Security researchers have identified a sophisticated malvertising campaign targeting users of Anthropic’s Claude AI by leveraging Google Ads to funnel high-intent AI developers toward “ClickFix” social engineering attacks.
The campaign specifically targets keywords such as “Claude download” and “Claude Mac download.” Once a user clicks the ad, they are eventually routed to a landing page designed to harvest credentials or deploy malware.

The core of the threat is the “ClickFix” or “PasteFix” technique. Rather than relying on a traditional download button, the malicious landing pages present a fake error message, often claiming a connection issue or a missing component. Users are prompted to click a button to “fix” the problem, which silently copies a malicious command to their clipboard. The page then instructs the user to open a system utility—PowerShell on Windows or the Terminal on macOS—and paste the command to resolve the error.
Recent iterations of this campaign have shown an evolution in infrastructure. According to research by Zscaler, attackers are increasingly moving away from standalone phishing sites in favor of abusing the official claude.ai domain. By using legitimate shared Claude chat links to host malicious instructions, the scam gains a layer of perceived authenticity that traditional phishing sites lack. The shared chat interface serves as the lure, convincing users that the instructions are part of an official troubleshooting process provided by the AI.
When the pasted command is executed, it typically triggers a base64-encoded shell script. This script facilitates the delivery of various info-stealers, including Lumma Stealer and MacSync. These payloads are designed to harvest sensitive data from the infected machine, such as browser cookies, stored credentials, and cryptocurrency wallet information.
To combat these “paste-and-run” tactics, Apple has reportedly introduced specific OS-level protections in the latest builds of macOS. macOS Tahoe 26.4 and later versions have reportedly implemented warnings specifically designed to alert users about potential ClickFix “paste-and-run” attacks. These warnings act as a final barrier against social engineering attacks that rely on user-initiated command execution. Security experts recommend that users avoid interacting with search ads for software downloads and instead navigate directly to official vendor websites.
