Tools

News

Notícias

Classificados

Cursos

Broker

IPv4:

IPv6:

 

UpOrDown
Ping
MTR
Smokeping
MTU Detect
Portscan
DNS
HTTP/SSL
My IP
IP Calc
IP Extractor

Atomic Stealer Reaches Macs via Malvertising

Image © Arstechnica
Security researchers warn that search-engine ads impersonating major services are being used to deliver a macOS credential stealer to unsuspecting Mac users. LastPass is the latest brand to be targeted in this wide-ranging campaign.

Security researchers warn that malicious ads on search engines impersonate a wide range of services to recruit Macs into a credential-stealing campaign. The latest high-profile target is LastPass users.

LastPass disclosed a campaign that used search-engine optimization to push ads for LastPass macOS apps to the top of results on Google and Bing. Clicking these ads led to fraudulent GitHub pages that claimed to offer LastPass installers for Macs.

The pages instead installed a macOS credential stealer known as Atomic Stealer, also referred to as Amos Stealer by researchers. The campaign appears widespread, with takedown and disruption efforts ongoing.

LastPass notes the scam mirrors broader brand impersonation: other software and services targeted in similar ads include 1Password, Basecamp, Dropbox, Gemini, Hootsuite, Notion, Obsidian, Robinhood, Salesloft, SentinelOne, Shopify, Thunderbird, and TweetDeck. Ads typically present in bold fonts and redirect to GitHub pages that install versions of Atomic disguised as legitimate software.

In many cases, attackers lure Mac users into downloading disguised installers, which circumvent Gatekeeper protections by automating installation via prompt-like prompts or CAPTCHA bypass tactics. Security researchers say this technique has evolved over the past two years as defenders attempt to block it.

Users should only download software from official sites, avoid clicking suspicious ads, and verify publishers before installing anything. Enterprises should monitor for IoCs and keep an eye on the indicators LastPass and others have shared to help detect similar threats.

 

Arstechnica

Notícias relacionadas

Divergência MME e Aneel sobre cessão de postes
Brisanet dobra base móvel em 2025
Vivo anuncia Rogério Takayanagi como VP de engenharia e serviços
GT fará minuta da Política Nacional de Infraestruturas Críticas
Oi: Justiça prorroga blindagem de pagamentos até abril
Rogerio Takahyanagi assume Vivo como VP Engenharia

O ISP.Tools sobrevive graças aos anúncios.

Considere desativar seu bloqueador de anúncios.
Prometemos não ser intrusivos.

Consentimento para cookies

Utilizamos cookies para melhorar a sua experiência no nosso site.

Ao utilizar o nosso site, você concorda com o uso de cookies. Saiba mais