Fake Homebrew Google ads target Mac users with malware
ID: 930ad8ea-cbde-5517-a2fe-38816d38e68e
STIX ID: report--930ad8ea-cbde-5517-a2fe-38816d38e68e
Feed Name: Bleeping Computer
Malicious Google search ads impersonated the Homebrew site and redirected users to a fake installer hosted at brewe.sh; running the provided install command downloads AmosStealer (Atomic), an infostealer for macOS/Linux that steals credentials, browser data, desktop and extension cryptocurrency wallets. Security researchers linked a sample on VirusTotal and the ad was removed, but actors may reuse other redirect domains, so users should verify site URLs or bookmark official project pages before installing software.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
