• 07 3184 7575
  • September 28, 2026
  • 0 Comments

We recently reviewed research from Bitdefender highlighting an active malvertising campaign targeting macOS users. The findings show how attackers are increasingly abusing legitimate advertising platforms to distribute malware — without exploiting any software vulnerability.

Instead, they are exploiting trust.

According to Bitdefender, threat actors hijacked legitimate Google Ads accounts to deliver malicious sponsored results to users searching for popular software downloads.

How the Campaign Works

The campaign targets users searching for well-known macOS applications, including:

  • 7-Zip
  • Notepad++
  • LibreOffice
  • Microsoft Office
  • OBS Studio
  • Final Cut Pro

When users search for these exact product names, they may see a sponsored result at the top of Google’s search page. The ad appears legitimate because it matches the search query precisely.

However, instead of directing users to the official developer website, the ad redirects them to a shared Evernote page designed to look like an installation guide.

Rather than offering a traditional download, the page instructs users to:

  1. Open Terminal
  2. Paste a Base64-encoded command
  3. Execute the command manually

That command then downloads and runs malicious code.

This method shifts execution responsibility to the user and avoids hosting a typical fake installer page, making detection and takedown more difficult.

Hijacked, Not Fake, Advertisers

Bitdefender tracked more than 35 compromised Google Ads accounts and over 200 malicious ads linked to the operation.

The compromised advertiser accounts originated from multiple countries, including the United States, Canada, Italy, Germany, the UK, India, Japan, and others.

Importantly, many of these accounts were previously used by legitimate organisations — including charities, law firms, and commercial businesses.

This suggests attackers did not create new advertiser identities. Instead, they took over existing, trusted business profiles.

Because these accounts may have long-standing histories and valid billing arrangements, fraudulent activity is harder to detect.

Malware Delivered: MacSync Stealer

The Terminal command deploys a variant of MacSync Stealer (v1.1.2_release, build tag “symbiot”), a malware family designed for account takeover and financial theft.

According to Bitdefender, the stealer can:

  • Exfiltrate files and documents
  • Harvest browser cookies and login databases
  • Collect Telegram data and macOS Notes content
  • Target crypto wallets and browser-based crypto extensions
  • Extract credentials from password managers
  • Display fake macOS password prompts to capture system credentials

The infrastructure overlaps with previously documented malvertising campaigns, including earlier ClickFix operations that abused Meta ads.

This suggests a broader ecosystem operating across multiple advertising platforms and targeting both macOS and Windows users.

A Shift Toward Platform Abuse

This campaign reinforces a growing trend:

Threat actors are increasingly abusing legitimate platforms rather than exploiting software vulnerabilities.

Sponsored ads provide:

  • High visibility
  • Precise keyword targeting
  • Immediate access to users actively seeking downloads

Cloud services such as Evernote further complicate detection because they are widely used for legitimate collaboration.

In other words, the attack chain blends into normal digital behaviour.

Bitdefender’s Recommendations

Bitdefender advises:

  • Avoid clicking sponsored search results for software downloads
  • Download applications only from official developer domains
  • Never run Terminal commands provided by a website
  • Be cautious when instructions include encoded strings

Security tools can help detect malicious scripts and block persistence mechanisms, but user awareness remains critical.

A CSB Perspective

At CSB, we see this campaign as a reminder that modern cyber threats are increasingly about manipulation of trusted ecosystems rather than exploitation of technical flaws.

Search engines, advertising platforms, and cloud collaboration tools are core components of daily business activity. When attackers compromise legitimate advertiser accounts, traditional red flags become harder to spot.

Key takeaways for organisations and users:

  • Treat sponsored search results with caution
  • Restrict administrative access to advertising platforms
  • Implement strong MFA for marketing and ad accounts
  • Monitor ad account activity for anomalies
  • Educate staff not to execute Terminal or PowerShell commands from web instructions

Mac users are often perceived as less frequently targeted, but this campaign demonstrates that macOS environments are firmly within attackers’ focus — particularly when financial theft is involved.

The broader lesson is clear: trust signals online — including ads and cloud-hosted pages — are no longer reliable indicators of safety.

Previous Post
Strengthening Superannuation Security: Why Phishing-Resistant Authentication Can No Longer Wait