Skip to Content
Company: Banner with Media - Background

INC-2026-001: Fake “Claude for Mac” Malvertising Leads to a macOS Infostealer Compromise

Overview

In August 2026, a Sophos employee setting up a new macOS (Apple silicon) laptop searched a public web search engine for a desktop build of a legitimate AI-assistant application. The user clicked a malicious sponsored advertisement that impersonated the software vendor, and was redirected to a newly registered lure domain. The page presented a “ClickFix” social-engineering prompt instructing the visitor to copy a command into the macOS Terminal to complete the installation. The user followed the instruction and pasted the command.

The command was a loader that retrieved a multi-stage macOS infostealer from attacker-controlled infrastructure. Over a period of roughly two minutes the malware collected locally stored secrets, staged approximately 16.5 MB of data, exfiltrated it over HTTP to a command-and-control (C2) server, installed a privileged persistence mechanism disguised as an Apple system service, and deleted its staging directory to remove evidence. We assess the capability to be an AMOS-class macOS information stealer based on its behavior and artifacts.

The endpoint’s on-device antimalware was installed and running throughout, but it did not block the delivery, execution, persistence, or exfiltration. Detection came from Sophos MDR behavioral analytics, which flagged the malicious post-execution activity as it occurred, within the same two-minute window. The confirmed compromise was escalated to the Sophos internal incident response team later that day. The team isolated the endpoint and, together with IT, reset the affected user’s corporate credentials and active sessions within hours of the case being opened. The exposed developer personal access token was rotated as a further precaution, with rotation confirmed several days later.

A subsequent enterprise-wide threat hunt across the endpoint estate, together with a source-control audit of the exposed developer token, confirmed that the activity was confined to the single endpoint. No lateral movement was observed, and no abuse of the exfiltrated credentials was seen. SophosLabs analyzed the recovered samples, deployed global blocks for the attacker infrastructure, and released endpoint detection signatures for the malware components. The device was rebuilt and returned to service.

Impact

The impact of this incident was limited to a single internal Sophos endpoint. No Sophos customers, customer data, customer-facing systems, or Sophos products and services were affected.

Because the malware harvested locally stored data before it was contained, all secrets accessible from the affected user’s profile were treated as compromised. The harvested data included operating-system keychain contents, browser-saved credentials, password-manager vault data, cloud and developer access keys (AWS, Google Cloud, Docker, and FileZilla), SSH keys, a developer personal access token, messaging-application session data, shell and browser history. Approximately 16.5 MB of data was exfiltrated. As a precaution, every harvested item that could be rotated was rotated: the keychain contents, the browser-saved and password-manager-stored credentials, the cloud and developer access keys, the SSH keys, and the developer personal access token. Items that cannot be rotated — including the messaging-application session data and shell and browser history — were treated as disclosed.

The following were explicitly confirmed during the investigation:

  • No lateral movement from the affected endpoint to any other host was observed.
  • Enterprise-wide endpoint threat hunting identified no additional affected hosts (no co-victims).
  • An audit of the exposed developer personal access token found no evidence of misuse.
  • No customer or production environment was accessed, and no Sophos product or service was affected.

Timeline

Rows are mapped across the incident response lifecycle: detection and analysis, containment, eradication, and recovery.

Time (UTC)EventActor
August 28, 2026 06:21 UTCUser searched a public web search engine for a macOS build of a legitimate AI-assistant desktop application.User (Sophos employee)
August 28, 2026 06:21 UTCUser clicked a malicious sponsored advertisement impersonating the vendor and was redirected to a newly registered lure domain presenting a “ClickFix” prompt.Threat actor
August 28, 2026 ~06:22 UTCFollowing the on-page instructions, the user pasted a Terminal command that fetched a first-stage loader from attacker infrastructure.User (Sophos employee)
August 28, 2026 06:22–06:24 UTCA hidden Apple-silicon payload executed, collected local secrets, staged ~16.5 MB of data, exfiltrated it over HTTP to C2, installed a privileged LaunchDaemon disguised as an Apple system service, and deleted its staging directory.Threat actor
August 28, 2026 06:22–06:24 UTCSophos MDR behavioural analytics detected the payload execution, credential and data collection, C2 communication, exfiltration, and persistence.Sophos MDR (Detection & Analysis)
August 28, 2026 (morning)MDR escalated the confirmed compromise to the Sophos internal incident response team; a case was opened and assigned for investigation.Sophos MDR / IDR
August 28, 2026 ~13:55 UTCThe affected endpoint was isolated from the network via XDR.IDR (Containment)
August 28, 2026 15:00 UTCCorporate credentials and active sessions for the affected user were reset and revoked.IT / IDR (Eradication)
August 28 – September 2, 2026Live-response forensic triage was collected and analyzed by SophosLabs; an enterprise-wide XDR threat hunt and a source-control audit confirmed a single affected host with no lateral movement and no observed credential abuse.IDR / SophosLabs
August 31, 2026 ~16:00 UTCRotation of the exposed developer personal access token was confirmed.IT / IDR (Eradication)
September 2, 2026SophosLabs deployed global blocks for the attacker infrastructure and released endpoint detection signatures for the malware components; the device was rebuilt, returned to service, and network isolation was lifted.SophosLabs / IT (Eradication & Recovery)