Hackers use Google Ads to share chat from Claude.ai
Hackers detected using Google Ads to share chat from Claude.ai to make fake ads, release malware
According to a report by the website Bleeping Computer, a new Malvertising campaign using Google Ads advertising systems in conjunction with the Chat Sharing system of artificial intelligence or AI (Artificial Intelligence) Claude.ai has been used to spread malware to a group of people who use the macOS operating system with the search "Claude mac download," which, with Claude's Chat Sharing, allows the victim to see the URLs on the ads as claude.ai trapped in the end by downloading malware applications.
In this regard, researchers from Trendyol Group, an e-commerce company from Turkey, said that after the victim presses the link, Claude's chat will be found with the installation instructions. The instructions ask the victim to launch the Terminal app to run the command (Command), claiming to install the Claude application, but it is actually a malware installation to the machine. In addition to the campaign found by this researcher, the source (Bleeping Computer) found another campaign that was slightly different during the payload.
The campaign that researchers found downloaded the Payload file from hxxp: / / customroofingcontractors [.] com / curl / b42a0ed9d1ecb72e42d6034502c304845d98805481d99cea4e259359f9ab206e
While the campaign found by the source will be downloaded from hxxps: / / bernasibutuwqu2 [.] com / debug / loader.sh?build=a39427f9d5bfda11277f1a58c89b7c2d
The latter campaign is clearly a PowerShell script file compressed with a Gunzip called 'loader.sh'. This script runs directly on the memory, leaving very few traces to detect on the system. In addition, when you delve into it, you find that the server, when you receive a Payload request, will send a version that has been inserted to confuse the detection system (Obfuscation). Signature Analysis is also difficult to detect.
In the field of malware, it will start by checking whether the victim's machine is active in Russian or in the Commonwealth of Independent States. If it is detected, it will stop immediately by sending Ping that cis _ blocked back to the server. If not, the malware script will work in the next step by retaining the victim's information, such as external IP number, hostname, active operating system version, and keyboard language details, sent back to the server.
Script then downloads the second payload and installs it using a macOS-based tool like osascript to run such a payload. This is a method of remote execution (RCE or Remote Code Execution) without releasing Binary files. The malware is found to be a MacSync subspecies of malware that is a system-based data theft type or Infostealer. This malware has the ability to steal passwords, Cookies files, and password data saved on macOS Keychain. These are found to be The pack is included in the same package and then secretly sent (Exfiltration) back to the control server (C2 or Command and Control), which is expected to be located on the briskinternet [.] com domain, extrapolating from the script of the malware detected.
# Trending # Lemon 8 Howtoo # lemon 8 diary # freedomhack # google

















































































