A new attack has been spotted in the wild, and it’s a masterclass in social engineering. There’s no zero-day exploit here, and no sketchy .dmg or .exe from a misspelled domain. It relies entirely on trust in a Google Ad and a genuinely legitimate ChatGPT URL. A Google Ad leading to the real chatgpt.com domain, for the search term “codex mac download.”

Here’s how the infection chain works, and why it’s worth rethinking how you navigate to sensitive sites entirely. It’s also another entry in a pattern we’ve covered before: attackers weaponizing living-off-the-land techniques by hiding behind platforms users already trust, whether that’s Google Sites, Google Workspace, or in this case, ChatGPT itself.
The Anatomy of the Attack
The chain bypasses traditional red flags by hiding behind domains you already trust, in five simple steps.
- The Google Ad. An innocuous Google search for “codex macbook download” shows a sponsored result at the very top of page one.
- The trusted domain. Click the ad, and instead of landing on a typosquatted lookalike, you land on a genuine, legitimate chatgpt.com link.
- The shared chat. That link opens a carefully crafted “Shared Chat” built by the attackers. It provides friendly, helpful-looking instructions: open your Terminal and paste this installation command.
- The hidden payload. The command hides a base64-encoded string. Once executed, it decodes and triggers a silent curl download from a malicious domain.
- The devastation. That domain is a known ClickFix distributor dropping the MacSync stealer. Within seconds, passwords, Apple Keychain data, and crypto wallets are gone.

Alphabet, Google’s parent company, owns both Mandiant and VirusTotal. Both platforms already know about this ClickFix campaign and flag the domains involved as malicious. The Google Ads team apparently missed that memo, which raises an obvious question about how closely the ad-approval pipeline talks to the company’s own threat intelligence arm.
Key Takeaways to Protect Yourself
This particular chain targets Mac users, but equivalent infostealers work just as well against Windows. Share this with anyone in your circle, regardless of what they’re running.
Never use search to reach crypto or banking sites. Since ad networks will serve dubious results for a fee, searching for your exchange or wallet provider each time is a gamble. Find the legitimate URL once, bookmark it, and use only that bookmark going forward.
Never paste a terminal command you don’t fully understand. Not from an ad, a forum post, a shared chat, or a “fix” pop-up. If you can’t explain what every flag and string in that command does, don’t hit enter.
Don’t trust a platform blindly just because of its domain. A link starting with chatgpt.com, docs.google.com, or github.com tells you the platform is legitimate. It says nothing about whether the specific content hosted there is safe. Attackers increasingly use trusted platforms to host the trap itself.
Watch for base64. A command containing a long string of seemingly random, mixed-case letters and numbers is almost always hiding its real intent from you and your antivirus.
If a major ad platform won’t filter obvious malware out of its own paid search results, the last line of defense left is your own skepticism before you hit enter.
Worried about attackers abusing trusted platforms to target your users or your brand?
See how PhishFort detects living-off-the-land phishing campaigns before they reach your customers →



