Homebrew_headpic

Fake Homebrew Google ads target Mac users with malware

Share:

Hackers are once again abusing Google ads to spread malware, using a fake Homebrew website to infect Macs and Linux devices with an infostealer that steals credentials, browser data, and cryptocurrency wallets.

The malicious Google ads campaign was spotted by Ryan Chenkie, who warned on X about the risk of malware infection.

The malware used in this campaign is AmosStealer (aka ‘Atomic’), an infostealer designed for macOS systems and sold to cyber criminals as a subscription of $1,000/month.

The malware was seen recently in other malvertising campaigns promoting fake Google Meet conferencing pages and is currently the go-to stealer for cybercriminals targeting Apple users.

Targeting Homebrew users

Homebrew is a popular open-source package manager for macOS and Linux, allowing users to install, update, and manage software from the command line.

A malicious Google advertisement displayed the correct Homebrew URL, “brew.sh,” tricking even familiar users into clicking it. However, the ad redirected them to a fake Homebrew site hosted at “brewe.sh” instead.

Malvertisers have extensively used this URL technique to trick users into clicking on what seems to be the legitimate website for a project or organization.

Malicious Google Search result
Malicious Google Search result
Source: @ryanchenkie

Upon reaching the site, the visitor is prompted to install Homebrew by pasting a command shown in the macOS Terminal or a Linux shell prompt. The legitimate Homebrew site provides a similar command to execute to install the legitimate software.

However, when running the command shown by the fake website, it will download and execute malware on the device.

fake homebrew site
Fake Homebrew site
Source: @ryanchenkie

Security researcher JAMESWT found that the malware dropped in this case [VirusTotal] is Amos, a powerful infostealer that targets over 50 cryptocurrency extensions, desktop wallets, and data stored on web browsers.

Homebrew’s project leader, Mike McQuaid, stated that the project is aware of the situation but highlighted that it’s beyond its control, criticizing Google for its lack of scrutiny.

“Mac Homebrew Project Leader here. This seems taken down now,” tweeted McQuaid.

“There’s little we can do about this really, it keeps happening again and again and Google seems to like taking money from scammers. Please signal-boost this and hopefully someone at Google will fix this for good.”

At the time of writing, the malicious ad has been taken down, but the campaign could continue via other redirection domains, so Homebrew users need to be wary of sponsored ads for the project.

Unfortunately, malicious ads continue to be a problem in Google Search results for various search terms, even for Google Ads itself.

In that campaign, the threat actors targeted Google advertisers to steal their accounts and run malicious campaigns under the guise of legitimate and verified entities.

To minimize the risk of malware infection, whenever clicking on a link in Google, ensure that you are brought to the legitimate site for a project or company before entering sensitive information or downloading software.

Another safe method is to bookmark official project websites you need to visit often for sourcing software and use those instead of searching online every time.

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
5:23 am, Mar 17, 2025
weather icon 5°C
L: 4° | H: 6°
overcast clouds
Humidity: 80 %
Pressure: 1028 mb
Wind: 7 mph NNE
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 6:09 am
Sunset: 6:07 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
4° | 6°°C 0 mm 0% 10 mph 80 % 1028 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
3° | 9°°C 0 mm 0% 12 mph 69 % 1027 mb 0 mm/h
Wed Mar 19 9:00 pm
weather icon
3° | 15°°C 0 mm 0% 6 mph 82 % 1022 mb 0 mm/h
Thu Mar 20 9:00 pm
weather icon
8° | 16°°C 0 mm 0% 8 mph 74 % 1021 mb 0 mm/h
Fri Mar 21 9:00 pm
weather icon
9° | 13°°C 0.2 mm 20% 6 mph 93 % 1015 mb 0 mm/h
Today 6:00 am
weather icon
3° | 5°°C 0 mm 0% 7 mph 80 % 1028 mb 0 mm/h
Today 9:00 am
weather icon
5° | 6°°C 0 mm 0% 10 mph 74 % 1028 mb 0 mm/h
Today 12:00 pm
weather icon
7° | 8°°C 0 mm 0% 10 mph 63 % 1028 mb 0 mm/h
Today 3:00 pm
weather icon
8° | 8°°C 0 mm 0% 10 mph 56 % 1027 mb 0 mm/h
Today 6:00 pm
weather icon
6° | 6°°C 0 mm 0% 10 mph 73 % 1028 mb 0 mm/h
Today 9:00 pm
weather icon
5° | 5°°C 0 mm 0% 9 mph 76 % 1028 mb 0 mm/h
Tomorrow 12:00 am
weather icon
5° | 5°°C 0 mm 0% 9 mph 67 % 1027 mb 0 mm/h
Tomorrow 3:00 am
weather icon
4° | 4°°C 0 mm 0% 7 mph 69 % 1026 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€76,477.49
-1.34%
Ethereum(ETH)
€1,743.75
-1.59%
Tether(USDT)
€0.92
-0.01%
XRP(XRP)
€2.15
-1.93%
Solana(SOL)
€117.86
-4.98%
USDC(USDC)
€0.92
-0.01%
Dogecoin(DOGE)
€0.157800
-2.11%
Shiba Inu(SHIB)
€0.000012
2.88%
Pepe(PEPE)
€0.000006
-4.60%
Peanut the Squirrel(PNUT)
€0.189641
20.47%
Scroll to Top