June 27th, 2024

Mac users served info-stealer malware through Google ads

Mac users targeted by info-stealer malware via Google ads promoting fake Arc browser for Mac. Malware sends data to Poseidon info stealer control panel, extracting wallets and passwords. Google disclaims responsibility. Users urged caution.

Read original articleLink Icon
Mac users served info-stealer malware through Google ads

Mac users have been targeted by an info-stealer malware distributed through Google ads, marking the second instance in recent months of the ad platform being exploited for malicious purposes. Security firm Malwarebytes discovered ads promoting a Mac version of the Arc browser, leading users to a fake website resembling the real one. The malware, once installed, sends data to a control panel associated with the Poseidon info stealer. This malware boasts features like extracting cryptocurrency wallets and stealing passwords from various sources. The malicious ads were traced back to an advertiser verified by Google, highlighting the challenges in ad network security. Google Ads, like other networks, removes malicious content upon notification but disclaims responsibility for resulting damages. Users are advised to download software from official sources and be cautious of installation instructions that deviate from standard practices. Malwarebytes provides indicators of compromise for potential targets to identify if they have been affected by this malware campaign.

Link Icon 4 comments
By @shiroiushi - 4 months
Interestingly, there's a bunch of HNers who chide us and tell us we all have a moral responsibility to allow malware to be installed on our systems, because using an ad-blocker is "stealing".
By @robnado - 4 months
I've had phishing served to me through google ads a few times, so this hardly surprises.
By @tjpnz - 4 months
Never forget that Google is all but complicit in this.
By @freedomben - 4 months
Why is Apple allowing Google to serve ads to Apple's customers?