The MacSync Threat: A Multistage Attack
Security analysts at Huntress have uncovered a sophisticated malware campaign targeting macOS users. The threat, identified as MacSync, is a six-stage remote access Trojan (RAT) and information stealer. The attack is orchestrated through a deceptive installation guide for 'Claude Code,' which is being promoted via paid Google advertisements.
Once a user interacts with the malicious instructions, the malware systematically compromises the machine. The final phase of this infection involves the modification of installed Ledger and Trezor cryptocurrency wallet applications. These apps are replaced with compromised versions that display fake recovery prompts, tricking users into revealing their seed phrases and effectively emptying their digital asset accounts.
Exploiting Trusted Platforms
The campaign is notably dangerous because it relies on the abuse of legitimate infrastructure rather than traditional phishing domains. The attackers utilized Anthropic's 'public URL' feature, which allows users to share chat sessions. By hosting their guide directly on claude.ai, the malicious content benefit from the following factors:
- HTTPS Trust: The page operates under Anthropic’s own security certificates, leaving no warning signs for users.
- Platform Verification: The attackers set their display name to "Apple Support." The platform's own interface validated this, displaying the banner to readers as if it were a legitimate conversation between the user and official support.
- Search Engine Ranking: By using paid Google ads, the attackers secured the top spot in search results, giving the fake guide an appearance of official authorization.
A Pattern of Abuse
This incident highlights a growing trend where attackers weaponize the 'shareable link' features of AI platforms. As noted by Huntress, this is not an isolated occurrence. Similar delivery methods have been identified using poisoned conversations on ChatGPT and Grok, as well as deceptive installers for other AI utilities hosted on platforms like GitHub.
Researchers emphasized that because these pages are indexable and served from official domains, they can easily bypass standard user vigilance. As security experts warn, "users need to exercise extreme caution when following commands or installing software from sources found online, even if they appear to originate from reputable platforms promoted through search engine advertisements."
