Cyber Security News

Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware

Mac users seeking AI tools face a malware trap. Attackers are using fake Claude and ChatGPT installers and sponsored search results to push MacSync, a macOS password stealer.

The campaign relies on persuasion instead of a software flaw. A visitor is told that a download, connection, or verification step has failed, then instructed to copy a command into Terminal. That single action gives the attacker a route into the device.

MacSync is a malware-as-a-service operation, meaning its developers supply the tool and infrastructure to other criminal groups. Researchers said the threat emerged in 2025.

The risk goes beyond a stolen password. MacSync is designed to gather browser logins, session cookies, Mac Keychain data, SSH keys, cloud credentials, messaging sessions, and cryptocurrency wallet information.

SEQRITE said in a report shared with Cyber Security News (CSN) that it can also establish lasting access, leaving personal accounts and workplace systems exposed.

Hackers Use Fake Claude and ChatGPT Installers

The first stage often begins with a search for a desktop AI app. Criminals buy or manipulate search placements and send people to pages that imitate Claude AI, ChatGPT, developer tools, or other trusted services.

A previous report on malicious macOS Google ads shows how paid results can steer high-intent users toward a fraudulent AI download page. Instead of providing a normal application package, the page displays a ClickFix prompt.

These prompts may claim a WebSockets connection needs repair, a CAPTCHA must be completed, or an audio problem requires attention. Victims are asked to paste a helpful-looking command into Terminal, starting the infection themselves.

MacSync Attack Chain (Source – SEQRITE)

That technique is effective because it turns the user into the final delivery step. Traditional warning signs, such as an unsolicited attachment, may be absent.

The wider pattern was documented in coverage of macOS ClickFix credential theft, where fake verification pages similarly pushed commands to Mac users. After execution, a shell script launches a background component and unpacks the native MacSync stager.

The stager detaches from the Terminal session, suppresses visible output, and retrieves further instructions from attacker-controlled infrastructure. This layered design lets operators change later payloads.

Stealer Collects Data Quietly

MacSync downloads an AppleScript directly into memory and runs it through a built-in macOS automation utility, rather than saving the script as an obvious file.

The script can display a password request that resembles a system dialog, then collect credentials and other data from the compromised Mac.

The malware packages information, including browser vaults and wallet databases, before sending it to its operators in fixed-size pieces.

If a transfer fails, it retries with increasing delays. After a successful upload, it removes temporary material to reduce evidence for users or incident responders.

Execution Flow (Source – SEQRITE)

It can then deploy a remote-access component that uses the macOS launch mechanism to start after login. A helper program may also request screen-recording permission, giving criminals another opportunity to watch activity or capture sensitive content.

The result is a campaign that can move from a fake installer to account takeover and surveillance. The findings fit a broader rise in AI-themed malware delivery.

In another case, a weaponized ChatGPT download site used sponsored results and fake download choices to target both Mac and Windows users. Familiar branding lowers suspicion when people are looking for new tools or quick fixes.

Users should avoid sponsored links when downloading software and go to a vendor’s official website by typing the address or using a trusted bookmark.

They should never paste a command from a web page, chat, ad, or support message into Terminal unless they fully understand it and have independently verified its source.

Security teams should block the listed infrastructure, investigate unexpected command-line activity launched from browsers, and check Macs for unfamiliar launch items and permission requests.

Resetting passwords alone may not be enough after an infection; affected users should revoke active sessions, rotate exposed keys, and have the device examined for persistence.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
File name9ff32f7c0108e9d27a3b491edf04827b6ca025f44dbIdentified MacSync Mach-O sample file name
SHA-256 hash9ff32f7c0108e9d27a3b491edf04827b6ca025f44db68aMacSync sample hash reported by SEQRITE
MD5 hash9678f71ea4cccbc3d511dc8d7f24b113MacSync sample MD5 hash
SHA-1 hash59508d071661ea70fa5fcbe6f9e2fb72506e57dfMacSync sample SHA-1 hash
Code-signing identifiercom.utils.LauncherAd-hoc-signed MacSync stager identifier
CDHashd182eb7cba0ffa42d770d7b0d3499e49f24163a2Code directory hash associated with the sample
Staged archive/tmp/osalogging.zipTemporary archive used to hold collected data
Status file/tmp/.httpcodeTemporary file used to record server response status
Persistence filecom.google.keystone.plistPossible renamed LaunchAgent persistence file
Persistence filecom.apple.sync.plistPossible renamed LaunchAgent persistence file
C2 domaindrivinguber.comPrimary command-and-control host
C2 domainasia.newsinweb.comRegional fallback command-and-control host
C2 domainusa.newsinweb.comRegional fallback command-and-control host
C2 root domainnewsinweb.comRoot domain used for fallback infrastructure
Download URI/dynamic?txd=c4f70f37daae63fe47b0c92adf006f8cf50b6c522Path used to retrieve the in-memory AppleScript payload
Upload URI/gate?buildtxd=c4f70f37daae63fe47b0c92adf006f8cf50b6Path used for stolen-data uploads
HTTP request headerapi-key: de62a2f47d1c7dec2997f931a050a615API key observed in MacSync network requests
HTTP User-AgentMozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) CFN AppleWebKit/537.36User-Agent string used in command-and-control communications

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Microsoft Releases Emergency Windows 11 Update Following Patch Tuesday Bugs

Microsoft has pushed out an emergency, out-of-band Windows 11 update after its September Patch Tuesday…

8 seconds ago

Top 10 Best Cloud Detection & Response (CDR) Solutions in 2026

CDR is the runtime, real-time half of cloud security: while CSPM tells you what’s misconfigured,…

5 minutes ago

Top 10 Best SaaS Security Posture Management (SSPM) Tools in 2026

Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…

10 minutes ago

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

16 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

27 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago