Fake Claude Install Guide Delivers Six-Stage macOS Stealer and RAT, Huntress Finds
4 Articles
4 Articles
ClickFix Campaign Uses EtherHiding to Hide Malware and Exposes DPRK Wallet Trail
ClickFix-style fake macOS updates are now being weaponized with EtherHiding-backed command‑and‑control and a DPRK-linked crypto laundering network, turning a routine search click into a full-stack theft operation spanning browser, endpoint, blockchain, and exchange infrastructure. Instead of traditional web C2, the implant resolves its live command‑and‑control endpoints from Ethereum smart contracts, a takedown‑resistant pattern known as […] Thi…
DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running Contagious Interview campaign. The defining aspect of the attack is that bogus macOS software update screen stealthily
Fake Claude Install Guide Delivers Six-Stage macOS Stealer and RAT, Huntress Finds
Security researchers at Huntress have reverse-engineered a previously undocumented macOS malware family, dubbed MacSync, after tracing an intrusion back to a malicious advertisement masquerading as installation instructions for Anthropic’s Claude AI assistant. According to Huntress, the infection began when a victim searched Google for guidance on installing Claude on a Mac and clicked a sponsored result placed above Anthropic’s own organic list…
Coverage Details
Bias Distribution
- There is no tracked Bias information for the sources covering this story.
Factuality
To view factuality data please Upgrade to Premium






