Cybercriminals are running a new campaign that uses Fake Homebrew sites and other impersonated pages to spread malware through Google Ads. The attackers trick users into downloading info-stealer malware disguised as trusted software tools like Homebrew, LogMeIn, and TradingView.

The operation specifically targets macOS users, including developers who rely on these platforms for daily work. By mimicking legitimate domains, the campaign lures victims into executing terminal commands that install malware directly onto their systems.


How the Attack Works

Hackers purchase Google Ads that appear above legitimate search results. When users click these ads, they are redirected to fake websites nearly identical to the real ones. For example, a cloned domain may change only one letter in “brew.sh” to deceive users.

Once on the site, visitors are prompted to copy and paste a command into their macOS terminal. The command downloads the malware payload using tools like “curl” and executes it with elevated permissions. This grants the attackers access to sensitive data, including saved passwords, browser cookies, and cryptocurrency wallets.

Researchers have identified more than 80 domains used in the campaign. The payloads often include well-known info-stealers such as AMOS and Odyssey Stealer, capable of exfiltrating data from multiple browsers and applications.


Impact and Risks

The Fake Homebrew sites campaign highlights how trusted advertising platforms can be weaponized through malvertising. Even experienced users may mistake the fake pages for legitimate download sources. The attackers exploit that trust to infect systems at scale.

Google has reportedly taken down several malicious ads, but the campaign continues to evolve. The incident raises concerns about how effectively ad networks detect and block malicious advertisers before they reach users.


How to Stay Protected

Users can reduce risk by avoiding downloads from advertisements and navigating directly to official project domains. Verifying URLs and avoiding unfamiliar installer commands can prevent infection. Cybersecurity experts recommend enabling macOS Gatekeeper, keeping software updated, and monitoring for unusual network activity.


Conclusion

The campaign using Fake Homebrew sites underscores the growing threat of malvertising. It shows that even skilled users can fall victim to sophisticated deception. As attackers refine their methods, staying cautious and verifying every download source remains essential for keeping systems safe.


0 responses to “Fake Homebrew Sites Target Mac Users”