A new malvertising campaign has been discovered targeting macOS users at scale, utilizing fake text-sharing ads to distribute the AMOS ‘malext’ infostealer.
The campaign, which combines Google Ads with deceptive clickbait articles, aims to compromise macOS devices through social engineering.
This blog post breaks down the steps of the campaign, from the initial compromised Google Ads to the final payload delivery, highlighting how users can defend against such threats.
Gi7w0rm investigation into this malvertising campaign began with a tip from researcher @itspappy. The researcher reported an incident in which a macOS user almost fell victim to a malware attack after clicking a suspicious link in a Google search result.
The link led to a seemingly helpful Medium article about clearing up storage space on macOS. However, it included a shell command that requested administrative privileges when copied and pasted into the terminal.
The victim became suspicious when the system repeatedly asked for the macOS admin password after entering the command, aborting the operation just in time.

The malicious article and the associated domains optimize-storage-mac-os[.]medium[.]com, octopox[.]com, and vagturk[.]com were used in the attack, but were already taken down by the time the investigation began.
Malvertising At Scale
After identifying the initial indicators, PaPPy and I launched a deeper investigation into the campaign.
We uncovered over 34 ad campaigns using Google’s public Ads Library, showing that the attackers were continuously rotating through various compromised Google Ad accounts.

These ads often promoted fake Medium articles that claimed to offer solutions to common macOS problems. However, upon closer inspection, they led users to sites hosting malicious content.
In addition to Medium, the attackers used several other platforms, including Evernote, kimi.com, and mssg.me, to distribute their fake articles and scale the operation. T
he ads appeared legitimate, but their content was carefully crafted to deceive users into running malicious commands that eventually led to the installation of the AMOS ‘malext’ infostealer.
Analysis Of The Malicious Payload
The fake articles used very similar templates, often focusing on macOS troubleshooting or software tool installation.
The attackers used simple but effective tactics: they provided copy-paste terminal commands that users could easily follow.
These commands included obfuscated code, which, when decoded, downloaded the malicious AMOS ‘malext’ payload onto the victim’s machine.

The malware’s payload is a macOS binary, carefully crafted to evade detection by both sandboxes and antivirus software.
Upon execution, the malware collects various types of sensitive data, including system information, passwords, browser cookies, Apple Notes content, and crypto wallet data. This data is then compressed into a zip file and exfiltrated to the attacker’s Command and Control (C2) server.
This malvertising campaign is a clear example of how attackers are evolving their tactics, using widely trusted platforms and sophisticated social engineering to deliver dangerous payloads.
By staying vigilant and applying best security practices, macOS users can protect themselves from falling victim to such attacks.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.