Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Exploit AI Platforms for Sophisticated Attacks

Hackers Exploit AI Platforms for Sophisticated Attacks

Posted on June 18, 2026 By CWS

Cybersecurity experts have identified a growing trend where hackers are leveraging reputable AI platforms to conduct advanced social engineering attacks. Recent findings reveal that cybercriminals have been exploiting Claude.ai’s shared chat feature to host harmful ClickFix instructions.

Evolution of ClickFix Tactics

Research by TrendAI uncovers that attackers implemented 106 unique malicious hostnames across six campaign waves over seven weeks. By continuously changing their infrastructure and employing various AI-themed tactics, they aimed to enhance the success of their campaigns.

This operation signifies a shift in ClickFix strategies, moving away from conventional malicious hosting to using trusted platforms like Claude.ai. Initially, the campaign utilized GitLab Pages with over 90 malicious subdomains impersonating popular AI developer tools such as Claude AI and ChatGPT Codex.

Manipulating Trusted Platforms

Hackers used Google Ads to lure technically skilled individuals searching for these AI tools. By doing so, they increased the chances of interaction from users who might be inclined to execute the suggested commands.

Victims were deceived into manually running harmful commands under the guise of software installation or repair. This method bypasses traditional security measures, as users unknowingly execute the payload themselves.

Geographical Targeting and Response

The campaign saw a significant escalation in May 2026 when attackers exploited Claude.ai’s shared chat feature. Malicious ads redirected users to legitimate Claude.ai URLs, avoiding common security warnings and protections.

TrendMicro’s analysis revealed that the payload included the MacSync infostealer, targeting macOS systems and collecting sensitive data. The campaign mainly targeted the Asia-Pacific region, with Taiwan accounting for over 30% of traffic, followed by Japan and Singapore.

In response to these threats, Anthropic has banned malicious accounts and removed harmful shared chats from Claude.ai, implementing further measures to prevent future abuse.

Preventive Measures and Future Outlook

Security analysts warn of a broader trend where legitimate platforms are weaponized for malicious purposes. As AI tools become integral to developer workflows, such exploitations are expected to rise.

Organizations are advised to educate their users about the risks of ClickFix-style attacks, monitor unusual command execution, and deploy robust endpoint detection solutions. Users should exercise caution when installing software from search ads, verify URLs, and avoid executing commands from untrusted sources.

Staying informed and vigilant is crucial as the landscape of cyber threats continues to evolve. Follow us on Google News, LinkedIn, and X for more instant updates on cybersecurity developments.

Cyber Security News Tags:AI security, Claude AI, Claude shared chat, ClickFix, Cybersecurity, MacSync infostealer, malicious ads, Malware, social engineering, TrendAI

Post navigation

Previous Post: Hackers Exploit AI Tools for Sophisticated Cyber Attacks
Next Post: Cisco ISE Flaws Enable Remote Code Execution Risk

Related Posts

Fortinet FortiSIEM Command Injection Vulnerability (CVE-2025-25256) Fortinet FortiSIEM Command Injection Vulnerability (CVE-2025-25256) Cyber Security News
LLM-enabled MalTerminal Malware Leverages GPT-4 to Generate Ransomware Code LLM-enabled MalTerminal Malware Leverages GPT-4 to Generate Ransomware Code Cyber Security News
Flowise Vulnerability Exposes Millions to Remote Code Risks Flowise Vulnerability Exposes Millions to Remote Code Risks Cyber Security News
Revolut Denies Data Breach Amidst Hacker Claims Revolut Denies Data Breach Amidst Hacker Claims Cyber Security News
Discord Implements Default E2EE for Voice and Video Discord Implements Default E2EE for Voice and Video Cyber Security News
Top 10 Best Practices for Securing Your Database Top 10 Best Practices for Securing Your Database Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • New York Allocates $9 Million for Water System Cybersecurity
  • Android RAT Threat Poses as Emergency App
  • Critical VeloCloud Vulnerability Actively Exploited
  • Critical Rails Vulnerability Threatens Cloud Security
  • Malicious npm Packages Target Alibaba Users with RAT

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • New York Allocates $9 Million for Water System Cybersecurity
  • Android RAT Threat Poses as Emergency App
  • Critical VeloCloud Vulnerability Actively Exploited
  • Critical Rails Vulnerability Threatens Cloud Security
  • Malicious npm Packages Target Alibaba Users with RAT

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark