A malvertising campaign is using Google Ads and a fake Claude Code installer to reach macOS users, showing how cybercrime now leans on trust instead of obvious exploits.
A Claude Desktop-themed download flow is being used to deliver SectopRAT, showing how ad-driven redirection and fake installers can turn brand trust into a credential and file theft problem.
A malware chain built around ScreenConnect abuse and fake installers shows how attackers can turn everyday remote-management habits into a quiet path to AsyncRAT.
A renewed ValleyRAT wave uses installer lures and Japanese-language email bait to turn ordinary Windows trust decisions into remote-control risk.
Counterfeit installers posing as Gemini CLI and Claude Code show how search manipulation can become a delivery channel for malware, even when the underlying products are not the target.
A spoofed Gemini CLI download path shows how attackers can turn ordinary developer search habits into a delivery channel for malware.
A fake download package built around HWMonitor shows how DLL sideloading can turn ordinary software execution into a covert malware path.
A counterfeit installer aimed at developers highlights how trusted setup habits can be repurposed into browser password and cookie theft.
A reported malvertising chain uses Google Ads and shared Claude chats to steer users toward a MacSync malware variant by making a fake developer-tool guide look routine.