Google ads for fake Homebrew, LogMeIn sites push infostealers
ID: 3c682936-ff62-57da-82a1-0fe3fb8687bc
STIX ID: report--3c682936-ff62-57da-82a1-0fe3fb8687bc
Feed Name: Bleeping Computer
Threat Score
A malvertising campaign impersonating Homebrew, LogMeIn, and TradingView lures macOS users into copying Terminal commands (ClickFix) that download and run install scripts which deploy AMOS or Odyssey infostealers; researchers uncovered 85+ spoof domains, Google Ads-driven traffic, Gatekeeper/quarantine bypass techniques, and data-exfiltration of browser credentials, crypto wallets, and Keychain items.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
