Google Ad Promotes Fake Homebrew Malware

Google Ad Promotes Fake Homebrew Malware

Source: YouTube · John Hammond · published Jan 21, 2025 · 24:49

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

A malicious Google Ads campaign targeted Homebrew users with fake sponsored results leading to a cloned website that installs malware alongside the legitimate package manager 0:15-0:35.

Key Takeaways:
• The fake website used brew[.]sh (a one-letter difference from the official brew[.]sh) to trick users into running a malicious curl command 2:44-3:31
• The malware was identified as Atomic Stealer (Amos Stealer), an macOS info stealer that targets browser data, crypto wallets, and sensitive files 14:32-17:07
• The malware steals data and exfiltrates it to a command and control server at IP 181.119.135.54 17:55-18:10
• Google Ads allows advertisers to display fake URLs while redirecting to different sites through tracking templates 21:35-22:48

This attack highlights the dangers of malvertising and the importance of verifying URLs before installing software, especially when using curl pipe to bash commands 22:39-23:31.

Sources:

  • 0:15-0:35 Fake Homebrew website with malicious curl command
  • 2:44-3:31 Comparison of legitimate vs malicious installation commands
  • 14:32-17:07 Analysis of the info stealer functionality
  • 17:55-18:10 Command and control server details
  • 21:35-22:48 Google Ads tracking template explanation
  • 22:39-23:31 Prevention recommendations for users

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

over the past weekend if you had done a Google search for Homebrew one of the most popular package managers for Mac OS and Linux you would have very likely seen one more result than what we're seeing here in fact you probably would have seen the top result being a sponsored listing for Homebrew what looks like the real genuine and legitimate Homebrew website at www. brew. but this is not actually the official website in fact it's a clone fake website that will granted help you install Homebrew but alongside it it'll install malware I saw this first shared on Twitter or X thanks to Ryan who said hey developers be careful when installing Homebrew Google is serving sponsored links to a Homebrew site clone that has a curl command to malware the URL for this website is just one letter different…