
Hackers are stealing access to crypto wallets via Google Docs and Claude. Attackers are actively exploiting the cloud editor and the GitHub platform. Fraudsters are also spoofing pages of Anthropic's neural network. This was reported by security specialists from Huntress. They described an incident involving a participant in the Black Hat conference. The victim had also attended the DEF CON expo. The attacker initiated a conversation with the user on the social network X, posing as a senior staff member of CoinDesk. He offered the user an opportunity to participate in a conference and sent over a document.
The fake document prompted the user to enter a special encryption key. The system deliberately displayed a critical error. The victim then received detailed instructions on how to fix the issue and ended up installing malicious software themselves. Mac users were directed to download a file from GitHub. Researchers identified similarities between the code and the known AMOS virus. The program steals browser passwords and crypto wallet data, and also exfiltrates files from Telegram. Windows users were shown a fake Google API Connector update.
The NetSupport RAT tool was covertly installed on the device. Fraudsters deployed a fake Ledger hardware wallet application. Attackers also used spoofed Dropbox DocSend files. Hackers placed fraudulent ads in the Bing search engine, targeting people searching for instructions on how to install the neural network. Victims were redirected to a disguised Claude AI page whose interface fully mimicked a standard chatbot conversation. Instead of instructions, users were prompted to execute a specific command, which instantly resulted in the installation of infected software.
Specialists outlined the capabilities of the MacSync malware. The virus steals cookies and saved passwords, as well as secret seed phrases from crypto wallets, and modifies applications to request those secret phrases. Another program, SectopRAT, steals payment card data, VPN credentials, and wallet logins. The company Socket discovered sixteen malicious browser extensions targeting Google Chrome and Microsoft Edge. The programs steal cryptocurrencies from EVM, Solana, and Tron networks.

