Connect with us

Technology

Google Ads spread Mac malware disguised as popular browser

Published

on

Google Ads spread Mac malware disguised as popular browser

Join Fox News for access to this content

You have reached your maximum number of articles. Log in or create an account FREE of charge to continue reading.

By entering your email and pushing continue, you are agreeing to Fox News’ Terms of Use and Privacy Policy, which includes our Notice of Financial Incentive.

Please enter a valid email address.

Having trouble? Click here.

Google Ads are mostly harmless, but if you see one promoting a particular web browser, avoid clicking.

Security researchers have discovered new malware for Mac devices that steals passwords, cryptocurrency wallets and other sensitive data. 

Advertisement

It masquerades as Arc, a new browser that recently gained popularity due to its unconventional user experience.

GET SECURITY ALERTS, EXPERT TIPS — SIGN UP FOR KURT’S NEWSLETTER — THE CYBERGUY REPORT HERE

Real new browser image. (Arc)

How the Mac malware infects your device

The Mac malware lurks behind sponsored search results. Clicking the ad redirects you to arc-download[.]com, a phony website that pretends to offer a Mac version of Arc. The downloaded file looks like a typical Mac app installer.

However, there’s one catch — you’re asked to run the file by right-clicking and choosing open, rather than the more straightforward method of simply double-clicking on the file. This is to bypass a security measure Macs have in place. By forcing you to skip this step, the malware tricks you into installing it.

Advertisement

WHAT IS ARTIFICIAL INTELLIGENCE (AI)?

An analysis of the malware code shows that once installed, the stealer sends stolen information, such as your passwords, to the IP address 79.137.192.4, which turns out to be the home base for this malware’s control panel. This sneaky panel lets cybercriminals access stolen data from infected accounts.

“There is an active scene for Mac malware development focused on stealers,” Jérôme Segura, lead malware intelligence analyst at Malwarebytes, wrote. “As we can see in this post, there are many contributing factors to such a criminal enterprise. The vendor needs to convince potential customers that their product is feature-rich and has low detection from antivirus software.”

Fake Arc browser ad. (Malwarebytes)

ANDROID BANKING TROJAN MASQUERADES AS GOOGLE PLAY TO STEAL YOUR DATA

Advertisement

The Mac malware is ‘verified by Google’

The Mac malware posing as a Google ad is called Poseidon, according to researchers at Malwarebytes. When clicking the “more information” option next to the ad, it shows it was purchased by an entity called Coles & Co, an advertiser identity Google claims to have verified.

Google verifies every entity that wants to advertise on its platform. In Google’s own words, this process aims “to provide a safe and trustworthy ad ecosystem for users and to comply with emerging regulations.” However, there seems to be some lapse in the verification process if advertisers can openly distribute malware to users. Though it is Google’s job to do everything it can to block bad ads, sometimes bad actors can temporarily evade their detection.

This isn’t even the first instance of cybercriminals exploiting Google ads. I reported in May that ads are being used to position bogus websites atop your search results. These websites pose as trustworthy sites, and they pilfer your money and personal information.

In this latest instance, Google identified this issue and suspended the advertiser account for violating its policies, removing all its ads from its platforms, even before the Malwarebytes report.

Advertisement

We reached out to Google, and a spokesperson offered this statement:

“We prohibit ads that attempt to circumvent our enforcement by disguising the advertiser’s identity to deceive users. When we identify ads that violate our policies we move quickly to remove the ads and suspend the associated advertiser account when applicable, as we did in this case.”

Fake entity called Coles & Co behind bogus ad. (Malwarebytes)

ANDROID USERS AT RISK AS BANKING TROJAN TARGETS MORE APPS

5 ways to protect yourself from Google ads malware

It’s hard to detect which Google ad is malicious. Follow these five tips to protect yourself from these Google search scams.

Advertisement

1. Bookmark or save URL: If you frequently visit certain sites, particularly social media and financial platforms, bookmark or save their URLs. This will ensure that you end up on the right page and avoid counterfeit pages.

2. Avoid clicking on unknown links: Always type the website address directly into your browser’s address bar. Avoid clicking on links, especially those sent via email or found on unfamiliar websites, as they might lead to counterfeit or malicious pages. By manually entering the URL, you ensure that you’re navigating to the correct and intended site, reducing the risk of phishing attacks and other online threats.

The best way to protect yourself from clicking malicious links that install malware that may get access to your private information is to have strong antivirus protection installed on all your devices. This can also alert you of any phishing emails or ransomware scams. Get my picks for the best 2024 antivirus protection winners for your Windows, Mac, Android & iOS devices.

3. Download apps from trusted platforms: When downloading apps on your Mac or any other Apple device, use the App Store. Apple has strict security guidelines that only allow secure and legitimate apps to be hosted on its platform.

4. Keep your browser updated for maximum security: Regularly updating your browser is crucial, as updates often include security patches that protect against newly discovered vulnerabilities.

Advertisement

5. Recognize urgent requests as potential scams: Always be wary if someone is urgently requesting you to do something like send money, provide personal information or click on a link — chances are it’s a scam.

HOW TO REMOVE YOUR PRIVATE DATA FROM THE INTERNET

Kurt’s key takeaway

The Poseidon malware case is a wake-up call for everyone to be super careful with online ads, especially those for popular software. Don’t just click on the first sponsored search result that pops up. Also, ensure you only download apps from trusted sources, like official app stores. To add another layer of security, consider using strong antivirus protection.

Do you feel confident in recognizing legitimate download sites versus fake ones? Let us know by writing us at Cyberguy.com/Contact

Advertisement

For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter

Ask Kurt a question or let us know what stories you’d like us to cover.

Follow Kurt on his social channels:

Answers to the most-asked CyberGuy questions:

Copyright 2024 CyberGuy.com. All rights reserved.

Advertisement

Technology

Betterment’s financial app sends customers a $10,000 crypto scam message

Published

on

Betterment’s financial app sends customers a ,000 crypto scam message

We’ll triple your crypto! (Limited Time)

Bryan: Betterment is giving back!

We’re celebrating our best-performing year yet by tripling Bitcoin and Ethereum deposits for the next three hours.

For example, if you send $10,000 in Bitcoin or Ethereum, we’ll send you right back $30,000 to your sending Bitcoin or Ethereum address.

Send deposits to these addresses:

Advertisement
Continue Reading

Technology

Fox News AI Newsletter: 10 showstopping CES innovations

Published

on

Fox News AI Newsletter: 10 showstopping CES innovations

NEWYou can now listen to Fox News articles!

Welcome to Fox News’ Artificial Intelligence newsletter with the latest AI technology advancements.

IN TODAY’S NEWSLETTER:

– CES 2026 showstoppers: 10 gadgets you have to see
– Construction giant unveils AI to help prevent job site accidents: ‘It’s essentially a personal assistant’
– Fox News gets exclusive look at company helping businesses nationwide harness AI-powered robots to boost efficiency and fill labor gaps

CES 2026 put health tech front and center, with companies showcasing smarter ways to support prevention, mobility and long-term wellness. (CES)

Advertisement

FUTURE IS NOW: Every January, the Consumer Electronics Show, better known as CES, takes over Las Vegas. It’s where tech companies show off what they’re building next, from products that are almost ready to buy to ideas that feel pulled from the future.

SAFER SITES: Construction equipment giant Caterpillar has unveiled a new artificial intelligence (AI) tool designed to improve job site safety and boost efficiency as the industry grapples with labor shortages.

FUTURE OF WELLNESS: The Consumer Electronics Show, better known as CES, is the world’s largest consumer technology event, and it’s underway in Las Vegas. It takes over the city every January for four days and draws global attention from tech companies, startups, researchers, investors and journalists, of course.

FUTURE OF WORK: As artificial intelligence is rapidly evolving, Fox News got an exclusive look at a company helping businesses nationwide harness AI-powered robots to boost efficiency and fill labor gaps. RobotLAB, with 36 locations across the country and headquartered in Texas, houses more than 50 different types of robots, from cleaning and customer service bots to security bots.

The LG CLOiD robot and the LG OLED evo AI Wallpaper TV are displayed onstage during an LG Electronics news conference at CES 2026 in Las Vegas, Jan. 5, 2026. (REUTERS/Steve Marcus)

Advertisement

COMPUTE CRUNCH: The price tag for competing in the artificial intelligence race is rapidly climbing, fueling demand for advanced computing power and the high-end chips that are needed to support it. Advanced Micro Devices (AMD) CEO Lisa Su said demand for AI computing is accelerating as industries rush to expand their capabilities.

AI GONE WRONG: A California teenager used a chatbot over several months for drug-use guidance on ChatGPT, his mother said. Sam Nelson, 18, was preparing for college when he asked an AI chatbot how many grams of kratom, a plant-based painkiller commonly sold at smoke shops and gas stations across the country, he would need to get a strong high, his mother, Leila Turner-Scott, told SFGate, according to the New York Post. 

DR CHAT: ‘The Big Money Show’ panelists weigh in on a report on people turning to ChatGPT for medical and healthcare questions.

‘FUNDAMENTALLY DEFLATIONARY’: OpenAI Board Chair Bret Taylor discusses artificial intelligence’s potential to change traditional work and its increasing use in healthcare on ‘Varney & Co.’

MIND TRAP ALERT: Artificial intelligence chatbots are quickly becoming part of our daily lives. Many of us turn to them for ideas, advice or conversation. For most, that interaction feels harmless. However, mental health experts now warn that for a small group of vulnerable people, long and emotionally charged conversations with AI may worsen delusions or psychotic symptoms.

Advertisement

A California teenager sought drug-use guidance from a ChatGPT chatbot over several months while preparing for college, his mother told SFGate, according to the New York Post. (Kurt “CyberGuy” Knutsson)

FOLLOW FOX NEWS ON SOCIAL MEDIA

Facebook
Instagram
YouTube
X
LinkedIn

SIGN UP FOR OUR OTHER NEWSLETTERS

Fox News First
Fox News Opinion
Fox News Lifestyle
Fox News Health

DOWNLOAD OUR APPS

Fox News
Fox Business
Fox Weather
Fox Sports
Tubi

WATCH FOX NEWS ONLINE

Fox News Go

Advertisement

STREAM FOX NATION

Fox Nation

Stay up to date on the latest AI technology advancements and learn about the challenges and opportunities AI presents now and for the future with Fox News here.

Advertisement
Continue Reading

Technology

Meta expands nuclear power ambitions to include Bill Gates’ startup

Published

on

Meta expands nuclear power ambitions to include Bill Gates’ startup

These AI projects include Prometheus, the first of several supercluster computing systems, which is expected to come online in New Albany, Ohio, sometime this year. Meta is funding the construction of new nuclear reactors as part of the agreements, the first of which may come online “as early as 2030.” These announcements are part of Meta’s ongoing goal to support its future AI operations with nuclear energy, having previously signed a deal with Constellation to revive an aging nuclear power plant last year.

Financial information for the agreements hasn’t been released, but Meta says that it will “pay the full costs for energy used by our data centers so consumers don’t bear these expenses.”

“Our agreements with Vistra, TerraPower, Oklo, and Constellation make Meta one of the most significant corporate purchasers of nuclear energy in American history,” Meta’s chief global affairs officer, Joel Kaplan, said in the announcement. “State-of-the-art data centers and AI infrastructure are essential to securing America’s position as a global leader in AI.”

Continue Reading
Advertisement

Trending