Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign
June 18, 2026, 8:35 p.m.
Description
Cybercriminals orchestrated a sophisticated malvertising operation leveraging Google Ads to impersonate popular AI developer tools including Claude AI, ChatGPT Codex, Perplexity, Cursor IDE, and JetBrains. Over seven weeks spanning April to June 2026, attackers deployed 106 unique malicious hostnames across six distinct waves, initially hosting ClickFix social engineering pages on GitLab infrastructure before pivoting to weaponize claude.ai's legitimate shared chat feature. The campaign targeted technically proficient users searching for AI development tools, tricking them into executing terminal commands that deployed the MacSync infostealer. This credential-harvesting malware collected browser data, SSH keys, and cryptocurrency wallets. The Asia-Pacific region sustained the heaviest impact with 67.2% of over 2,000 victims, particularly concentrated in Taiwan. Anthropic responded by banning malicious accounts and implementing additional abuse mitigations.
Tags
Date
- Created: June 18, 2026, 10:09 a.m.
- Published: June 18, 2026, 10:09 a.m.
- Modified: June 18, 2026, 8:35 p.m.
Indicators
- https://loserrq0j1sha8.com/debug/loader.sh?build=a39427f9d5bfda11277f1a58c89b7c2d
Additional Informations
- Technology
- plirepsijr74.com
- isgilan.com
- alabamarecoverycenter.com
- yoauction.com
- touristprogram.com
- claude-code.official-version.com
- customroofingcontractors.com
- thnikagent.com
- briskinternet.com
- loserrq0j1sha8.com
- babulikinet.com
- 20claude.ai
- oaklandwaterdamage.com
- a2abotnet.com
- 5x5web.com
- homeinspectionnaperville.com
- jerryshvac.com
- bernasibutuwqu2.com
- peowqlauoshau8.com
- bewqslkslikrtjinfg9.com
- Taiwan
- India
- British Indian Ocean Territory
- Hong Kong
- Japan
- Malaysia
- Singapore
- France
- Italy