惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - Franky
雷峰网
雷峰网
The Cloudflare Blog
WordPress大学
WordPress大学
博客园 - 聂微东
人人都是产品经理
人人都是产品经理
IT之家
IT之家
V
V2EX
博客园 - 司徒正美
小众软件
小众软件
博客园_首页
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
酷 壳 – CoolShell
酷 壳 – CoolShell
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Hugging Face - Blog
Hugging Face - Blog
T
Tailwind CSS Blog
Last Week in AI
Last Week in AI
Jina AI
Jina AI
博客园 - 叶小钗
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
阮一峰的网络日志
阮一峰的网络日志
爱范儿
爱范儿

Cyber Security News

AIRecon: AI-Powered Penetration Testing Tool with Kali Linux Sandbox Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code - Update Now! UNC3753 Uses Screen-Sharing Sessions and RMM Tools to Exfiltrate Sensitive Legal Data New OnionDrop Loader Campaign Uses gainmsg C2 to Deliver LegionLoader Payloads ClickFix Campaign Uses EtherHiding and GULoader to Infect Windows Users via Fake CAPTCHA Ghostwriter Hackers Abuse Gmail Admin-Themed Emails to Steal Credentials and 2FA Codes The Half-Life of Threat Intelligence: When Does an IOC Stop Being Useful? Critical Fortinet FortiSandbox Vulnerabilities Actively Exploited in Attacks Aembit Extends IAM for Agentic AI to Microsoft Copilot Studio India Temporarily Bans Telegram Messenger Over Medical Exam Fraud Microsoft 365 Device Code Phishing Campaign Bypasses Password Theft With Legitimate Login Flow AppViewX Launches Agent Identity Security to Govern Agents for the AI and Quantum Era Hackers Weaponize Microsoft Teams Relay to Hide Ransomware Traffic Developer laptops are the credential store attackers are picking through in 2026, GitGuardian announces Endpoint Protection Interlock and Rhysida Ransomware Operations Share Supper Backdoor and Malware Codebase Novo Nordisk Confirms Cyber Attack — Hackers Accessed Patient Medical Data and Internal AI Assets Russian and Chinese Influence Actors Use AI to Evade Bot Detection and Mimic Human Behavior Microsoft Teams Analyze the Wi-Fi Hotspot Data Connected to an Employee’s Device PRC-Nexus Hackers Exploit REDCap Servers to Spy on US Medical Research Institutions Infinite Campus Data Breach Exposes 137,000 Users Personal Details OptinMonster Plugin Hack Exposes 1.2 Million Wordpress Sites to Cyberattack Ransomware Ecosystem Consolidates Around LockBit Alumni, Qilin, Hyflock, and The Gentlemen Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Exploited in the Wild Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks Nearly 14,000 SimpleHelp Servers Exposed Amid Critical Authentication Bypass Disclosure Microsoft Site Showing Warning Following Certificate Expiry DPAPISnoop Tool Extracts CREDHIST Hashes for Offline Windows Credential Recovery SHADOWBYT3$ Allegedly Claim Breach of Nintendo, Stealing Sensitive Data Anthropic Updated Privacy Policy to Include Identity Verification for Claude Users
Hackers Abuse Claude.ai Shared Chat Feature to Host the C...
Abinaya · 2026-06-18 · via Cyber Security News

Hackers are increasingly exploiting trusted AI platforms to deliver sophisticated social engineering attacks, with a recent campaign abusing Claude.ai’s shared chat feature to host malicious ClickFix instructions.

According to TrendAI Research, attackers deployed 106 unique malicious hostnames across six campaign waves within seven weeks, continuously rotating infrastructure and testing different AI-themed lures to maximize effectiveness.

The operation marks a significant evolution in ClickFix tactics, shifting from traditional malicious hosting to trusted platforms like Claude.ai.

The campaign initially relied on GitLab Pages, using over 90 malicious subdomains hosted under the trusted *. gitlab.io domain.

These pages impersonated popular AI developer tools, including Claude AI, ChatGPT Codex, Perplexity, Cursor IDE, and JetBrains.

By leveraging Google Ads, threat actors targeted users actively searching for these tools, increasing the likelihood of interaction from technically skilled individuals.

ClickFix attacks rely on tricking users into manually executing malicious commands. In this campaign, victims were instructed to copy and paste terminal or PowerShell commands under the pretense of installing or fixing software.

This technique bypasses many traditional security controls because the user unknowingly executes the payload. The campaign escalated significantly in May 2026, when attackers pivoted to abusing Claude.ai’s shared chat feature.

Claude Malvertising Campaign Infection Chain (Source : trendmicro)
Claude Malvertising Campaign Infection Chain (Source: TrendMicro)

Instead of directing victims to suspicious domains, malicious ads redirected users to legitimate Claude.ai shared chat URLs. These pages appeared trustworthy, effectively bypassing browser warnings, URL inspection, and Safe Browsing protections.

Once on the page, victims encountered fake support conversations impersonating entities such as Apple Support or development teams.

These chats provided step-by-step instructions for opening a terminal and executing a command. The command typically included a base64-encoded script that, once decoded, fetched a second-stage payload.

Top 20 Countries Targeted by the Campaign  (Source : trendmicro)
Top 20 Countries Targeted by the Campaign (Source: TrendMicro)

Analysis revealed that the payload delivered the MacSync infostealer, which targets macOS systems. The malware collects browser credentials, cookies, SSH keys, and cryptocurrency wallet data, then exfiltrates them to attacker-controlled servers.

Notably, the malware includes a check for Russian keyboard layouts, likely to avoid infecting systems in CIS regions.

The campaign’s geographic targeting was heavily concentrated in the Asia-Pacific region, which accounted for over 67 percent of victims.

“Running Claude Code on Mac” - A Shared Chat Posing as Apple Support (Source : trendmicro)
“Running Claude Code on Mac” – A Shared Chat Posing as Apple Support (Source: TrendMicro)

Taiwan alone represented more than 30 percent of observed traffic, followed by Japan and Singapore. Later waves expanded targeting to countries including India, France, and Italy, indicating ongoing optimization of ad targeting strategies.

TrendAI researchers observed at least 45 malicious Claude.ai shared chat instances in early stages, increasing to over 60 in later waves.

This shift to trusted infrastructure removes many traditional detection signals, leaving user awareness as the primary defense.

Top 10 Countries by Confirmed Victim Interactions (Source : trendmicro)
Top 10 Countries by Confirmed Victim Interactions (Source: TrendMicro)

Following responsible disclosure, Anthropic took action by banning the malicious accounts, removing harmful shared chats, and implementing additional safeguards to prevent abuse of the feature.

Security experts warn that this campaign highlights a broader trend where attackers weaponize legitimate platforms to evade detection. As AI tools become more embedded in developer workflows, such abuse is expected to increase.

Organizations are advised to educate users about ClickFix-style attacks, monitor unusual command execution, and deploy endpoint detection solutions.

Users should avoid installing software via search ads, verify URLs carefully, and never execute commands from untrusted sources.

Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

Abinaya

Abinayahttps://cybersecuritynews.com/

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.