MacSync Stealer Targets macOS via Malicious Google Ads Campaign
Article Content
- •MacSync Stealer is distributed via Google Ads impersonating Claude Code CLI.
- •The malware targets macOS systems, stealing credentials and compromising crypto wallets.
- •Beezlebub Labs has reverse-engineered the attack, revealing its multi-stage infection process.
The MacSync Stealer, a newly identified macOS infostealer, is being distributed through a sophisticated malvertising campaign on Google Ads that mimics Anthropic’s Claude Code CLI. Security researchers from Beezlebub Labs have detailed a multi-stage infection process that includes social engineering, credential harvesting, and persistent hijacking of cryptocurrency wallets. The malware not only steals credentials but also compromises Ledger Live and Ledger Wallet applications to extract crypto seed phrases. This campaign poses a significant risk to macOS users, particularly those involved in cryptocurrency transactions. The full scope of the attack and the number of affected users is still under investigation. The researchers utilized their threat-intel platform Caronte to reverse-engineer the malware and understand its operation. As of now, the campaign remains active, and users are advised to exercise caution when interacting with ads related to Claude Code.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (9)
Following this threat?
Track MacSync Stealer and Ledger in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
HBO Max Account Compromise Fuels ClickFix Malware Campaign In September 2026, hackers compromised the verified HBO Max Reddit account, launching a ClickFix campaign that distributed 108 malicious ads over 48 hours. The ads targeted both macOS and Windows users, tricking them into executing commands that installed information-stealing malware. This operation, dubbed…
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…