Malware, Threat Intelligence

Hijacked Google Ads enable MacSync infostealer delivery

Cybernews reports that threat actors have launched the information-stealing MacSync malware in a new malvertising campaign that weaponized at least 35 breached Google Ads accounts promoting law firms, hotels, and other legitimate businesses around the world to push over 200 illicit ads spoofing widely used macOS software, including 7-Zip, LibreOffice, Notepad++, and Final Cut Pro.

Malicious ads appearing on top of software searches diverted to shared Evernote notes masquerading as installation guides that trick visitors into executing a command in Terminal, which subsequently delivers MacSync, according to Bitdefender researchers. Aside from pilfering documents and browser-stored data, MacSync also siphons Telegram and macOS Notes information and cryptocurrency wallet details. Such a campaign was noted by researchers to potentially be a part of more widespread malvertising attacks targeting Windows and macOS environments.

"The same threat actor (or tightly linked group) may be running parallel campaigns across advertising platforms, adapting lures while reusing backend infrastructure," said the report.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds