logo

Fake “Mac Cleaner” Campaign Uses Google Ads to Redirect Users to Malware

ID: 1484638b-e0b4-5a18-980f-a212ca1d19f2

STIX ID: report--1484638b-e0b4-5a18-980f-a212ca1d19f2

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-01-29

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Security researchers uncovered a campaign where threat actors exploit legitimate Google Search Ads (via compromised ad accounts) to send macOS users searching for disk-cleaning tools to Apple-branded Google Apps Script pages that host obfuscated remote code execution payloads; the malware uses Base64 and shell obfuscation to silently download and run remote scripts, enabling backdoors, data theft, and cryptomining.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.