Hackers are spreading infostealers through fake Google Docs files, malicious GitHub files, and spoofed Claude.ai pages, while also posing as CoinDesk employees on X to trick users into installing malware. According to Odaily, Mac users face the Atomic macOS Stealer threat, Windows users are being pushed a fake Google API Connector update, and devices have been infected with NetSupport RAT and a counterfeit Ledger app.
The attackers are also placing fake ads on Bing to direct users to spoofed Claude.ai pages. Odaily said MacSync and SectopRAT can steal cookies, passwords, seed phrases, and payment card information, and 16 malicious extensions for Chrome and Edge were found that can drain EVM, Solana, and Tron wallet assets.