• News/
  • https://www.bleepingcomputer.com/news/security/google-ads-for-shared-chatgpt-grok-guides-push-macos-infostealer-malware/

Google ads for shared ChatGPT, Grok guides push macOS infostealer malware

BleepingComputer
·
Bill Toulas
·
Published Dec 10, 2025
·
Updated

A new AMOS infostealer campaign is abusing Google search ads to lure users into Grok and ChatGPT conversations that appear to offer “helpful” instructions but ultimately lead to installing the AMOS info-stealing malware on macOS. The campaign was first spotted by researchers at cybersecurity company Kaspersky yesterday, while Huntress managed security platform published a more detailed report earlier today. The ClickFix attack begins with victims searching for macOS-related terms, such as maintenance questions, problem-solving, or for Atlas - OpenAI's AI-powered web browser for macOS. Google advertisement link directly to ChatGPT and Grok conversations that had been publicly shared in preparation for the attack. The chats are hosted on the legitimate LLM platforms and contain the malicious instructions used to install the malware. "During our investigation, the Huntress team reproduced these poisoned results across multiple variations of the same question, 'how to clear data on iMac,' 'clear system data on iMac,' 'free up storage on Mac,' confirming this isn't an isolated result but a deliberate, widespread poisoning campaign targeting common troubleshooting queries," Huntress researchers explain. If users fall for the trick and execute the commands from the AI chat in macOS Terminal, a base64-encoded URL decodes into a bash script (update) that loads a fake password prompt dialog. When the password is provided, the script validates, stores, and uses it to execute privileged...

Read full article

Affected Software

3 affected components
OpenAI ChatGPT
Grok Grok
Apple macOS
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a recent campaign using Google ads to distribute macOS infostealer malware through fake ChatGPT and Grok guides.

2

What security implications are discussed in the article?

The article highlights the risk of malware installation through deceptive advertising tactics that exploit popular tools like ChatGPT and Grok.

3

What products or software are affected by the AMOS infostealer malware?

The affected products include OpenAI's ChatGPT, Grok, and Apple's macOS.

4

How does the AMOS infostealer malware operate according to the article?

The malware operates by luring users into conversations that promise helpful content but lead to malicious software installation.

5

What is the significance of Google ads in this malware distribution campaign?

Google ads play a crucial role by attracting users to the malicious sites that promote the infostealer malware under the guise of legitimate services.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203