malware that steals passwords, cryptocurrency wallets, and other sensitive data has been spotted circulating through Google Ads.

This is at least the second time in two months that the widely used advertising platform has been abused to infect internet users.
The recent ads, spotted by security Malwarebytes on Monday, promote Mac versions of Arc, an innovative browser that was released for the macOS platform last July. The ad promises users a “calmer, more personal” experience with less clutter and distractions, following the marketing message of The Browser Company, the startup behind Arc.
See more: Google ad impersonates Whales Market and promotes malware
When verification fails
According to Malwarebytes, internet users who clicked on the ads were redirected to arc-download[.]com, a completely fake page that looks almost identical to the real Arc browser page.
Further investigation into the ad reveals that it was purchased by an entity called Coles & Co, an advertiser identity that, according to Google, has been verified.

Visitors who click the download button on arc-download[.]com will download a .dmg installer file that looks genuine, with one difference: it includes instructions to run the file by right-clicking and selecting “Open” instead of the usual double-click. This is done to bypass a macOS security mechanism that prevents applications from being installed unless they have been digitally signed by a certified Apple.
An analysis of the malware reveals that, once installed, the hacker sends data to the IP address 79.137.192[.]4. This address hosts the Poseidon, which is actively sold on criminal marketplaces. The control panel allows customers to access accounts and extract information from the collected data.

Read also: Malicious advertising campaign spreads Oyster Backdoor
“There is an active Mac malware development scene that is focused on hackers,” wrote Jérôme Segura, lead malware intelligence analyst at Malwarebytes. “As it turns out, there are many factors that contribute to such a criminal enterprise. The vendor must convince potential customers that their product is feature-rich and has a low detection rate by antivirus .”
Poseidon is advertised as a macOS “thief” with capabilities such as “extracting files, extracting cryptocurrency wallets, stealing passwords from managers like Bitwarden and KeePassXC, as well as collecting data from browsers.” Atomic Stealer, a similar macOS thief, appears to share much of the same underlying source code as Poseidon.
The author of the post, Rodrigo4, has added a new feature for configuring VPNs, which is not yet functional, probably because it is still under development. The forum post appeared on Sunday, and Malwarebytes detected the malicious ads a day later. This discovery comes a month after Malwarebytes detected another batch of Google ads promoting a fake version of Arc for Windows. The installer for this campaign installed a suspected infostealer for that platform.
Read more: Hackers use fake Facebook ads to distribute malware
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Like many other major ad networks, Google Ads often serves malicious content that is not removed until it is approved. Google Ads assumes no responsibility for any damages that may result. In an email, the company said it removes malicious ads as soon as it is notified and suspends the advertiser's account, as it did in this case.
People looking to install software advertised online should look for the official download site and not trust the advertising site. They should also be wary of any instructions that suggest Mac users install applications via the right-click method mentioned above. Malwarebytes' post provides indicators of compromisethat users to determine if they have been targeted.
See also: Notepad++ – VNote: Malicious ads target users
Source: arstechnica
