Hackers abuse Google ads, Claude.ai chats to push Mac malware
2026-05-11T07:23:27Z•8eba002c9f1c2b4dac4d259c987d740acee03d291f7a87d02b7aea5ae6ddbfd4
CISACanvas defacementClaude.aiCrimenetworkGoogle AdsHugging FaceIvantiJDownloaderLinux Dirty FragNVIDIA GeForce NOWPython RATRansomHouseShinyHuntersTCLBanker','WhatsApp propagation','Outlook propagation','trojan‑compromised websitedata breachinfostealerlocal privilege escalationmac malwaremalvertisingmarketplace takedownroot exploitsource-code leaksupply-chain compromisezero-day
What happened
Multiple active threats and breaches were reported: attackers are abusing Google Ads and legitimate Claude.ai shared chats to deliver Mac malware via malicious download instructions; the JDownloader site was compromised to serve Windows and Linux installers that deploy a Python RAT; a fake OpenAI repo on Hugging Face pushed an info‑stealer to Windows users; and NVIDIA confirmed a GeForce NOW user data exposure affecting Armenian users. Law enforcement shut down a reboot of the Crimenetwork marketplace and arrested its operator, while Trellix source code leaks were claimed by RansomHouse. High‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 8eba002c9f1c2b4dac4d259c987d740acee03d291f7a87d02b7aea5ae6ddbfd4
- Enrichment time
- 2026-05-11T07:23:27Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.