Cybernews reports that threat actors have launched the information-stealing MacSync malware in a new malvertising campaign that weaponized at least 35 breached Google Ads accounts promoting law firms, hotels, and other legitimate businesses around the world to push over 200 illicit ads spoofing widely used macOS software, including 7-Zip, LibreOffice, Notepad++, and Final Cut Pro.Malicious ads appearing on top of software searches diverted to shared Evernote notes masquerading as installation guides that trick visitors into executing a command in Terminal, which subsequently delivers MacSync, according to Bitdefender researchers. Aside from pilfering documents and browser-stored data, MacSync also siphons Telegram and macOS Notes information and cryptocurrency wallet details. Such a campaign was noted by researchers to potentially be a part of more widespread malvertising attacks targeting Windows and macOS environments."The same threat actor (or tightly linked group) may be running parallel campaigns across advertising platforms, adapting lures while reusing backend infrastructure," said the report.
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



