{
  "name": "Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign",
  "slug": "threat-actors-abuse-claudeai-shared-chat-for-clickfix-malvertising-campaign",
  "description": "Cybercriminals orchestrated a sophisticated malvertising operation leveraging Google Ads to impersonate popular AI developer tools including Claude AI, ChatGPT Codex, Perplexity, Cursor IDE, and JetBrains. Over seven weeks spanning April to June 2026, attackers deployed 106 unique malicious hostnames across six distinct waves, initially hosting ClickFix social engineering pages on GitLab infrastructure before pivoting to weaponize claude.ai's legitimate shared chat feature. The campaign targeted technically proficient users searching for AI development tools, tricking them into executing terminal commands that deployed the MacSync infostealer. This credential-harvesting malware collected browser data, SSH keys, and cryptocurrency wallets. The Asia-Pacific region sustained the heaviest impact with 67.2% of over 2,000 victims, particularly concentrated in Taiwan. Anthropic responded by banning malicious accounts and implementing additional abuse mitigations.",
  "published": "2026-06-18T10:09:50.681000+00:00",
  "created_at": "2026-06-18T20:35:01.645000+00:00",
  "modified_at": null,
  "created_at_opencti": "2026-06-18T20:35:01.645000+00:00",
  "author": "AlienVault",
  "confidence": 100,
  "report_types": [
    "threat-report"
  ],
  "labels": [
    "ai impersonation",
    "apac targeting",
    "clickfix",
    "gitlab pages abuse",
    "google ads abuse",
    "macsync",
    "macsync infostealer",
    "malvertising",
    "social engineering"
  ],
  "tags": [],
  "related_entities": {
    "indicators": [
      {
        "id": "f8e8d693-a9bb-44d9-be30-807a155f5dc5",
        "name": "plirepsijr74.com"
      },
      {
        "id": "a8c37a08-7b81-474b-9998-a77ba5d6338c",
        "name": "https://loserrq0j1sha8.com/debug/loader.sh?build=a39427f9d5bfda11277f1a58c89b7c2d"
      },
      {
        "id": "5a5fd633-66cd-4be5-b5a6-b355a5d335d9",
        "name": "isgilan.com"
      },
      {
        "id": "4234f3aa-39c3-42e8-883f-d06ed8894fa2",
        "name": "alabamarecoverycenter.com"
      },
      {
        "id": "d3c3e820-1ed9-4225-9114-20ed3dd9f182",
        "name": "yoauction.com"
      },
      {
        "id": "1351af31-3389-48c6-aa57-0c133013cf78",
        "name": "touristprogram.com"
      },
      {
        "id": "be23e386-91a8-44ac-8652-c24336a8a041",
        "name": "claude-code.official-version.com"
      },
      {
        "id": "aed9a5dc-fae3-43ff-8b34-72d0134e9d3c",
        "name": "customroofingcontractors.com"
      },
      {
        "id": "4b5482cb-ecb4-4f21-a818-07e319269c4b",
        "name": "thnikagent.com"
      },
      {
        "id": "83b6b26d-9214-46c9-ab5d-6604947343a8",
        "name": "briskinternet.com"
      },
      {
        "id": "8989071f-0343-4180-b759-842888e40aa6",
        "name": "loserrq0j1sha8.com"
      },
      {
        "id": "95f11769-936b-4e4a-93f6-c328438e7ae3",
        "name": "babulikinet.com"
      },
      {
        "id": "b94e9e1d-7538-472a-a732-c421094cfd74",
        "name": "20claude.ai"
      },
      {
        "id": "30cf7400-6605-4677-a7c6-848ee4e4ad7b",
        "name": "oaklandwaterdamage.com"
      },
      {
        "id": "8c4a8cd3-8b52-450f-8fd8-a2776660051d",
        "name": "a2abotnet.com"
      },
      {
        "id": "e3578e4e-fae0-4a70-8b46-274242d7e6ad",
        "name": "5x5web.com"
      },
      {
        "id": "df4bc600-0a79-4adc-9f6d-16e475da6054",
        "name": "homeinspectionnaperville.com"
      },
      {
        "id": "e160c9c5-9a46-46c7-9177-e48b5b5d73db",
        "name": "jerryshvac.com"
      },
      {
        "id": "55ea6285-011d-42b8-96b7-17ed17738388",
        "name": "bernasibutuwqu2.com"
      },
      {
        "id": "4b782721-fec3-4373-b4f1-b64415465ed8",
        "name": "peowqlauoshau8.com"
      },
      {
        "id": "be29aaa6-c0d9-4772-822e-e0854f5d5b1d",
        "name": "bewqslkslikrtjinfg9.com"
      }
    ],
    "attack_patterns": [
      {
        "id": "6ccd4566-e15e-40cf-b7df-4a3f737ce5cd",
        "name": "T1036.005"
      },
      {
        "id": "79525d9e-3824-4347-a471-7dcea20fd864",
        "name": "T1583.006"
      },
      {
        "id": "d3254e3b-07e6-4420-96e0-2e107ce17712",
        "name": "T1102.001"
      },
      {
        "id": "b7ba0db0-7d4f-436f-8d5f-c431d690b048",
        "name": "T1555.003"
      },
      {
        "id": "a72b6e11-a5d5-4f5a-8f0d-8861e90c34f7",
        "name": "T1555"
      },
      {
        "id": "e615d5ec-8d67-4048-b21d-a5fb09925bb9",
        "name": "T1552.001"
      },
      {
        "id": "97d377d8-89c7-48f8-a79f-0f48bd60df74",
        "name": "T1005"
      },
      {
        "id": "cbd87c8c-3bed-461a-acef-56ffc8b87571",
        "name": "T1105"
      },
      {
        "id": "2e0c6db7-16a7-4bf6-992e-263474014fce",
        "name": "T1059.004"
      },
      {
        "id": "b7c6c1ad-f183-4128-8427-3891029c73dc",
        "name": "T1539"
      },
      {
        "id": "52b92395-d3d3-4e05-976a-0fccccfce8d2",
        "name": "T1566.002"
      },
      {
        "id": "5b7c66d1-0466-4ba7-af6f-eb82c2f9d05b",
        "name": "T1033"
      },
      {
        "id": "fe6f2946-a01e-460c-9636-8c48b45dd0e6",
        "name": "T1189"
      },
      {
        "id": "05ac27d4-58d0-44b2-a984-cd5aefd1f7f9",
        "name": "T1497.001"
      },
      {
        "id": "1c9d3b0c-7ba8-40bc-be57-2c8e2495861d",
        "name": "T1204.003"
      },
      {
        "id": "0156fcda-e385-4662-b388-086c3e16feec",
        "name": "T1140"
      },
      {
        "id": "45082a8e-9c79-470e-ad1b-decac7188e8f",
        "name": "T1083"
      },
      {
        "id": "70616b2f-4019-4963-b758-5d9f6f20e201",
        "name": "T1082"
      },
      {
        "id": "fa3b8b48-d97c-4242-83a6-07d435a5a79e",
        "name": "T1041"
      }
    ],
    "malware": [
      {
        "id": "c057a34a-6d00-4fa4-976a-90d6d6ede9bc",
        "name": "MacSync",
        "slug": "macsync"
      }
    ],
    "observables": [
      {
        "id": "1b053482-6f06-4f64-970d-0dc73a7a5d4f",
        "name": "bewqslkslikrtjinfg9.com"
      },
      {
        "id": "168983a8-a502-4ebd-a10b-eac2eb1a6947",
        "name": "touristprogram.com"
      },
      {
        "id": "8ef04ac2-9e58-4fcc-aeab-1bad6672fc0b",
        "name": "alabamarecoverycenter.com"
      },
      {
        "id": "146c9857-0f41-4e43-afdd-eeac755346aa",
        "name": "20claude.ai"
      },
      {
        "id": "d928b750-2cac-4fd8-8952-74751e1663a8",
        "name": "customroofingcontractors.com"
      },
      {
        "id": "685d0eb5-2c7e-4209-852f-08a34e22fc16",
        "name": "homeinspectionnaperville.com"
      },
      {
        "id": "d64908ee-f8ba-4aef-85a9-2d8090936d43",
        "name": "babulikinet.com"
      },
      {
        "id": "276627c7-b7d5-4a00-b6f4-d2a1a3ae3f73",
        "name": "jerryshvac.com"
      },
      {
        "id": "70e9f2f3-3359-464b-8295-d07280966aaf",
        "name": "loserrq0j1sha8.com"
      },
      {
        "id": "671133a4-016a-449c-a720-6d8bfce05160",
        "name": "oaklandwaterdamage.com"
      },
      {
        "id": "f72ab820-4b66-4b97-a4c8-ffee0b74012c",
        "name": "5x5web.com"
      },
      {
        "id": "467e0f9b-c5a3-45b9-8e51-400cb9800aa7",
        "name": "briskinternet.com"
      },
      {
        "id": "7cc29b44-c07a-4e0f-b6de-a7877615f74f",
        "name": "yoauction.com"
      },
      {
        "id": "da03d171-f297-461c-8c3a-2c5cbe541ef8",
        "name": "thnikagent.com"
      },
      {
        "id": "d60e4237-2c61-4f9b-bd63-60a33eab3598",
        "name": "bernasibutuwqu2.com"
      },
      {
        "id": "e2dfebf5-2763-43e6-b8df-d4695a693103",
        "name": "a2abotnet.com"
      },
      {
        "id": "6233a121-ac1c-44ed-8d6c-2e6cf9876ed3",
        "name": "peowqlauoshau8.com"
      },
      {
        "id": "c40ade31-6d46-48ae-8f78-b255d5f2d674",
        "name": "plirepsijr74.com"
      },
      {
        "id": "fcc48f4b-a77b-4df0-8497-a36a98136162",
        "name": "isgilan.com"
      },
      {
        "id": "a33eaf6f-b55b-42cc-9b43-3d8471662661",
        "name": "claude-code.official-version.com"
      },
      {
        "id": "7f07df16-014d-4ee8-a87d-fb39b801203d",
        "name": "https://loserrq0j1sha8.com/debug/loader.sh?build=a39427f9d5bfda11277f1a58c89b7c2d"
      }
    ]
  },
  "external_refs": [
    {
      "id": "9959cd02-1e32-4fa6-afc0-9c859e59da4e",
      "standard_id": "external-reference--7e90ff77-0b26-521c-80f1-e620a24ad2c6",
      "entity_type": "External-Reference",
      "source_name": "AlienVault",
      "description": null,
      "url": "https://www.trendmicro.com/en_us/research/26/f/claudeai-shared-chat-abused-in-malvertising.html",
      "hash": null,
      "external_id": null,
      "created": "2026-06-18T20:35:01.582Z",
      "modified": "2026-06-18T20:35:01.582Z",
      "createdById": null
    },
    {
      "id": "6d733144-b7c4-45da-bf95-52e7056fdafe",
      "standard_id": "external-reference--805e604c-3b08-5457-8a79-0cda319dfabf",
      "entity_type": "External-Reference",
      "source_name": "AlienVault",
      "description": null,
      "url": "https://otx.alienvault.com/pulse/6a33c3eeab85c6e12893a90e",
      "hash": null,
      "external_id": "6a33c3eeab85c6e12893a90e",
      "created": "2026-06-18T20:35:01.544Z",
      "modified": "2026-06-18T20:35:01.544Z",
      "createdById": null
    }
  ]
}