
Tradecraft Tuesday | Fake Claude install guide, real macOS stealer
Source: YouTube · Huntress · published Aug 12, 2026 · 57:15
Threat actors are exploiting public interest in AI tools by weaponizing legitimate Claude share links to deliver a sophisticated six-stage macOS stealer campaign that steals credentials, crypto wallets, and establishes persistent remote access 1:02-1:07.
Key Takeaways:
• The attack begins when victims Google "install Claude on macOS" and click a malvertising link that directs them to a weaponized conversation hosted on the legitimate claude.ai domain, displaying "Apple Support" as the author 13:56-14:09
• Users are instructed to paste a base64-encoded curl command into Terminal, which silently fetches a polymorphic payload that evades hash-based detection by changing per victim 14:21-14:28
• The malware manipulates macOS's TCC (Transparency, Consent, and Control) framework to obtain Full Disk Access, using a clever technique that adds Terminal to the access list then prompts users to enable it 26:47-27:06
• Stage three steals browser cookies, SSH keys, AWS/Kubernetes configs, Apple Notes, and crypto wallet data, while also deploying a persistent RAT that communicates over encrypted WebSocket TLS with XOR-obfuscated fallback URLs 32:37-33:07
• The most damaging stage targets Ledger Live and Trezor Suite by replacing internal app components, redirecting users to fake recovery pages to harvest seed phrases—which cannot be revoked or reset once stolen 48:27-48:59
The most effective defense is simply not executing unverified commands; users should inspect base64 strings before running them, as the entire kill chain executes within seconds 51:22-51:36.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
[music] [music] >> All right. Good morning, everyone. Welcome to another episode of TradeCraft Tuesday, uh post Black Hat DEF CON edition here. So, I'm Lindsey Walsh with Huntress, and we've got a really cool show today for everybody. Uh you know the drill while we kick it off, uh feel free to give a shoutout in the comments where you're tuning in from, or maybe, you know, if you went to hacker summer camp last week, you know, what your favorite session or thing about it was. So, today two of our experts from our SOC are going to be talking about a fake Claude install guide that actually led to uh the deployment of Max Stealer, um which, you know, we've actually seen quite a bit of malvertising campaign stemming from people's interest in AI, which may come as no surprise. We actually saw a…