Homebrew_headpic

Fake Homebrew Google ads target Mac users with malware

Teilen:

Hackers are once again abusing Google ads to spread malware, using a fake Homebrew website to infect Macs and Linux devices with an infostealer that steals credentials, browser data, and cryptocurrency wallets.

The malicious Google ads campaign was spotted by Ryan Chenkie, who warned on X about the risk of malware infection.

The malware used in this campaign is AmosStealer (aka ‘Atomic’), an infostealer designed for macOS systems and sold to cyber criminals as a subscription of $1,000/month.

The malware was seen recently in other malvertising campaigns promoting fake Google Meet conferencing pages and is currently the go-to stealer for cybercriminals targeting Apple users.

Targeting Homebrew users

Homebrew is a popular open-source package manager for macOS and Linux, allowing users to install, update, and manage software from the command line.

A malicious Google advertisement displayed the correct Homebrew URL, “brew.sh,” tricking even familiar users into clicking it. However, the ad redirected them to a fake Homebrew site hosted at “brewe.sh” instead.

Malvertisers have extensively used this URL technique to trick users into clicking on what seems to be the legitimate website for a project or organization.

Malicious Google Search result
Malicious Google Search result
Source: @ryanchenkie

Upon reaching the site, the visitor is prompted to install Homebrew by pasting a command shown in the macOS Terminal or a Linux shell prompt. The legitimate Homebrew site provides a similar command to execute to install the legitimate software.

However, when running the command shown by the fake website, it will download and execute malware on the device.

fake homebrew site
Fake Homebrew site
Source: @ryanchenkie

Security researcher JAMESWT found that the malware dropped in this case [VirusTotal] is Amos, a powerful infostealer that targets over 50 cryptocurrency extensions, desktop wallets, and data stored on web browsers.

Homebrew’s project leader, Mike McQuaid, stated that the project is aware of the situation but highlighted that it’s beyond its control, criticizing Google for its lack of scrutiny.

“Mac Homebrew Project Leader here. This seems taken down now,” tweeted McQuaid.

“There’s little we can do about this really, it keeps happening again and again and Google seems to like taking money from scammers. Please signal-boost this and hopefully someone at Google will fix this for good.”

At the time of writing, the malicious ad has been taken down, but the campaign could continue via other redirection domains, so Homebrew users need to be wary of sponsored ads for the project.

Unfortunately, malicious ads continue to be a problem in Google Search results for various search terms, even for Google Ads itself.

In that campaign, the threat actors targeted Google advertisers to steal their accounts and run malicious campaigns under the guise of legitimate and verified entities.

To minimize the risk of malware infection, whenever clicking on a link in Google, ensure that you are brought to the legitimate site for a project or company before entering sensitive information or downloading software.

Another safe method is to bookmark official project websites you need to visit often for sourcing software and use those instead of searching online every time.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
5:55 am, März 17, 2025
Wetter-Symbol 5°C
L: 5° | H: 6°
overcast clouds
Luftfeuchtigkeit: 80 %
Druck: 1028 mb
Wind: 9 mph NE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 6:09 am
Sonnenuntergang: 6:07 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
5° | 6°°C 0 mm 0% 10 mph 80 % 1028 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
3° | 9°°C 0 mm 0% 12 mph 69 % 1027 mb 0 mm/h
Mi. März 19 9:00 pm
Wetter-Symbol
3° | 15°°C 0 mm 0% 6 mph 82 % 1022 mb 0 mm/h
Do. März 20 9:00 pm
Wetter-Symbol
8° | 16°°C 0 mm 0% 8 mph 74 % 1021 mb 0 mm/h
Fr. März 21 9:00 pm
Wetter-Symbol
9° | 13°°C 0.2 mm 20% 6 mph 93 % 1015 mb 0 mm/h
Today 6:00 am
Wetter-Symbol
3° | 5°°C 0 mm 0% 7 mph 80 % 1028 mb 0 mm/h
Today 9:00 am
Wetter-Symbol
5° | 6°°C 0 mm 0% 10 mph 74 % 1028 mb 0 mm/h
Today 12:00 pm
Wetter-Symbol
7° | 8°°C 0 mm 0% 10 mph 63 % 1028 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
8° | 8°°C 0 mm 0% 10 mph 56 % 1027 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
6° | 6°°C 0 mm 0% 10 mph 73 % 1028 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
5° | 5°°C 0 mm 0% 9 mph 76 % 1028 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
5° | 5°°C 0 mm 0% 9 mph 67 % 1027 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
4° | 4°°C 0 mm 0% 7 mph 69 % 1026 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€76,505.98
-1.30%
Ethereum(ETH)
€1,745.73
-1.58%
Fesseln(USDT)
€0.92
-0.01%
XRP(XRP)
€2.15
-1.94%
Solana(SOL)
€118.02
-4.89%
USDC(USDC)
€0.92
-0.01%
Dogecoin(DOGE)
€0.158441
-2.01%
Shiba Inu(SHIB)
€0.000012
2.31%
Pepe(PEPE)
€0.000006
-4.36%
Peanut das Eichhörnchen(PNUT)
€0.189641
20.47%
Nach oben scrollen