Threat intelligence report · AlienVault OTX

Shared Claude Chats Meet ClickFix

A ClickFix campaign has been identified that abuses Anthropic's Claude platform through shareable chat links to distribute MacSync Stealer targeting macOS users. Attackers utilized malvertising with paid Google ads to direct victims searching for Claude-related terms to malicious shared Claude chats falsely labeled as 'Apple Support.' These chats contained obfuscated installation commands that, when executed, deployed a multi-stage infection chain. The malware steals credentials from browsers and password managers, cryptocurrency wallet data, sensitive files, and system information. The campaign ran from June 12-19, 2026, targeting primarily Mac users with Russian-language comments in the code suggesting Russian-speaking threat actors. Domains used adopted themes related to U.S. local services to appear legitimate.

· unknown severity · unattributed attribution

Evidence and provenance

Original source
AlienVault OTX report ↗
Published
2026-07-15T21:49:00.997000Z
Confidence basis
No actor match
Record ID
1d5a8fe8f830f7a617f0

Use and citation

Verify the original report before making operational decisions. Cite this permanent page together with the original source, publication date, confidence level, and review status.