Automatically translated.View original post

Hackers use Google Ads to share chat from Claude.ai

Hackers detected using Google Ads to share chat from Claude.ai to make fake ads, release malware

According to a report by the website Bleeping Computer, a new Malvertising campaign using Google Ads advertising systems in conjunction with the Chat Sharing system of artificial intelligence or AI (Artificial Intelligence) Claude.ai has been used to spread malware to a group of people who use the macOS operating system with the search "Claude mac download," which, with Claude's Chat Sharing, allows the victim to see the URLs on the ads as claude.ai trapped in the end by downloading malware applications.

In this regard, researchers from Trendyol Group, an e-commerce company from Turkey, said that after the victim presses the link, Claude's chat will be found with the installation instructions. The instructions ask the victim to launch the Terminal app to run the command (Command), claiming to install the Claude application, but it is actually a malware installation to the machine. In addition to the campaign found by this researcher, the source (Bleeping Computer) found another campaign that was slightly different during the payload.

The campaign that researchers found downloaded the Payload file from hxxp: / / customroofingcontractors [.] com / curl / b42a0ed9d1ecb72e42d6034502c304845d98805481d99cea4e259359f9ab206e

While the campaign found by the source will be downloaded from hxxps: / / bernasibutuwqu2 [.] com / debug / loader.sh?build=a39427f9d5bfda11277f1a58c89b7c2d

The latter campaign is clearly a PowerShell script file compressed with a Gunzip called 'loader.sh'. This script runs directly on the memory, leaving very few traces to detect on the system. In addition, when you delve into it, you find that the server, when you receive a Payload request, will send a version that has been inserted to confuse the detection system (Obfuscation). Signature Analysis is also difficult to detect.

In the field of malware, it will start by checking whether the victim's machine is active in Russian or in the Commonwealth of Independent States. If it is detected, it will stop immediately by sending Ping that cis _ blocked back to the server. If not, the malware script will work in the next step by retaining the victim's information, such as external IP number, hostname, active operating system version, and keyboard language details, sent back to the server.

Script then downloads the second payload and installs it using a macOS-based tool like osascript to run such a payload. This is a method of remote execution (RCE or Remote Code Execution) without releasing Binary files. The malware is found to be a MacSync subspecies of malware that is a system-based data theft type or Infostealer. This malware has the ability to steal passwords, Cookies files, and password data saved on macOS Keychain. These are found to be The pack is included in the same package and then secretly sent (Exfiltration) back to the control server (C2 or Command and Control), which is expected to be located on the briskinternet [.] com domain, extrapolating from the script of the malware detected.

# Trending # Lemon 8 Howtoo # lemon 8 diary # freedomhack # google

4 hours agoEdited to

Related posts

Powerful Websites
#freewebsite #website #fromsoftware #fyplemon8 #fyp
Tha Smoke Websites

Tha Smoke Websites

700 likes

A laptop with a cloudy sky wallpaper and a white cup with a red logo. Text overlay reads: 'Free Websites That Saved My GPA AND MY SANITY Sharing So You Don't Struggle Too'.
A laptop screen displays Yahoo search results for 'Quizlet'. An overlay describes Quizlet as a free flashcard tool for memorizing terms, definitions, and formulas, making studying feel like a game.
A laptop screen displays Yahoo search results for 'Unriddle.ai'. An overlay describes Unriddle.ai as a free tool that breaks down notes, articles, or assignments to aid understanding of long readings.
Websites You NEED to Pass Your College Courses
Y’all college is hard enough without trying to figure everything out on your own 😩 So here’s my list of websites that actually helped me pass my classes like, these were in my survival kit. I’m not gatekeeping 🫶🏽 Quizlet When I needed to memorize terms FAST. I used it for flashcards, and the matc
Beauty

Beauty

285 likes

The image shows a keyboard with a fingerprint icon, overlaid with "OUTSMART HACKERS" and "Secrets they don't want you to know," serving as the title for a guide on cybersecurity.
This image explains hackers use software to guess passwords and advises creating long passwords with a random mix of letters, numbers, and symbols to defend against such attacks.
The image warns that hackers try common passwords and advises users to defend themselves by avoiding easy words/phrases and not reusing passwords across different sites.
SECRETS Hackers DON’T Want You to Know!
After hackers got into my Facebook account and completely erased it, I dusted myself off and started a deep dive to understand why and how hackers work. The best way to protect yourself is to outsmart them. Here are 5 secrets Hackers DON'T want you to know! Share this with everyone! #lemon8pa
techgirljen

techgirljen

424 likes

SIEGEX is all CHEATERS & HACKERS😭
Why is this game full of cheaters and hackers and bugs🤷‍♀️ #siege #rainbowsixsiege #gaming #streamer #foryou
Phasma

Phasma

39 likes

A laptop displaying a vibrant floral wallpaper on a wooden desk, accompanied by a blue cloud wrist rest, pink mouse, and books, with the overlay text "Make google CHROME BETTER."
The best google chrome extension
Ever played around with Chrome extensions? They’re like little hacks to make browsing aesthetic and functional. From widgets to wallpapers, it’s the easiest way to give your browser personality. #techreview #browser #laptop #google
Amelia Cozy Nook

Amelia Cozy Nook

85 likes

#yungblud
watch4hackers

watch4hackers

8 likes

Ban Hackers
Vinicius Jr 🇧🇷 #fcmobile #eafcmobile #fifamobile #fcmobile25 #eafc
manuelofficial_13

manuelofficial_13

1 like

A message to Minecraft hackers…
You should join the server #minecraft #gaming #fyp
BendersMC

BendersMC

13 likes

Taco Tuesday 🤯 Admin Abuse ⁉️ #stealabrainrot #robloxstealabrainrot #roblox #neoskittles
NeoSkittles

NeoSkittles

6 likes

My head hurts and my heart feels anxious about AI, how about u? #ai #aiagents #aiforbeginners #chatgpt #gemini #claude #marketingtips
celinefung_

celinefung_

9 likes

A phone displaying the ChatGPT app interface with text overlay 'my Chat GPT got hacked' and 'essential security steps I wish I did sooner', alongside the ChatGPT logo.
Text explaining a ChatGPT account hack due to session token access, with random chats appearing. It introduces security steps, shown with a stylized ChatGPT interface.
Instructions on how to 'Turn On 2FA' for ChatGPT, detailing steps to enable multi-factor authentication in settings, with a screenshot showing the 'Enabled' status.
ChatGPT Security Settings You Shouldn’t Skip 🔐
So… my ChatGPT account got hacked 😳 Someone got access to my session token and random people started chats on my account. I could literally see everything happening in real time. Here are the basic security steps I really wish I had done earlier 👇 📌 Turn on 2FA - adds an extra layer of prote
Unrealtoreal

Unrealtoreal

184 likes

The image shows a phone screen displaying a 'Creating...' message with text claiming entities are 'hackers, trackers and child predators.' It includes a person surrounded by swirling energy and mentions Lilith, Satan, and Ra as parasitic beings.
The image displays a list of AI prompt suggestions, including 'Make me best friends with the Grim Reaper drinking boba tea,' which is circled. Below, text questions why befriending the Grim Reaper (Satan) is acceptable.
The image features a person with swirling energy and text stating, 'Can't create videos of prominent figures. Try something else instead.' It questions when Satan, Lilith, and Ra became prominent figures, describing them as disembodied beings preying on teens.
YouTube made Satan/Lilith/Ra (Demon Spirits) Prominent Figures #teen YouTube
I claim my protected emotional, mental, emotional, and digital space. All energetic loosh and currency stays with me, not those who prey upon it. *"I do not give, offer, or forfeit my crown to the dark forces who oppose me."* Those who steal will, with crafted weaved intentions div
Energy Frequency & Magic

Energy Frequency & Magic

0 likes

PSA PSA PSA ‼️ #fyp #hackers #facebook #scammers #viral
Kay’s House ✨

Kay’s House ✨

2 likes

WARZONE HACKERS
Warzone is full hackers and call of duty does not care #warzone #hacker #memesdaily #memes🤣 #gaming
DUSTINMYRQ ™

DUSTINMYRQ ™

5 likes

too much to ask?
Riley - Dropshipping & eBay

Riley - Dropshipping & eBay

0 likes

Learn real AI skills in just 10–15 mins a day with Coursiv. Use code LEARN20 #coursiv #learning #skills
mischa.renee

mischa.renee

1 like

Use your BRAIN 🧠 🧳✈️↙️
Don’t say I never give you GREAT travel tips 🤷🏾‍♀️🧳✈️ 🔗Access this vacuum under “AMAZON FINDS” link in my bio. Direct link → amzn.to/3r774RZ 🔗 🧳Recommended carryon suitcase: @calvinklein 📝Tag @calvinklein to let them know that one of your fav travel besties is @thetravellingafro 😘 #use
TravellingAfro

TravellingAfro

10 likes

BIG Holiday Costco Shop & Haul | Anchorage, Alaska
vanditsv

vanditsv

2 likes

I wanted a real project I could actually show, not just talk about. So I used Atoms ⚛️ Check it out here: https://tinyurl.com/3xzc8xbe It feels like having a whole AI team helping me: 🔍 they do the deep research first 🏁 then Race Mode builds different versions so I can compare 👥 I just pick
emilie.studygram

emilie.studygram

19 likes

Hackers
How call of duty has me #call of duty #hacker #warzone
Stevie_Wonders

Stevie_Wonders

1 like

Just An FYI This Is How So Many People are Getting Hacked!!! Plz Don’t Fall For Message Like These!!! it’s A Fake Account!!! #fakeaccount #hackers
MaryBell

MaryBell

2 likes

Bumble is killing the swipe and replacing it with an AI that interviews you and builds a full profile on your values, relationship goals, and dating intentions. 🚨 Here is why that is a privacy red flag: 1️⃣ One company now holds your most sensitive psychological data, sexual orientation, location
Cybersecurity Girl

Cybersecurity Girl

1 like

scammers and hackers beware
Hudson
cercofhell

cercofhell

27 likes

These Hackers on Marvel Rivals getting crazy!
#marvelrivals #twitchtv #followme #Hackers #marvelfunny
MisFit Miracles

MisFit Miracles

2 likes

warzone hackers be mad little babies
#cod #ps5 #gamergirl #warzone #fuckhackers
Twilightvile

Twilightvile

2 likes

Bumble is killing the swipe and replacing it with an AI that interviews you and builds a full profile on your values, relationship goals, and dating intentions. 🚨 Here is why that is a privacy red flag: 1️⃣ One company now holds your most sensitive psychological data, sexual orientation, loca
Cybersecurity Girl

Cybersecurity Girl

1 like

Bigfoot Super Hackers.
#manthoughts #hackers #laughoutloud #bigfootvlog #lifetips
Alien Hayes

Alien Hayes

13 likes

Hackers are using tricks & steal financial info.🌸🍋
SECURITY TIPS: Be careful from hackers they use multiple different types of software and tricks to steal data from computers, cell phones or other devices to steal your data, financial information and personal details. When they hack via computer systems Showing they are from Microsoft Security Ale
Mujahid Bakht

Mujahid Bakht

6 likes

Replying to @Red what parts or the dark web live in your brain rent free? #scarystories #horror #eductional #darkweb
Liz Cooper🦋

Liz Cooper🦋

43 likes

Kalebdavis19

Kalebdavis19

1 like

⚠️ The Hidden Dangers of Public Wi-Fi Free Wi-Fi feels convenient, but it can be a trap. Hackers can create what’s called an “evil twin” network—a fake hotspot that looks legitimate. The moment you connect, they can access your data, passwords, banking info, and private messages. Listen
Dannah Eve

Dannah Eve

82 likes

i spent 11 hours on a creative brief and i don't know if words are real anymore. if you're not hunting customer pain points like a heat-seeking missile, you're not going deep enough.
Mei

Mei

0 likes

Hackers Be Like:
#fypage
AidenIsMyself

AidenIsMyself

0 likes

King Trump
GrouchyGrandpaChannel

GrouchyGrandpaChannel

3 likes

Bumble is killing the swipe and replacing it with an AI that interviews you and builds a full profile on your values, relationship goals, and dating intentions. 🚨 Here is why that is a privacy red flag: 1️⃣ One company now holds your most sensitive psychological data, sexual orientation, loca
Cybersecurity Girl

Cybersecurity Girl

2 likes

A humanoid robot uses a laptop displaying 'MAKE MONEY ONLINE DIGITAL PRODUCTS' with icons for images, documents, and music, while dollar bills float in the background, illustrating AI's role in generating income through digital products.
A tablet on a desk shows a cover image with a robotic figure and the title 'Digital Marketing With A.I.', representing a digital marketing mastery course focused on artificial intelligence.
A text list titled 'Mastery Bundle: Training's List: Part 1' details various digital marketing and content creation courses, including CapCut, Instagram, TikTok, and Systeme.IO training, flanked by two small robot figures.
😳 HOW To Use ChatGPT To Make $500-$1000 a Week
This is the best investment I have ever made in my life. It was only $97 and the amount of trainings you get is insane. Since I started on December 31, 2024 I’ve made over $27K using ChatGPT and AI to create multiple digital products. Mastering AI now will help solidify you and your family’s
jtiz

jtiz

2 likes

This is a keyboard for hackers.
Barry

Barry

1 like

You shouldn’t be worried about the hackers, you should be worried about your settings. Check out ThreatLocker DAC today #ad #cybersecurity
Cybersecurity Girl

Cybersecurity Girl

25 likes

HACKERS IN THE BETA
Blackops 7 has hackers already…. #hacker #blackops7 #bo7
Goofstha

Goofstha

1 like

Blue jackets hockey is on the riseeeeeeee
peyton

peyton

1 like

A large scoreboard in Nationwide Arena displays "COLUMBUS BLUE JACKETS VS WASHINGTON CAPITALS" with team logos and a "PREGAME 6:52" countdown. The arena seating is visible in the background.
Four hockey players and a referee are on the ice near the center circle during a game. Two players wear dark jerseys, one with number 23, and two wear white jerseys.
An aerial view of a hockey game in progress, showing players on the ice and spectators in the stands. The scoreboard in the upper right corner indicates the 3rd period with 1:23 remaining and 46 shot attempts.
Columbus blue Jackets hockey
Pre season came to an end at home, home opener Monday October 13th! #columbusbluejackets #hockey #ohio
Kalebdavis19

Kalebdavis19

14 likes

KillerBeeTac

KillerBeeTac

28 likes

A smartphone displays a message asking God to unblock it due to hackers. A patterned pad and colorful items are in the hazy background. The image includes Lemon8 branding and a username.
God, please unblock this android, hackers have in
Olga Ledbetter

Olga Ledbetter

37 likes

Chinese Hackers Breach U.S. Treasury
#cybersecurity #cyberattack #ustreasury #janetyellen
Her Tidings

Her Tidings

0 likes

SEPT WRAP UP PT 1.
september had me in a CHOKEHOLD y'all 😮‍💨 i read so much i have to break this into TWO PARTS 😂😂 • 47 books read (don't play with me •) • 19 new authors • multiple favorites that little binge had me blowing right past my 200 book goal, so you know i had to bump it up to 250 from messy d
LEXI 💓

LEXI 💓

33 likes

Nice one boys
#cod #callofdutyp #codapartments #pvp #ashika #finalexfil #ashikapowerplant #almazrah #talkingshit #squad #dmz #gamer #sniper #headshot #longrange #headbussa #letthebodieshitthefloor #proxie #closecombat #closecombatfight #talkingshit #kamikazi #nomercy #nolovelost #groundhack #rocke
TheAuditor

TheAuditor

1 like

See more