Your One-Stop Source for the Latest PPC News
Your One-Stop Source for the Latest PPC News

Malicious Google Ads Redirect Mac Users to Fake Apple Pages

A Google search page for "mac cleaner" displays Google Ads for Mac optimization and storage tips, with related searches and a button to hide sponsored results. The interface is in dark mode, catering to Mac users seeking help beyond Apple Support.

A new malicious campaign is abusing Google Ads to target Mac users, displaying sponsored results that appear to lead to legitimate Google domains such as docs.google.com and business.google.com.

A Google search page for "mac cleaner" displays Google Ads for Mac optimization and storage tips, with related searches and a button to hide sponsored results. The interface is in dark mode, catering to Mac users seeking help beyond Apple Support.

From there, users are redirected to Google Apps Script pages and fake Medium profiles that closely mimic Apple’s official website or Apple Support accounts. These pages instruct users to run obfuscated Terminal commands (Base64-encoded and executed via zsh), potentially compromising their systems.

A webpage for Mac users explaining how to free up storage space, with clear steps to open Terminal, a command line example, and an explanation beneath. The page is titled "Free up storage space on Mac" and offers helpful Apple Support tips.

The ads appear to come from Google-verified advertiser accounts, suggesting that legitimate accounts may have been compromised rather than created solely for malicious use.

A pop-up window titled "My Ad Center" shows Google Ads details, highlighting "Paid for by Nathaniel Lucas Rodriguez" in red. The background displays blurred Google search results.

By leveraging both trusted Google domains and verified advertiser status, this campaign poses a high-risk phishing threat for Mac users and raises serious concerns about the integrity of the Google Ads ecosystem.

blank

This news was shared by Olena Khomych from MacKeeper.

Share this article
0
Share
Shareable URL
Read next