Medium A.I CyberSecurity Scoring
Medium
Company Information
Website:https://job-boards.greenhouse.io/medium
Employees number:9,820
Number of followers:210,919
NAICS:51913
Industry Type:Internet Publishing
Homepage:greenhouse.io
Medium Risk Score (AI oriented)
Between 700 and 749
MediumInternet Publishing
Updated:
08/05/2026
08/05/2026
745/1000
Moderate
Ba
Medium Global Score (TPRM)
xxxx
MediumInternet Publishing
Score locked

MediumModerate
Current Score
745Ba (MODERATE)
01000
2 incidents
-19 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
747
JUNE 2026
747
MAY 2026
745
APRIL 2026
745
MARCH 2026
744
FEBRUARY 2026
763
Cyber Attack
14 Feb 2026 • Medium
Anthropic, Google, Medium and Apple: Malicious Campaign Uses Claude Artifacts and Google Ads to Deliver macOS Malware
Sophisticated macOS Malware Campaign Exploits Google Ads, Claude AI, and Medium to Distribute MacSync Stealer
742
CRITICAL-21
ANTGOOAPPMED1771064819
Sophisticated macOS Malware Campaign Exploits Google Ads, Claude AI, and Medium to Distribute MacSync Stealer
A recent malware campaign is targeting macOS users through a multi-pronged attack leveraging sponsored Google search results, Claude AI’s public artifact feature, and fraudulent Medium articles. The operation, uncovered by cybersecurity researchers at Moonlock Lab, has exposed over 15,000 users to the MacSync information stealer, which siphons sensitive data including keychain credentials, browser data, and cryptocurrency wallets.
The campaign employs two distinct variants, both using the ClickFix social engineering technique to deceive users into executing malicious commands.
### First Variant: Fake DNS Resolver via Claude AI
When users search for "Online DNS resolver" on Google, a sponsored result directs them to a public Claude AI artifact titled "macOS Secure Command Execution." The fake guide masquerades as a legitimate security tool, instructing victims to paste a base64-encoded command into their Terminal. Upon execution, the command downloads a loader for MacSync from `/tmp/osalogging.zip`, which then establishes communication with a command-and-control (C2) server at `a2abotnet[.]com/dynamic`.
The malware uses a hardcoded authentication token and API key, spoofs a macOS browser User-Agent string to evade detection, and exfiltrates stolen data via Apple’s `osascript` utility. Larger datasets are uploaded in chunks with retry mechanisms and exponential backoff to ensure successful transmission. After exfiltration, the malware deletes staging files to cover its tracks.
### Second Variant: Fake Disk Space Analyzer via Medium
A second attack vector targets users searching for "macOS CLI disk space analyzer" through a fraudulent Medium article hosted at `apple-mac-disk-space.medium[.]com`. The article impersonates Apple’s official Support Team and delivers a similar ClickFix payload with additional obfuscation, including string concatenation tricks (e.g., `cur””l`) to bypass detection. The malicious payload is fetched from `raxelpak[.]com`.
### Evasion Tactics and Broader Implications
The threat actors behind this campaign demonstrate a deep understanding of social engineering and evasion techniques, exploiting trusted platforms like Google Ads, Claude AI, and Medium to lend legitimacy to their attacks. By abusing these services, they bypass traditional security controls and reach a broader audience.
The MacSync stealer remains a persistent threat, with its operators continuously refining their methods to avoid detection while maximizing data theft. The campaign underscores the growing trend of malware distributors leveraging legitimate services to propagate malicious payloads.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
763
DECEMBER 2025
762
NOVEMBER 2025
778
Cyber Attack
01 Nov 2025 • Medium
Squarespace, Medium, Apple and Craft: Fake macOS Troubleshooting Sites Used to Steal iCloud Data in ClickFix Scam
New ClickFix Social Engineering Campaign Targets macOS Users with Fake Troubleshooting Guides
761
HIGH-17
SQUNODMEDAPP1778279131
New ClickFix Social Engineering Campaign Targets macOS Users with Fake Troubleshooting Guides
Microsoft’s Defender Security Research Team has uncovered a sophisticated cyberattack campaign leveraging a social engineering tactic called ClickFix to compromise Apple computers. Active since late 2025 and continuing into early 2026, the campaign tricks users into executing malicious commands under the guise of legitimate troubleshooting solutions.
Attackers distribute fake guides on platforms like Medium, Craft, and Squarespace, offering fixes for common issues such as disk space errors or system malfunctions. Instead of providing downloads, these sites instruct users to copy and paste commands into macOS Terminal, claiming they are system utilities or quick repairs. The guides are often multilingual and appear on websites that have since been taken down or reported.
Once executed, the commands bypass macOS security features like Gatekeeper, which typically only scans app bundles and disk images not direct Terminal inputs. The malware including AMOS (Atomic macOS Stealer), Macsync, and SHub Stealer then prompts users to enter their system password under the pretense of installing a "helper tool." If granted, attackers gain full access to sensitive files, settings, and credentials.
The malware targets a range of high-value data, including:
- iCloud and Telegram account credentials
- Private documents, notes, and photos under 2 MB
- Cryptocurrency wallet keys (Exodus, Ledger, Trezor)
- Saved browser passwords (Chrome, Firefox)
- Authentic crypto apps, which attackers replace with trojanized versions to monitor transactions and steal funds
The campaign employs fileless attack techniques, using tools like curl and osascript to run malware directly in memory, evading traditional antivirus detection. Microsoft also identified a kill switch in the malware that halts execution if a Russian keyboard layout is detected.
In response, Apple has introduced a security feature in macOS 26.4, which now displays a "Possible malware, Paste blocked" warning when users attempt to paste suspicious commands into Terminal. The update aims to mitigate the risk of unintentional execution of malicious scripts.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
OCTOBER 2025
778
SEPTEMBER 2025
778
AUGUST 2025
778
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Medium ??
What was Medium's A.I Rankiteo Cyber Score in June 2026 ??
What was Medium's A.I Rankiteo Cyber Score in May 2026 ??
What was Medium's A.I Rankiteo Cyber Score in April 2026 ??
What was Medium's A.I Rankiteo Cyber Score in March 2026 ??
What was Medium's A.I Rankiteo Cyber Score in February 2026 ??
What was Medium's A.I Rankiteo Cyber Score in January 2026 ??
What was Medium's A.I Rankiteo Cyber Score in December 2025 ??
What was Medium's A.I Rankiteo Cyber Score in November 2025 ??
What was Medium's A.I Rankiteo Cyber Score in October 2025 ??
What was Medium's A.I Rankiteo Cyber Score in September 2025 ??
What was Medium's A.I Rankiteo Cyber Score in August 2025 ??
What is the average per-incident point impact on Medium's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Medium ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Medium's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?