Huntress says hackers are using fake Google Docs and spoofed Claude pages to target crypto users

Huntress says hackers are using fake Google Docs and spoofed Claude pages to target crypto users

N
News Editor
2026-09-01 09:56:45
Security firm Huntress said attackers are distributing info-stealing malware to cryptocurrency users through fake Google Docs files, malicious files hosted on GitHub, and spoofed Claude.ai pages. According to the company, the operators impersonated senior CoinDesk staff on X and used invitations to online meetings to trick targets into opening Google Docs documents containing malicious code, then guided them to install malware themselves. Huntress said Mac users face Atomic macOS Stealer, or AMOS, which can steal browser passwords, crypto wallet data, and Telegram files. Windows users are being served a fake Google API Connector update that installs NetSupport RAT and a counterfeit Ledger hardware wallet application. The firm also said attackers bought fake ads on search engines including Bing to steer users to imitation Claude.ai pages where they were prompted to run malicious commands. In that part of the campaign, malware families MacSync and SectopRAT were used to steal cookies, saved passwords, seed phrases, and payment card data. Separately, security company Socket said it found 16 malicious extensions targeting Chrome and Edge that can drain wallets on EVM, Solana, and Tron.

ChainCatcher reported that security firm Huntress has disclosed a campaign targeting cryptocurrency users with info-stealing malware delivered through fake Google Docs files, malicious files hosted on GitHub, and spoofed Claude.ai pages.

According to Huntress, the attackers posed as senior CoinDesk employees on X. They invited targets to online meetings, then pushed them to open Google Docs documents containing malicious code and guided them into installing the malware themselves.

On macOS, victims face Atomic macOS Stealer, or AMOS, which can steal browser passwords, crypto wallet data, and Telegram files. On Windows, users are served a fake Google API Connector update that installs NetSupport RAT along with a counterfeit Ledger hardware wallet app.

Huntress also said the attackers placed fake ads on search engines including Bing, directing users to imitation Claude.ai pages and prompting them to execute malicious commands. Malware tied to that flow, MacSync and SectopRAT, can steal cookies, saved passwords, seed phrases, and payment card information.

Separately, security company Socket said it had identified 16 malicious extensions for Chrome and Edge that can drain wallets on EVM, Solana, and Tron.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
500

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.