Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware
Attackers distribute MacSync macOS infostealer via fake Claude and ChatGPT installers and sponsored search ads, stealing passwords, cookies, keys, and wallets.
SEQRITE reports a malware-as-a-service campaign pushing MacSync, a macOS password stealer, through sponsored search results and fake Claude and ChatGPT download pages. ClickFix-style prompts trick users into pasting a Terminal command that launches a stager, which loads an in-memory AppleScript to harvest credentials. The malware collects browser vaults, Keychain data, SSH keys, session cookies, messaging sessions, and cryptocurrency wallets, then persists via renamed LaunchAgents and can request screen-recording permissions.
Fake OpenAI Codex download tricks macOS users into installing malware
Cato Networks uncovered a malware campaign using sponsored search ads and fake OpenAI Codex pages to deliver an AMOS-like infostealer to macOS users.
Cato Networks researchers discovered a campaign using sponsored search results and a fake OpenAI Codex download portal on Google Sites to lure macOS users. Victims are instructed to paste a Terminal command that decodes a Base64-encoded URL and runs a multi-stage infection chain ending in a universal Mach-O binary. The delivery chain closely resembles Atomic macOS Stealer (AMOS), and related infrastructure impersonating Claude Code was also found. Operators use iframe-based hosting and path/device gating to evade analysts and automated scanners.
US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware
US, UK, and Dutch agencies warn Iranian state actors deploy Windows surveillance malware 'Chosen Brick' against dissidents, activists, and journalists worldwide.
Joint advisories from US, UK, and Dutch agencies describe Chosen Brick, a Windows surveillance malware active since at least 2025 and used by Iranian state cyber actors to track regime opponents. The malware harvests contacts, emails, and social media messages, persists via registry Run keys, evades Microsoft Defender, and uses per-victim Telegram bot IDs for command-and-control and exfiltration. Operators build rapport on WhatsApp and Telegram posing as acquaintances or support staff, disguising payloads as utility software or fake medical documents. Capabilities include screenshot capture, audio recording, credential theft, secondary payload delivery, and data wiping.
StreamRat Android malware spreads through Meta and TikTok ads
Malwarebytes reports StreamRat Android banking trojan spread via Meta and TikTok ads reaching roughly 570,000 users, mostly in Spain.
Malwarebytes researchers uncovered a malicious advertising campaign on Meta and TikTok promoting a fake free TV-streaming service that delivered the StreamRat Android banking trojan and infostealer. The ads, aimed at Spanish-speaking users with most victims in Spain, reached approximately 570,000 Meta users in a campaign running June 11 through July 3, 2026. The download site detected Android devices and the referral source, then coached users through sideloading steps including enabling installs from unknown sources. StreamRat can monitor the screen, capture typed credentials, display fake login screens, and give attackers remote control, including black-screen and fake Android update overlays.