New Mac Stealer Discovered Impersonating Apple Support in Claude Chat Windows
Key point
Malware that steals information from Mac users by impersonating Apple Support through Claude's shared chat window has been discovered.
Details
According to security researchers and Bleeping Computer, attackers are exploiting Claude's shared chat feature in a new attack method that impersonates Apple Support.
The attacker induces users to install 'Claude Code' software, tricking them into copying and executing terminal commands. During this process, malware is downloaded and executed in the background.
The key characteristics are as follows.
- Volatile installation: It mainly runs within memory (RAM), leaving almost no clear trace on storage devices.
- Data theft: It collects login information, cookies, macOS Keychain contents, and more, then transmits them to the attacker's server.
- Regional filtering: A notable feature is that the malware terminates itself when Russian or CIS region keyboard settings are detected.
The malware has been identified as a variant of 'MacSync', and similar attacks have also occurred via ChatGPT and Grok. Users should always keep macOS updated to the latest version and carefully check system warnings when pasting externally copied commands into the terminal.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.