Malvertising Delivers AMOS ‘malext’ Infostealer via Fake Text-Sharing Ads

A new malvertising campaign has been discovered targeting macOS users at scale, utilizing fake text-sharing ads to distribute the AMOS ‘malext’ infostealer.

The campaign, which combines Google Ads with deceptive clickbait articles, aims to compromise macOS devices through social engineering.

This blog post breaks down the steps of the campaign, from the initial compromised Google Ads to the final payload delivery, highlighting how users can defend against such threats.

Gi7w0rm investigation into this malvertising campaign began with a tip from researcher @itspappy. The researcher reported an incident in which a macOS user almost fell victim to a malware attack after clicking a suspicious link in a Google search result.

The link led to a seemingly helpful Medium article about clearing up storage space on macOS. However, it included a shell command that requested administrative privileges when copied and pasted into the terminal.

The victim became suspicious when the system repeatedly asked for the macOS admin password after entering the command, aborting the operation just in time.

Google malvertising targeting MacOS users (Source: medium)
Google malvertising targeting MacOS users (Source: medium)

The malicious article and the associated domains optimize-storage-mac-os[.]medium[.]com, octopox[.]com, and vagturk[.]com were used in the attack, but were already taken down by the time the investigation began.

Malvertising At Scale

After identifying the initial indicators, PaPPy and I launched a deeper investigation into the campaign.

We uncovered over 34 ad campaigns using Google’s public Ads Library, showing that the attackers were continuously rotating through various compromised Google Ad accounts.

Cruiseship Ad account pushing MacOS USB upgrade AD (Source: medium)
Cruiseship Ad account pushing MacOS USB upgrade AD (Source: medium)

These ads often promoted fake Medium articles that claimed to offer solutions to common macOS problems. However, upon closer inspection, they led users to sites hosting malicious content.

In addition to Medium, the attackers used several other platforms, including Evernote, kimi.com, and mssg.me, to distribute their fake articles and scale the operation. T

he ads appeared legitimate, but their content was carefully crafted to deceive users into running malicious commands that eventually led to the installation of the AMOS ‘malext’ infostealer.

Analysis Of The Malicious Payload

The fake articles used very similar templates, often focusing on macOS troubleshooting or software tool installation.

The attackers used simple but effective tactics: they provided copy-paste terminal commands that users could easily follow.

These commands included obfuscated code, which, when decoded, downloaded the malicious AMOS ‘malext’ payload onto the victim’s machine.

Examples of Evernote Ads (Source: medium)
Examples of Evernote Ads (Source: medium)

The malware’s payload is a macOS binary, carefully crafted to evade detection by both sandboxes and antivirus software.

Upon execution, the malware collects various types of sensitive data, including system information, passwords, browser cookies, Apple Notes content, and crypto wallet data. This data is then compressed into a zip file and exfiltrated to the attacker’s Command and Control (C2) server.

TypeIndicatorDescription
Domainmalext[.]comPrimary C2 and trojan downloads
IP38.244.158[.]56Primary exfil server
IP199.217.98.33Fallback exfil
File~/.pass, ~/.agent, ~/.username, ~/.mainhelperPersistence and creds

This malvertising campaign is a clear example of how attackers are evolving their tactics, using widely trusted platforms and sophisticated social engineering to deliver dangerous payloads.

By staying vigilant and applying best security practices, macOS users can protect themselves from falling victim to such attacks.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories