Tools

News

Notícias

Classificados

Cursos

Broker

IPv4:
IPv6:
UpOrDown
Ping
MTR
MTU Detect
Portscan
DNS
HTTP/SSL
My IP
IP Calc & Sum

Atomic Stealer Reaches Macs via Malvertising

Image © Arstechnica
Security researchers warn that search-engine ads impersonating major services are being used to deliver a macOS credential stealer to unsuspecting Mac users. LastPass is the latest brand to be targeted in this wide-ranging campaign.

Security researchers warn that malicious ads on search engines impersonate a wide range of services to recruit Macs into a credential-stealing campaign. The latest high-profile target is LastPass users.

LastPass disclosed a campaign that used search-engine optimization to push ads for LastPass macOS apps to the top of results on Google and Bing. Clicking these ads led to fraudulent GitHub pages that claimed to offer LastPass installers for Macs.

The pages instead installed a macOS credential stealer known as Atomic Stealer, also referred to as Amos Stealer by researchers. The campaign appears widespread, with takedown and disruption efforts ongoing.

LastPass notes the scam mirrors broader brand impersonation: other software and services targeted in similar ads include 1Password, Basecamp, Dropbox, Gemini, Hootsuite, Notion, Obsidian, Robinhood, Salesloft, SentinelOne, Shopify, Thunderbird, and TweetDeck. Ads typically present in bold fonts and redirect to GitHub pages that install versions of Atomic disguised as legitimate software.

In many cases, attackers lure Mac users into downloading disguised installers, which circumvent Gatekeeper protections by automating installation via prompt-like prompts or CAPTCHA bypass tactics. Security researchers say this technique has evolved over the past two years as defenders attempt to block it.

Users should only download software from official sites, avoid clicking suspicious ads, and verify publishers before installing anything. Enterprises should monitor for IoCs and keep an eye on the indicators LastPass and others have shared to help detect similar threats.

 

Arstechnica

Related News

Wasco Gets $10M Fiber Upgrade
Pixnapping Threat Expands to Android 2FA
Bluepeak Upgrades 25k Customers in SD MN
Signal's Post-Quantum Upgrade: Engineering Triumph
Comcast Begins Teays Valley Internet Buildout
Metronet expands in 4 Michigan towns

ISP.Tools survives thanks to ads.

Consider disabling your ad blocker.
We promise not to be intrusive.

Cookie Consent

We use cookies to improve your experience on our site.

By using our site you consent to cookies. Learn more