Warning: Dangerous Google Ads Trick Mac Users with Fake Homebrew Downloads


Fake Homebrew Google Ads Campaign Spreads Dangerous Malware

A new cybersecurity threat has emerged targeting Mac and Linux users through malicious Google advertisements. Hackers are impersonating Homebrew, a popular open-source package manager, to distribute the AmosStealer malware.

The Deceptive Campaign
Security researcher Ryan Chenkie discovered that cybercriminals are using Google ads displaying the legitimate Homebrew URL (brew.sh) but redirecting users to a fraudulent site (brewe.sh). The fake website mimics Homebrew’s official interface and installation process, tricking users into downloading malware instead of the legitimate package manager.

The Malware Threat
AmosStealer, also known as ‘Atomic’, is a sophisticated infostealer targeting macOS systems. Sold to cybercriminals for $1,000 per month, it can:
– Steal credentials
– Harvest browser data
– Target over 50 cryptocurrency extensions and wallets

Response and Prevention
Homebrew’s project leader, Mike McQuaid, acknowledged the issue but noted limited control over Google’s advertising platform. While the malicious ad has been removed, similar campaigns may emerge using different domains.

Safety Recommendations:
1. Verify website URLs before downloading software
2. Bookmark official project websites
3. Avoid clicking on sponsored search results
4. Use direct sources for downloading software packages

The incident highlights ongoing concerns about malvertising in Google Search results and the need for enhanced security measures in digital advertising platforms.

Share This Article