Security company Huntress: Hackers steal cryptocurrency wallet data by spoofing Google Docs and Claude.ai pages
According to security company Huntress, hackers are spreading theft malware to cryptocurrency users by forging Google Docs files, hosting malicious files on GitHub, and impersonating Claude.ai pages. Attackers disguise themselves as senior employees of CoinDesk on the social platform X, luring victims to open Google Docs documents containing malicious code under the pretext of inviting them to an online meeting, thereby guiding users to install the malicious program themselves.
Mac users face the threat of Atomic macOS Stealer (AMOS), which can steal browser passwords, cryptocurrency wallet data, and Telegram files; Windows users are pushed fake Google API Connector updates, which, once installed, implant NetSupport RAT and a counterfeit Ledger hardware wallet application. Additionally, hackers are placing false advertisements on search engines like Bing, enticing users to visit counterfeit Claude.ai pages and execute malicious commands. The related malware MacSync and SectopRAT can steal cookies, saved passwords, recovery phrases, and payment card information.
Security company Socket also discovered 16 malicious extensions targeting Chrome and Edge, capable of emptying EVM, Solana, and Tron wallet assets.






