Threat Actors Leverage Google Search Ads for ‘Mac Cleaner’ to Direct Users to Malicious Websites
ID: c396f8f6-2b4c-53d1-8bfe-392dc7ab062b
STIX ID: report--c396f8f6-2b4c-53d1-8bfe-392dc7ab062b
Feed Name: cybersecurityNews.com
Cybercriminals are running a malvertising campaign that places sponsored Google Search Ads for terms like “mac cleaner,” redirecting macOS users to Apple-lookalike pages that supply base64‑encoded Terminal commands; when copied and executed by victims, these commands decode, download and run malicious scripts granting attackers full system control to install malware, steal SSH keys and files, deploy backdoors or mine cryptocurrency. MacKeeper researchers traced the operation to hijacked Google Ads accounts and reported the ads to Google, which removed them from search results.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
