#ClaudeFix
Attackers turned claude.ai's own shared-chat feature into a ClickFix lure dropping the MacSync macOS stealer. https://intel.threadlinqs.com/threat/TL-2026-2241 #ThreatIntel #MacSync #ClaudeFix #Claude
August 31, 2026 at 12:59 AM
July 21, 2026 at 12:07 PM
@zscalerinc.bsky.social
MacSync Stealer is distributed via ClickFix instructions hosted on shared Claude chats through malvertising.
-
IOCs: lasvegaslaminateflooring. com, realtorsmichigan. com, centralfloridapowerwash. com
-
...
ClaudeFix ClickFix Campaign
www.zscaler.com
July 16, 2026 at 2:10 PM
ClaudeFix: How Cybercriminals Turned Anthropic’s AI Platform Into a Dangerous Malware Delivery Channel for macOS Users + Video

Introduction Artificial intelligence has rapidly become one of the most trusted technologies on the internet. Millions of users rely on AI assistants every day for coding,…
ClaudeFix: How Cybercriminals Turned Anthropic’s AI Platform Into a Dangerous Malware Delivery Channel for macOS Users + Video
Introduction Artificial intelligence has rapidly become one of the most trusted technologies on the internet. Millions of users rely on AI assistants every day for coding, research, productivity, and technical support. Unfortunately, cybercriminals have noticed this growing trust and are now weaponizing AI platforms themselves as part of sophisticated social engineering campaigns. Security researchers have uncovered a dangerous new campaign known as ClaudeFix, where attackers abuse Anthropic's shared Claude conversations to distribute MacSync Stealer, a powerful information-stealing malware designed specifically for macOS.
undercodenews.com
July 16, 2026 at 8:20 AM
ClaudeFixキャンペーン、Claudeの共有チャットを悪用しMacSyncスティーラーを配布

新たなClickFixキャンペーンが、Anthropic社のClaudeプラットフォームを悪用してMacSyncスティーラーを配布していることが判明しました。MacSyncスティーラーはmacOSを標的とする情報窃取型マルウェアで、認証情報や機密ファイル、暗号資産ウォレットのデータを収集する能力を備えています。 Zs...
ClaudeFixキャンペーン、Claudeの共有チャットを悪用しMacSyncスティーラーを配布
新たなClickFixキャンペーンが、Anthropic社のClaudeプラットフォームを悪用してMacSyncスティーラーを配布していることが判明しました。MacSyncスティーラーはmacOSを標的とする情報窃取型マルウェアで、認証情報や機密ファイル、暗号資産ウォレットのデータを収集する能力を備えています。 Zs
blackhatnews.tokyo
July 16, 2026 at 7:48 AM
One pasted Terminal command from a fake Claude 'fix' hands Mac keychains and crypto wallets to attackers. https://intel.threadlinqs.com/threat/TL-2026-1384 #ThreatIntel #MacSync #Atomic #Amatera
July 15, 2026 at 5:38 PM
Mac users were targeted by a MacSync Stealer ClickFix campaign that used paid ads and shared Claude chats to deliver malicious paste-and-run commands, stealing credentials, browser data, cloud keys, Telegram files, and crypto wallet info. #Claude
ClaudeFix: Shared Claude Chats Meet ClickFix
Zscaler reports a MacSync Stealer ClickFix campaign that used paid ads and shared Claude chats to trick Mac users into running malicious paste-and-run commands. The multi-stage attack stole credentials, browser data, cloud keys, Telegram files, and cryptocurrency wallet information while showing signs of Russian-speaking involvement. #MacSyncStealer #Claude #AppleSupport #LedgerWallet #LedgerLive #TrezorSuite
www.hendryadrian.com
July 15, 2026 at 7:15 PM