Fake Claude macOS Malware
Key point
A fake Claude installation guide spread via Google Ads distributed a macOS stealer and RAT.
Details
Huntress discovered macOS malware disguised as a Claude.AI installation guide.
Attackers lured users to the fake guide through Google Ads, then had them run a copy-and-paste curl command that could bypass security warnings.
This payload installs macOS info-stealing malware and a RAT (Remote Access Trojan) through a 6-stage infection process. When downloading Claude-related installers or commands, users should verify the official website and distribution channels.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.