Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    AI Influencers Are Heading Into Uncharted Territory

    August 5, 2026

    The Download: NASA’s new telescope and Chinese tech import curbs

    August 5, 2026

    A New Device Eases One of the Most Annoying Parts of Routine Physicals

    August 5, 2026
    Facebook X (Twitter) Instagram
    Trending
    • AI Influencers Are Heading Into Uncharted Territory
    • The Download: NASA’s new telescope and Chinese tech import curbs
    • A New Device Eases One of the Most Annoying Parts of Routine Physicals
    • NASA’s new dark energy space telescope can also detect killer asteroids
    • The AI Notetaker Has Been Invited to All the Meetings
    • OK, Well, Rogue AI Agents Are Hacking Again
    • Heat Is an Orbital Data Center’s Greatest Foe. These Tiles Dump It at the Source.
    • The White House Is Keeping Its AI Cybersecurity Framework Secret
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»Google ads for fake Homebrew, LogMeIn sites push infostealers
    Cybersecurity

    Google ads for fake Homebrew, LogMeIn sites push infostealers

    kirklandc008@gmail.comBy kirklandc008@gmail.comOctober 18, 2025No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Google ads for fake Homebrew, LogMeIn sites push infostealers
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A new malicious campaign is targeting macOS developers with fake Homebrew, LogMeIn, and TradingView platforms that deliver infostealing malware like AMOS (Atomic macOS Stealer) and Odyssey.

    The campaign employs “ClickFix” techniques where targets are tricked into executing commands in Terminal, infecting themselves with malware.

    Homebrew is a popular open-source package management system that makes it easier to install software on macOS and Linux. Threat actors have used in the past the platform’s name to distribute AMOS in malvertising campaigns.

    LogMeIn is a remote access service, and TradingView is a financial charting and market analysis platform, both widely used by Apple users.

    Researchers at threat hunting company Hunt.io identified more than 85 domains impersonating the three platforms in this campaign, including the following:

    Some of the domains Hunt.io and Bleepingcomputer uncovered
    http://homebrewclubs.org/
    https://sites-phantom.com/
    http://homebrewfaq.org/
    https://tradingviewen.com/
    http://homebrewlub.us/
    https://tradingvieweu.com/
    http://homebrewonline.org/
    https://www.homebrewclubs.org/
    http://homebrewupdate.org/
    https://www.homebrewfaq.org/
    http://sites-phantom.com/
    https://www.homebrewfaq.us/
    http://tradingviewen.com/
    https://www.homebrewonline.org/
    http://tradingvieweu.com/
    https://www.homebrewupdate.org/
    http://www.homebrewfaq.us/
    https://www.tradingvieweu.com/
    http://www.homebrewonline.org/
    https://filmoraus.com/
    http://www.tradingviewen.com/
    https://homebrewfaq.org/
    https://filmoraus.com/
    https://homebrewfaq.us/
    https://homebrewfaq.org/
    https://homebrewlub.us/

    When checking some of the domains, BleepingComputer discovered that in some cases the traffic to the sites was driven via Google Ads, indicating that the threat actor promoted them to appear in Google Search results.

    The malicious sites feature convincing download portals for the fake apps and instruct users to copy a curl command in their Terminal to install them, the researchers say.

    Homebrew-themed ClickFix page
    Source: Hunt.io

    In other cases, like for TradingView, the malicious commands are presented as a “connection security confirmation step.” However, if the user clicks on the ‘copy’ button, a base64-encoded installation command is delivered to the clipboard instead of the displayed Cloudflare verification ID.

    Fake TradingView page
    Source: Hunt.io

    The commands fetch and decode an ‘install.sh’ file, which downloads a payload binary, removing quarantine flags an bypass Gatekeeper prompts to allow its execution.

    The payload is either AMOS or Odyssey, executed on the machine after checking if the environment is a virtual machine or an analysis system.

    The malware explicitly invokes sudo to run commands as root, and its first action is to collect detailed hardware and memory information of the host.

    Next, it manipulates system services like killing OneDrive updater daemons and interacts with macOS XPC services to blend its malicious activity with legitimate processes.

    Eventually, the information-stealing components of the malware are activated, harvesting sensitive information stored on the browser, cryptocurrency credentials, and exfiltrating to the command and control (C2).

    AMOS, first documented in April 2023, is a malware-as-a-service (MaaS) available under a $1,000/month subscription. It can steal a broad range of data from infected hosts.

    Recently, its creators added a backdoor component to the malware to give operators remote persistent access capabilities.

    Odyssey Stealer, documented by CYFIRMA researchers this summer, is a relatively new family derived from the Poseidon Stealer, which itself was forked from AMOS.

    It targets credentials and cookies stored in Chrome, Firefox, and Safari browsers, over a hundred cryptocurrency wallet extensions, Keychain data, and personal files, and sends them to the attackers in ZIP format.

    It is strongly recommended that users don’t paste in the Terminal commands found online if they don’t fully understand what they do.

    46% of environments had passwords cracked, nearly doubling from 25% last year.

    Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

    Get the Blue Report 2025

    ads Fake Google Homebrew infostealers LogMeIn push sites
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    Private Claude Chats Exposed in Google and Bing Search Results

    July 27, 2026

    Ransomware in 2026: More groups, more victims, no slowdown

    July 26, 2026

    The 3 types of people who will excel in the AI agent era, according to tech leaders

    July 26, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views

    The AirPods 4 and Lego’s brick-ified Grogu are our favorite deals this week

    October 12, 20253 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • AI Influencers Are Heading Into Uncharted Territory
    • The Download: NASA’s new telescope and Chinese tech import curbs
    • A New Device Eases One of the Most Annoying Parts of Routine Physicals
    • NASA’s new dark energy space telescope can also detect killer asteroids
    • The AI Notetaker Has Been Invited to All the Meetings

    AI Influencers Are Heading Into Uncharted Territory

    August 5, 2026

    The Download: NASA’s new telescope and Chinese tech import curbs

    August 5, 2026

    A New Device Eases One of the Most Annoying Parts of Routine Physicals

    August 5, 2026

    NASA’s new dark energy space telescope can also detect killer asteroids

    August 5, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.