HomeSecurityGoogle Ads Spread Malware Through Fake Homebrew Site

Google Ads Spread Malware Through Fake Homebrew Site

Security researchers have revealed that a sophisticated malvertising campaign, detected last week, is targeting software developers with malware through malicious Google ads pretending to be from the popular Homebrew.

See also: Hackers exploited flaw in Krpano framework for Spam Ads

Homebrew malware

This attack demonstrates the evolution of cybercriminal tactics, who exploit trusted verification systems to distribute information-stealing malware.

The campaign was first spotted by developer Ryan Chenkie on January 18, 2025, and uses a deceptively simple but effective method. Malicious ads on Google display the legitimate Homebrew address “brew.sh” in search results, but when users click on them, they are silently redirected to a nearly identical fake domain, “brewe.sh” – which differs by only one letter.

The fake website that delivers the malware almost exactly copies the installation page of the official Homebrew website, asking users to run a command that resembles the standard installation process.

However, instead of downloading the authentic package manager, the command installs AmosStealer (also known as Atomic Stealer), a powerful malware designed specifically for macOS.

Security researcher JAMESWT identified the malicious payload and confirmed its dangerous capabilities.

See also: Scallywag: New ad-fraud campaign uses WordPress plugins

AmosStealer is capable of exfiltrating credentials, browser data, cryptocurrency wallets , and sensitive files from infected devices. The malware targets more than 50 cryptocurrency-related browser extensions, as well as various desktop wallet applications.

Google Ads Spread Malware Through Fake Homebrew Site
Google Ads Spread Malware Through Fake Homebrew Site

The sophistication of this campaign reflects the profitable nature of the underlying malware-as-a-service business.

AmosStealer is sold on dark web marketplaces for subscriptions ranging from $1,000 to $3,000 per month, revealing the significant financial motivations behind these attacks.

Homebrew is an attractive target for cybercriminals due to its popularity among developers and technical users, who often hold valuable digital assets, such as cryptocurrency wallets and sensitive business credentials.

This particular package manager is widely used on macOS and Linux systems for installing and managing software.

See also: Google suspended 39 million suspected fraud ad accounts

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Based on the above, we can point out that cyberattacks of this type signal a worrying trend: cybercriminals are no longer targeting only "ordinary" users, but are turning to more specialized and technically skilled groups, such as programmers.

Source: cybersecuritynews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS