The runaway popularity of AI chat tools has handed cybercriminals a fresh disguise, and security researchers say Mac users are now the target. Zscaler, the American cloud security giant, has flagged a malware campaign in which attackers dress up malicious software as the Claude chat app to slip past the caution of everyday users on Apple computers, according to reporting by SecurityBrief Australia.
The lure: a trusted name turned into bait
The tactic itself is old, but the packaging is new. For years, criminals have wrapped information-stealing malware inside fake installers for well-known software, betting that a familiar logo and a plausible download page will lower a victim’s guard. What has changed is the shop window. As tools built by Anthropic and its rivals have surged into mainstream use, the brands attached to them have become some of the most searched and most trusted names in software. That makes them ideal cover for a payload that a user would never knowingly run.
Zscaler’s threat research arm, ThreatLabz, has spent the past couple of years tracking a sharp rise in malware built specifically for macOS, a platform many users still assume is largely immune to this sort of thing. The family of threats known broadly as macOS stealers is designed to quietly harvest passwords saved in browsers, session cookies, cryptocurrency wallet data and other credentials, then ship them off to an attacker-controlled server. Dressing that payload up as an AI chat client is simply the latest twist on a distribution problem the criminals have already solved.
Why Macs, and why now
The comfortable belief that Apple hardware does not get malware has always been more marketing than fact, and it is wearing thinner by the year. As Mac market share has grown, particularly among developers, executives and creative professionals who tend to hold valuable credentials, the incentive to build Mac-specific malware has grown with it. Security researchers have repeatedly noted that the people most likely to download an early AI tool, the tinkerers and the enthusiasts, are also the people most likely to have crypto wallets, cloud logins and corporate access sitting on the same machine.
There is a second, more uncomfortable point of view worth airing here. A campaign like this does not reflect any weakness in the AI product being impersonated. Anthropic’s software is not the vector; the criminals are trading purely on the reputation of the name. That distinction matters, because the natural instinct after a scare like this is to distrust the tool rather than the download source. The safer lesson is the reverse. The application is fine when it comes from the official channel, and dangerous when it arrives via a search advertisement, a lookalike website or a link in a forum post.
How the con typically works
Campaigns of this shape tend to follow a well-worn script. Attackers stand up a website that mimics an official product page, then buy their way to the top of search results or seed links across social platforms and messaging apps so their fake sits above the genuine article. A user searching for the app clicks through, downloads what looks like a normal installer, and is then walked through steps that quietly hand over the permissions the malware needs. On macOS, that often means coaxing the victim into bypassing Apple’s Gatekeeper protections or typing in their system password under the guise of a routine setup step.
Once installed, a stealer does its work in seconds and often deletes traces of itself, which is part of why these infections are so easy to miss. Victims frequently have no idea anything is wrong until money moves out of a wallet or an account is hijacked days later.
What it means for Australia
Australia is not a bystander in this. AI adoption here has been among the fastest in the developed world, and the enthusiasm cuts across startups, agencies, universities and the public service. That eagerness is a genuine competitive advantage, but it also widens the pool of people typing an AI product’s name into a search bar and clicking the first plausible result, which is exactly the behaviour these campaigns are built to exploit.
The local threat picture has been sharpening for a while. The Australian Signals Directorate and its Australian Cyber Security Centre have repeatedly warned that credential theft and identity compromise sit behind a large share of the incidents they respond to, and that small businesses in particular struggle to spot a convincing fake before damage is done. Layer AI-branded bait on top of that, and you have a phishing lure with unusually broad appeal. For Australian IT and security teams, a Mac in the hands of a designer or a founder is no longer a device that can be quietly trusted to look after itself.
The practical defences are unglamorous but effective. Download AI tools only from the developer’s official website or an official app store, treat search advertisements for popular software with suspicion, and be wary of any installer that asks you to disable a security protection or hand over your system password. For organisations, endpoint protection that actually covers macOS, hardware-backed multi-factor authentication and quick revocation of stolen sessions are the difference between a near miss and a breach. None of it is exotic, but it is the sort of hygiene that a fake Claude installer is specifically designed to slip past.
What’s next
Expect more of the same rather than less. As long as new AI products keep arriving with household-name recognition and a rush of first-time downloaders, their branding will remain valuable cover for whoever is distributing the current crop of stealers. The AI vendors will keep leaning on official app stores and verified download channels to give users a safe default, and researchers such as Zscaler’s ThreatLabz will keep publishing indicators so defenders can block the fakes. The harder problem is the human one. The whole trick depends on a moment of trust in a name, and that is precisely the reflex the industry now has to retrain across a workforce that has learned to reach for AI tools without a second thought.
Sources: SecurityBrief Australia.


















































