logo

Google ads for fake Homebrew, LogMeIn sites push infostealers

ID: 3c682936-ff62-57da-82a1-0fe3fb8687bc

STIX ID: report--3c682936-ff62-57da-82a1-0fe3fb8687bc

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2025-10-18

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

A malvertising campaign impersonating Homebrew, LogMeIn, and TradingView lures macOS users into copying Terminal commands (ClickFix) that download and run install scripts which deploy AMOS or Odyssey infostealers; researchers uncovered 85+ spoof domains, Google Ads-driven traffic, Gatekeeper/quarantine bypass techniques, and data-exfiltration of browser credentials, crypto wallets, and Keychain items.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.