Hackers Are Using Google Docs and Claude.ai to Spread Crypto Malware

Hackers Are Using Google Docs and Claude.ai to Spread Crypto Malware

Last Updated:
Hackers Are Using Google Docs and Claude.ai to Spread Crypto Malware
Google News

Get our latest news first. Add us as your Preferred Source on Google and tap "Star" to prioritize our updates.

  • Hackers use Google Docs and Claude.ai to make malware attacks look legitimate.
  • Fake ads and documents trick users into installing malware or sharing sensitive data.
  • Crypto users face risks from stolen passwords, wallets, and recovery phrases.

Cybercriminals are using Google Docs and Claude.ai to make malware attacks look legitimate. They use social engineering, fake search ads, and impersonation to trick people into installing harmful software or sharing sensitive information.

Recent investigations show that attackers have moved beyond typical phishing websites and now use Google, Claude, X, and GitHub in their attacks.

The goal is to make victims feel safe enough to run malicious software to steal passwords, browser sessions, and crypto wallet information.

Google Docs Used to Deliver Malware

One malware campaign targeted a security researcher after Black Hat and DEF CON. The attacker pretended to be a senior CoinDesk executive and contacted conference attendees on X, saying they were organizing an online conference.

The attacker then sent a fake conference document on Google Docs that included a feature that asked the victim to enter an “encryption key.”

After the victim entered the key, the process appeared to fail. The victim was then given instructions to “fix” the problem. These steps secretly led to malware.

On Mac, victims were directed to run commands in Terminal or download a malicious file from GitHub. Huntress found similarities between the malware and Atomic macOS Stealer (AMOS), which steals browser passwords, crypto wallets, Keychain data, and Telegram files.

On Windows, victims were shown a fake Google API Connector update. This installed malicious tools like NetSupport RAT and a fake Ledger wallet app. The attackers later used a fake Dropbox DocSend file share in another attempt.

This shows they switch between trusted brands to make their attacks more convincing — to make malware look like normal documents, updates, or troubleshooting steps.

Attackers Used Claude.ai to Make Malware Look Legitimate

Attackers have been using Claude.ai and fake search ads to make malware look trustworthy.

In one attack, they targeted people looking for instructions on how to install Claude on a Mac. 

Victims were sent to a real Claude.ai page that looked like a normal conversation.  Instead of giving installation instructions, the page told users to copy and paste a command into Terminal, which installed malware.

Another attack used fake Bing ads to promote a fake Claude Desktop installer. Users were sent through a fake Claude page before downloading the infected installer.

The malware steals sensitive information and gives attackers remote access. One type, MacSync, could steal:

  • Browser cookies and saved passwords
  • Keychain data
  • Telegram sessions
  • Cloud and SSH keys
  • Crypto wallet recovery phrases

It also has the ability to change some crypto wallet apps to show fake errors asking users for their recovery phrases.

The second attack delivered SectopRAT, which steals browser passwords, cookies, payment-card details, files, messaging data, VPN credentials, and crypto wallet information.

The attackers also used advanced tricks to hide the malware. For example, they used legitimate software components to load malicious code, created fake update tasks that looked like Microsoft Edge updates, and added exclusions to Microsoft Defender. They also hid information used to control the malware inside blockchain transaction data.

These attacks show how criminals combine trusted brands, fake search results, social engineering, and legitimate software to make malware seem safe. 

Instead of using an obviously fake website, they create a believable series of steps that tricks users into installing malware.

Why Trusted Platforms Make These Attacks More Dangerous

The main reason these attacks work is trust.

People are more likely to trust a Google Doc from a familiar account, a Claude conversation on the real Claude.ai website, or a sponsored search result than a strange website or unknown download.

Attackers take advantage of this trust to make their malware look legitimate.

The Claude attacks target people who are already searching for software installation instructions. These users assume that a sponsored search result or a page on a familiar website is safe.

Crypto Users Should Be Careful With Installation Instructions

The biggest warning sign may not be the website itself. It is what the website asks you to do. Be careful if a document, search result, or support page tells you to:

  • Paste commands into Terminal or PowerShell.
  • Turn off security features such as Gatekeeper.
  • Install an unexpected “update.”
  • Give an app unusual permissions.
  • Download software from GitHub or another third-party site when the official website is available.
  • Enter your crypto wallet recovery phrase after seeing an error message.
  • Install a wallet app from an unfamiliar source.

For security teams, it is also important to look at how the malware works, not just its name. Unusual scheduled tasks, suspicious DLL loading, changes to Microsoft Defender, and programs running from unusual folders can all be warning signs.

For crypto users, the most important rule is to never enter your wallet recovery phrase because an app, website, document, or error message asks for it.

These attacks show that criminals do not need to create obviously fake websites anymore. They can hide malicious instructions inside trusted platforms, impersonate people victims know, and use legitimate services to make their attacks look real.

So instead of asking only, “Is this website legitimate?”, users should evaluate whether the action this website is asking me to take is safe.

Related: OkoBot Malware Steals Crypto Seed Phrases in 25+ Countries, Kaspersky Warns

Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.