Skip to content

// #malvertising

3 articles

🏛️ Architecture

Attackers Abuse Google Ads and Claude.ai Conversations to Deliver macOS Malware to Developers

A campaign targeting macOS users — particularly developers — is abusing both Google Ads and Claude.ai chat conversations as malware delivery vectors. Malicious ads impersonating developer tools redirect to sites hosting macOS malware, while a second vector embeds download links in Claude.ai conversations shared with targets. The campaign has updated the MacSync infostealer family with new macOS Sequoia-compatible components.

#macos +7
🔑 IAM

GoDaddy ManageWP Credentials Targeted by AiTM Phishing Campaign via Malicious Google Ads

A real-time adversary-in-the-middle phishing campaign is targeting GoDaddy ManageWP administrators through malicious Google search advertisements that appear above legitimate results for ManageWP login queries. The campaign steals session tokens via a real-time proxy, bypassing MFA, and uses Telegram for credential exfiltration. Each compromised ManageWP account typically controls hundreds of WordPress sites, making this a high-leverage credential theft campaign.

#phishing +8
🛡️ SecOps

MacSync Stealer Delivered via Malicious Google Ad Targeting macOS Homebrew Users

A macOS infostealer tracked as MacSync has been distributed through a malicious Google search advertisement impersonating the Homebrew package manager — a tool used by virtually all macOS developers. The campaign harvests browser credentials, session tokens, macOS keychain data, and cryptocurrency wallet files from developer machines. macOS users who installed Homebrew via a Google search in the past 30 days should verify their installation source.

#macos +6