Hackers Use Fake Claude Install Guide to Deploy MacSync Stealer and Trojanize Crypto Wallet Apps

Mac customers looking for assist with Claude Code are being lured right into a malware marketing campaign that turns a routine set up job right into a full gadget compromise.

The operation makes use of paid Google search outcomes and a convincing shared Claude dialog to steer victims to run a command in Terminal. The marketing campaign places on a regular basis Mac customers at severe threat.

The page is hosted on Claude.ai, which gives the lure an air of legitimacy, but it is not an official installation guide.

It tells visitors to copy and paste a curl command that downloads MacSync, an information stealer built to collect credentials, private data and cryptocurrency wallet recovery phrases.

Huntress analysts identified the activity after responding to an incident involving a customer who clicked the sponsored result in July.

Their investigation found a complete attack chain combining in-memory theft, persistent access and altered wallet apps.

A shared Claude conversation you might have been directed to after clicking on a sponsored search result in Google (Source - Huntress)
A shared Claude conversation you might have been directed to after clicking on a sponsored search result in Google (Source – Huntress)

The risk goes beyond a stolen browser password. MacSync can take over active accounts, collect cloud and SSH keys, capture screen content and wait inside wallet software for its owner to use it.

Huntress said in a report shared with Cyber Safety Information (CSN) that blend makes a single rushed Terminal command pricey for people and organizations.

Hackers Use Fake Claude Install Guide

The attack starts when someone searches Google for terms such as how to install Claude on a Mac and selects a sponsored listing.

Instead of reaching official documentation, the person lands on a Claude conversation styled as if it came from Apple Support. This misuse of trusted services mirrors earlier shared Claude chat abuse reported in related ClickFix exercise.

The false instructions rely on ClickFix, a social engineering method that gets victims to run the attacker’s command themselves.

In this case, the command launches a small zsh loader, which unpacks an encoded payload and begins the six-stage chain with little visible warning.

The six stages of the MacSync Stealer and RAT kill chain we observed (Source - Huntress)
The six stages of the MacSync Stealer and RAT kill chain we observed (Source – Huntress)

The researchers said the loader changes for each victim, making simple file-hash blocking unreliable. Defenders should instead watch for unusual curl activity, encoded Base64 content in shell commands and unexpected Terminal downloads.

MacSync then runs an AppleScript directly in memory and asks for powerful macOS permissions, including Full Disk Access.

If the user approves, it can harvest browser cookies, saved logins, Keychain secrets, account passwords, Telegram sessions and cloud credentials. Related macOS ClickFix attack tactics present why permission prompts deserve cautious scrutiny.

The stealer also plants a remote-access trojan that survives future logins through a LaunchAgent. This gives operators an interactive shell, the ability to run commands and transfer files.

A separate signed helper seeks Screen Recording permission, allowing the attackers to capture the victim’s display after consent is granted.

Wallet Trojans Raise Stakes

The final stage targets applications users already trust. MacSync checks for dozens of wallet browser extensions and desktop wallet programs, then copies and rewrites selected apps.

It also targets companion applications for hardware wallets, turning familiar software into a phishing tool.

When a victim later opens a modified wallet app, it can display a fake error page requesting the recovery phrase.

Unlike a password, a wallet recovery phrase cannot simply be reset after exposure. Anyone who obtains it may control every wallet created from that seed, a danger also seen in wallet replacement malware risks.

Users should never paste a command into Terminal solely because a search ad, chat page or support-looking post tells you to do so.

Download software from the vendor’s official site, inspect unfamiliar commands before running them, and deny unexpected permission requests.

Everything that MacSync stealer exfiltrates (Source - Huntress)
Everything that MacSync stealer exfiltrates (Source – Huntress)

Security teams should review alerting for shell-based download chains, as recent ClickFix campaign coverage exhibits the tactic stays extensively reused.

For users who may have executed the lure, promptly disconnecting the Mac from networks, changing exposed passwords from a clean device and moving cryptocurrency assets to a new wallet can limit further loss.

Organizations should also investigate browser sessions, cloud access tokens and persistence entries, since removing the visible installer alone may not remove the attacker’s access.

Indicators of compromise (IoCs):-

Type Indicator Description
IP address and port 85.206.161.241:8443 Direct command-and-control endpoint used by the Mach-O RAT through WebSocket over TLS
File path /tmp/osalogging.zip Archive used to stage and exfiltrate stolen data
File name .mpwd Local file where stolen user credentials are written for RAT retrieval
File name .zshrc Resource file used to launch persistence mechanisms
Function name daemon_function Background zsh function that runs the AppleScript payload, uploads stolen data and removes staging material

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *