Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Exploit AI Platforms for Sophisticated Attacks

Hackers Exploit AI Platforms for Sophisticated Attacks

Posted on June 18, 2026 By CWS

Cybersecurity experts have identified a growing trend where hackers are leveraging reputable AI platforms to conduct advanced social engineering attacks. Recent findings reveal that cybercriminals have been exploiting Claude.ai’s shared chat feature to host harmful ClickFix instructions.

Evolution of ClickFix Tactics

Research by TrendAI uncovers that attackers implemented 106 unique malicious hostnames across six campaign waves over seven weeks. By continuously changing their infrastructure and employing various AI-themed tactics, they aimed to enhance the success of their campaigns.

This operation signifies a shift in ClickFix strategies, moving away from conventional malicious hosting to using trusted platforms like Claude.ai. Initially, the campaign utilized GitLab Pages with over 90 malicious subdomains impersonating popular AI developer tools such as Claude AI and ChatGPT Codex.

Manipulating Trusted Platforms

Hackers used Google Ads to lure technically skilled individuals searching for these AI tools. By doing so, they increased the chances of interaction from users who might be inclined to execute the suggested commands.

Victims were deceived into manually running harmful commands under the guise of software installation or repair. This method bypasses traditional security measures, as users unknowingly execute the payload themselves.

Geographical Targeting and Response

The campaign saw a significant escalation in May 2026 when attackers exploited Claude.ai’s shared chat feature. Malicious ads redirected users to legitimate Claude.ai URLs, avoiding common security warnings and protections.

TrendMicro’s analysis revealed that the payload included the MacSync infostealer, targeting macOS systems and collecting sensitive data. The campaign mainly targeted the Asia-Pacific region, with Taiwan accounting for over 30% of traffic, followed by Japan and Singapore.

In response to these threats, Anthropic has banned malicious accounts and removed harmful shared chats from Claude.ai, implementing further measures to prevent future abuse.

Preventive Measures and Future Outlook

Security analysts warn of a broader trend where legitimate platforms are weaponized for malicious purposes. As AI tools become integral to developer workflows, such exploitations are expected to rise.

Organizations are advised to educate their users about the risks of ClickFix-style attacks, monitor unusual command execution, and deploy robust endpoint detection solutions. Users should exercise caution when installing software from search ads, verify URLs, and avoid executing commands from untrusted sources.

Staying informed and vigilant is crucial as the landscape of cyber threats continues to evolve. Follow us on Google News, LinkedIn, and X for more instant updates on cybersecurity developments.

Cyber Security News Tags:AI security, Claude AI, Claude shared chat, ClickFix, Cybersecurity, MacSync infostealer, malicious ads, Malware, social engineering, TrendAI

Post navigation

Previous Post: Hackers Exploit AI Tools for Sophisticated Cyber Attacks
Next Post: Cisco ISE Flaws Enable Remote Code Execution Risk

Related Posts

TaskHound Tool – Detects Windows Scheduled Tasks Running with Elevated Privileges and Stored Credentials TaskHound Tool – Detects Windows Scheduled Tasks Running with Elevated Privileges and Stored Credentials Cyber Security News
U.S. Treasury Warns of Crypto ATMs Fueling Criminal Activity U.S. Treasury Warns of Crypto ATMs Fueling Criminal Activity Cyber Security News
New GhostSocks Malware-as-a-Service Enables Threat Actors to Convert Compromised Devices into Proxies New GhostSocks Malware-as-a-Service Enables Threat Actors to Convert Compromised Devices into Proxies Cyber Security News
Microsoft Dismantles 300+ Websites Used to Distribute RaccoonO365 Phishing Service Microsoft Dismantles 300+ Websites Used to Distribute RaccoonO365 Phishing Service Cyber Security News
Threat Actors Compromise Xubuntu Website To Deliver Malicious Windows Executable Threat Actors Compromise Xubuntu Website To Deliver Malicious Windows Executable Cyber Security News
New EDRStartupHinder Tool blocks antivirus and EDR services at startup on Windows 11 25H2 Defender New EDRStartupHinder Tool blocks antivirus and EDR services at startup on Windows 11 25H2 Defender Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cisco ISE Flaws Enable Remote Code Execution Risk
  • Hackers Exploit AI Platforms for Sophisticated Attacks
  • Hackers Exploit AI Tools for Sophisticated Cyber Attacks
  • F5 Fixes Critical NGINX Vulnerabilities Allowing Code Execution
  • Microsoft Fondue.exe Exploited for Malware Deployment

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cisco ISE Flaws Enable Remote Code Execution Risk
  • Hackers Exploit AI Platforms for Sophisticated Attacks
  • Hackers Exploit AI Tools for Sophisticated Cyber Attacks
  • F5 Fixes Critical NGINX Vulnerabilities Allowing Code Execution
  • Microsoft Fondue.exe Exploited for Malware Deployment

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark