Malicious people have spread their tentacles in all fields, and even Google, which has the basic trust of Internet users, cannot escape its clutches. Recently, hackers have once again abused Google Ads to spread malware, using fake Homebrew websites to infect Mac and Linux systems and steal user credentials, browser data, cryptocurrency wallets, etc.

Google Ads now has fake ads, malware targets Mac users
According to foreign media Bleeping Computer According to reports, X user Ryan Chinkie posted a tweet in which he described his discovery of a malicious Google Ads campaign and warned everyone that the advertising campaign was at risk of malware infection.
⚠️ Developers, please be careful when installing Homebrew.
Google is serving sponsored links to a Homebrew site clone that has a cURL command to malware. The URL for this site is one letter different than the official site. pic.twitter.com/TTpWRfqGWo
— Ryan Chenkie (@ryanchenkie) January 18, 2025
The malware distributed by this malvertising disguised as a Homebrew website is AmosStealer (also known as Atomic), an information-stealing program designed for macOS systems and sold to cybercriminals on the underground market for a monthly subscription price of $1,000. The malware has recently surfaced in other malvertising campaigns promoting fake Google Meet pages, with Apple users a prime target for cybercriminals.
Malicious Google Ads display the correct Homebrew URL “brew.sh” and even trick familiar users into clicking on it. However, the ad redirects users to a fake Homebrew website hosted at “brewe.sh”. This technique is commonly used by malicious advertisers to disguise themselves as legitimate-looking projects or organizations.

Upon arriving at the fake website, visitors are prompted to install Homebrew by pasting the content displayed in a macOS terminal or Linux shell command. The legitimate Homebrew website provides similar instructions to execute to install legitimate software, however, when the instructions displayed by the fake website are run, it downloads and executes malware on the device.

The malicious ad has been removed, but malicious activity may continue through other redirect domains, so users must be wary of project-based search ads about Homebrew. In addition, in addition to Google Ads itself, special attention should be paid to the search results section.
Source: KOCPC Chinese