Hackers abuse Google ads, Claude.ai chats to push Mac malware

2026-05-11T07:23:27Z8eba002c9f1c2b4dac4d259c987d740acee03d291f7a87d02b7aea5ae6ddbfd4
CISACanvas defacementClaude.aiCrimenetworkGoogle AdsHugging FaceIvantiJDownloaderLinux Dirty FragNVIDIA GeForce NOWPython RATRansomHouseShinyHuntersTCLBanker','WhatsApp propagation','Outlook propagation','trojan‑compromised websitedata breachinfostealerlocal privilege escalationmac malwaremalvertisingmarketplace takedownroot exploitsource-code leaksupply-chain compromisezero-day

What happened

Multiple active threats and breaches were reported: attackers are abusing Google Ads and legitimate Claude.ai shared chats to deliver Mac malware via malicious download instructions; the JDownloader site was compromised to serve Windows and Linux installers that deploy a Python RAT; a fake OpenAI repo on Hugging Face pushed an info‑stealer to Windows users; and NVIDIA confirmed a GeForce NOW user data exposure affecting Armenian users. Law enforcement shut down a reboot of the Crimenetwork marketplace and arrested its operator, while Trellix source code leaks were claimed by RansomHouse. High‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
8eba002c9f1c2b4dac4d259c987d740acee03d291f7a87d02b7aea5ae6ddbfd4
Enrichment time
2026-05-11T07:23:27Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.