Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Shared Claude Chats Meet ClickFix

stratos37.com

TLP:CLEAR
Active

Domain

Description

A ClickFix campaign has been identified that abuses Anthropic's Claude platform through shareable chat links to distribute MacSync Stealer targeting macOS users. Attackers utilized malvertising with paid Google ads to direct victims searching for Claude-related terms to malicious shared Claude chats falsely labeled as 'Apple Support.' These chats contained obfuscated installation commands that, when executed, deployed a multi-stage infection chain. The malware steals credentials from browsers and password managers, cryptocurrency wallet data, sensitive files, and system information. The campaign ran from June 12-19, 2026, targeting primarily Mac users with Russian-language comments in the code suggesting Russian-speaking threat actors. Domains used adopted themes related to U.S. local services to appear legitimate.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Shared Claude Chats Meet ClickFix
Pattern Type
STIX
Confidence
75%
Valid From
Jul 15, 2026 22:01
Total Sightings
0
Added
Jul 15, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of stratos37.com

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.