• News/
  • https://www.bleepingcomputer.com/news/security/google-ads-for-fake-homebrew-logmein-sites-push-infostealers/

Google ads for fake Homebrew, LogMeIn sites push infostealers

BleepingComputer
·
Bill Toulas
·
Published Oct 18, 2025
·
Updated

A new malicious campaign is targeting macOS developers with fake Homebrew, LogMeIn, and TradingView platforms that deliver infostealing malware like AMOS (Atomic macOS Stealer) and Odyssey. The campaign employs “ClickFix” techniques where targets are tricked into executing commands in Terminal, infecting themselves with malware. Homebrew is a popular open-source package management system that makes it easier to install software on macOS and Linux. Threat actors have used in the past the platform's name to distribute AMOS in malvertising campaigns. LogMeIn is a remote access service, and TradingView is a financial charting and market analysis platform, both widely used by Apple users. Researchers at threat hunting company Hunt.io identified more than 85 domains impersonating the three platforms in this campaign, including the following: When checking some of the domains, BleepingComputer discovered that in some cases the traffic to the sites was driven via Google Ads, indicating that the threat actor promoted them to appear in Google Search results. The malicious sites feature convincing download portals for the fake apps and instruct users to copy a curl command in their Terminal to install them, the researchers say. In other cases, like for TradingView, the malicious commands are presented as a “connection security confirmation step.” However, if the user clicks on the 'copy' button, a base64-encoded installation command is delivered to the clipboard instead of the displaye...

Read full article

Affected Software

3 affected components
Homebrew Homebrew
LogMeIn LogMeIn
TradingView TradingView
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a malicious campaign targeting macOS developers that uses fake Homebrew, LogMeIn, and TradingView sites to distribute infostealing malware.

2

What types of malware are being distributed in this campaign?

The campaign delivers infostealers such as AMOS (Atomic macOS Stealer) and Odyssey.

3

What techniques are being used to deceive targets in this campaign?

The attackers are using 'ClickFix' techniques to trick users into executing harmful commands in Terminal.

4

Which software platforms are being impersonated in this malicious campaign?

The fake sites impersonate Homebrew, LogMeIn, and TradingView.

5

Who is primarily targeted by this security threat?

The primary targets of this malicious campaign are macOS developers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203