logo

Malicious Google Ads Target Mac Users with Fake Mac Cleaner Pages

ID: fa5bc2dd-03ff-53a1-aebd-9ba637aa810f

STIX ID: report--fa5bc2dd-03ff-53a1-aebd-9ba637aa810f

Feed Name: HackRead

Threat Score
70/100

Date Published: 2026-01-29

Date Updated: 2026-04-22

Author: Waqas

...
...

On 26 January 2026, MacKeeper researchers discovered malicious Google Ads for fake “Mac cleaner” tools that redirect victims to convincing Apple-style pages hosted on Google services (docs.google.com, business.google.com) and coerce users into executing Base64-obfuscated Terminal commands; those commands download and run a remote script that grants attackers full control of affected macOS systems, enabling file/SSH key theft, additional malware deployment, and abuse of system resources. The ads were served from Google-verified accounts that appear compromised, and MacKeeper has reported the activity to Google.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.