879],"class_list":["post-17172","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-ads","tag-claude","tag-code","tag-delivers","tag-fake","tag-google","tag-infostealer","tag-installer","tag-macos","tag-macsync"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17172","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=17172"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17172\/revisions"}],"predecessor-version":[{"id":17173,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17172\/revisions\/17173"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/17174"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=17172"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=17172"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=17172"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-07-28 22:18:43 UTC -->