Fake “Mac Cleaner” Campaign Uses Google Ads to Redirect Users to Malware
ID: 1484638b-e0b4-5a18-980f-a212ca1d19f2
STIX ID: report--1484638b-e0b4-5a18-980f-a212ca1d19f2
Feed Name: GBHackers
Threat Score
Security researchers uncovered a campaign where threat actors exploit legitimate Google Search Ads (via compromised ad accounts) to send macOS users searching for disk-cleaning tools to Apple-branded Google Apps Script pages that host obfuscated remote code execution payloads; the malware uses Base64 and shell obfuscation to silently download and run remote scripts, enabling backdoors, data theft, and cryptomining.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
