{"id":64923,"date":"2025-02-02T21:06:38","date_gmt":"2025-02-02T21:06:38","guid":{"rendered":"https:\/\/peraltafinancing.com\/apple-2\/cuckoo-returns-mac-malware-spreads-via-legit-looking-google-ads\/"},"modified":"2025-02-02T21:06:38","modified_gmt":"2025-02-02T21:06:38","slug":"cuckoo-returns-mac-malware-spreads-via-legit-looking-google-ads","status":"publish","type":"post","link":"https:\/\/fivemor.com\/?p=64923","title":{"rendered":"Cuckoo returns; Mac malware spreads via legit-looking Google Ads"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"post-103017\">\n<p class=\"cats\"><a href=\"https:\/\/www.intego.com\/mac-security-blog\/category\/malware\/\">Malware<\/a><\/p>\n<header>\n<p class=\"about-post\">\n          Posted on<br \/>\n          <time itemprop=\"datePublished\" datetime=\"2025-01-31\">January 31st, 2025<\/time> by<\/p>\n<p>          <span itemprop=\"author\"><br \/>\n            <a href=\"https:\/\/www.intego.com\/mac-security-blog\/author\/joshlong\/\" title=\"Posts by Joshua Long\" class=\"author url fn\" rel=\"author\">Joshua Long<\/a>          <\/span><\/p>\n<p>          <img decoding=\"async\" alt=\"\" src=\"https:\/\/secure.gravatar.com\/avatar\/5ad29f4111ce14911abaa98cbbcdea42?s=18&amp;d=mm&amp;r=g\" srcset=\"https:\/\/secure.gravatar.com\/avatar\/5ad29f4111ce14911abaa98cbbcdea42?s=36&amp;d=mm&amp;r=g 2x\" class=\"avatar avatar-18 photo\" height=\"18\" width=\"18\" loading=\"lazy\"\/>        <\/p>\n<\/header>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter wp-image-103014 size-full\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2025\/01\/OSX-Cuckoo-Mac-macOS-malware-logo-v4-600x300-1.jpg\" alt=\"\" width=\"600\" height=\"300\"\/><\/p>\n<p>Over the past couple years, we\u2019ve written a lot about <a href=\"https:\/\/www.intego.com\/mac-security-blog\/topic\/stealer-malware\/\">stealer malware that infects Macs<\/a>. One malware family that frequently resurfaces is <strong>Atomic Stealer<\/strong>, or <strong>AMOS<\/strong> (short for Atomic macOS Stealer). AMOS is designed to exfiltrate sensitive data from infected Macs; this typically includes things like saved passwords, cookies, autofill text, and cryptocurrency wallets. A sub-variant known as <strong>Cuckoo<\/strong> first appeared in May 2024.<\/p>\n<p>Just like last year, Cuckoo has been spreading in January 2025 via elaborate campaigns, leveraging malicious but legitimate-looking Google Ads that redirect to lookalike homepages with Trojan downloads. Here\u2019s everything you need to know about the latest Cuckoo variants, and how to stay protected.<\/p>\n<p><em>In this article:<\/em><\/p>\n<h3>A brief history of Cuckoo Mac malware<\/h3>\n<p>Atomic macOS Stealer (AMOS, or AtomicStealer) <a href=\"https:\/\/www.intego.com\/mac-security-blog\/atomic-stealer-thieving-mac-malware-sold-via-telegram\/\">first surfaced<\/a> in late April 2023. At the time, a threat actor began selling it via Telegram as <strong>malware as a service<\/strong>, licensable for $1,000 per month. Since then, we\u2019ve seen <a href=\"https:\/\/www.intego.com\/mac-security-blog\/topic\/atomic-stealer\">a plethora of AMOS variants<\/a> emerge.<\/p>\n<p>Most often, AMOS malware is distributed through malicious Google Ads campaigns. These poisoned Google ads appear at the top of search results, where many people will see and click on them. In some cases, the ads are virtually indistinguishable from legitimate Google Ads run by the real software companies they mimic.<\/p>\n<p>Some antivirus companies dubbed a particular sub-class of AMOS variants \u201cCuckoo.\u201d Back in May 2024, we wrote about Cuckoo variants that were spreading via poisoned Google Ads that look like they redirect to the real Homebrew homepage, but in fact led to malware distribution sites.<\/p>\n<h4><strong>Yet another Cuckoo variant emerges<\/strong><\/h4>\n<p>On January 9, 2025, a malware researcher <a href=\"https:\/\/x.com\/gregclermont\/status\/1877294378663784912\" target=\"_blank\" rel=\"noopener\">noted<\/a> that Homebrew was back with a new lookalike homepage.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Cuckoo is back with another fake homebrew website<br \/>brewmacos[.]com<br \/>C2: 185.62.56[.]131<a href=\"https:\/\/twitter.com\/birchb0y?ref_src=twsrc%5Etfw\">@birchb0y<\/a> <a href=\"https:\/\/twitter.com\/AdamJKohler?ref_src=twsrc%5Etfw\">@AdamJKohler<\/a> <a href=\"https:\/\/twitter.com\/L0Psec?ref_src=twsrc%5Etfw\">@L0Psec<\/a> <a href=\"https:\/\/twitter.com\/IntegoSecurity?ref_src=twsrc%5Etfw\">@IntegoSecurity<\/a><\/p>\n<p>\u2014 Gr\u00e9goire Clermont (@gregclermont) <a href=\"https:\/\/twitter.com\/gregclermont\/status\/1877294378663784912?ref_src=twsrc%5Etfw\">January 9, 2025<\/a><\/p>\n<\/blockquote>\n<p>A little over a week later, more reports emerged with additional details; one developer <a href=\"https:\/\/x.com\/ryanchenkie\/status\/1880730173634699393\" target=\"_blank\" rel=\"noopener\">reported<\/a> that he had observed a malicious Google Ads campaign leading to a different fake Homebrew site. The next day, a malware researcher <a href=\"https:\/\/x.com\/JAMESWT_MHT\/status\/1881249774932005270\">posted<\/a> about a third fake Homebrew homepage.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">\u26a0\ufe0f Developers, please be careful when installing Homebrew.<\/p>\n<p>Google is serving sponsored links to a Homebrew site clone that has a cURL command to malware. The URL for this site is one letter different than the official site. <a href=\"https:\/\/t.co\/TTpWRfqGWo\">pic.twitter.com\/TTpWRfqGWo<\/a><\/p>\n<p>\u2014 Ryan Chenkie (@ryanchenkie) <a href=\"https:\/\/twitter.com\/ryanchenkie\/status\/1880730173634699393?ref_src=twsrc%5Etfw\">January 18, 2025<\/a><\/p>\n<\/blockquote>\n<p>The real Homebrew is a popular macOS software package manager.<\/p>\n<p>Each of the new fake Homebrew homepages tries to trick users into copying and pasting a command from the site into their Mac\u2019s Terminal app. While that might sound ridiculously suspicious and dangerous\u2014and it normally would be\u2014the legitimate Homebrew software is actually installed in this exact way. <strong>Both the Google Ads and lookalike pages are so convincing that many professionals have said they could have fallen for the scheme.<\/strong><\/p>\n<div id=\"attachment_103018\" style=\"width: 610px\" class=\"wp-caption aligncenter\"><img decoding=\"async\" aria-describedby=\"caption-attachment-103018\" loading=\"lazy\" class=\"wp-image-103018 size-full\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2025\/01\/Homebrew-homepage-fake-AMOS-Cuckoo-malware-campaign-v2.jpg\" alt=\"A fake Homebrew homepage, part of an AMOS\/Cuckoo Mac malware campaign.\" width=\"600\" height=\"479\"\/><\/p>\n<p id=\"caption-attachment-103018\" class=\"wp-caption-text\">A fake Homebrew site, part of an AMOS\/Cuckoo Mac malware campaign.<\/p>\n<\/div>\n<p>Compare for yourself. Would you have guessed correctly which is real, and which is fake?<\/p>\n<div id=\"attachment_100579\" style=\"width: 610px\" class=\"wp-caption aligncenter\"><img decoding=\"async\" aria-describedby=\"caption-attachment-100579\" loading=\"lazy\" class=\"wp-image-100579 size-full\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/05\/Homebrew-homepage-real.jpg\" alt=\"The real Homebrew site. Ironically, it has a longer, more suspicious-looking install URL.\" width=\"600\" height=\"479\"\/><\/p>\n<p id=\"caption-attachment-100579\" class=\"wp-caption-text\">The real Homebrew site. Ironically, it has a longer, more suspicious-looking install URL.<\/p>\n<\/div>\n<p>Interestingly, this is not the first time that malware has tried to disguise itself as <a href=\"https:\/\/www.intego.com\/mac-security-blog\/topic\/homebrew\/\">Homebrew<\/a>. As we mentioned, there was <a href=\"https:\/\/www.intego.com\/mac-security-blog\/intego-discovers-new-cuckoo-mac-malware-mimicking-homebrew\/\">the first Cuckoo campaign<\/a> in May 2024. Back in 2020, <a href=\"https:\/\/www.intego.com\/mac-security-blog\/apple-notarizes-dozens-of-mac-malware-samples\/\">threat actors used another domain<\/a> that was similar to that of the real Homebrew site, as part of a <a href=\"https:\/\/www.intego.com\/mac-security-blog\/topic\/typosquatting\/\">typosquatting<\/a> campaign. And back <a href=\"https:\/\/www.intego.com\/mac-security-blog\/osxdok-can-read-encrypted-web-traffic-open-a-backdoor\/\">in 2017, Mac malware known as Dok<\/a> used \u201chomebrew\u201d in the filename of one of its LaunchAgents.<a name=\"source\"\/><\/p>\n<h3>Don\u2019t \u201cjust Google it\u201d<\/h3>\n<p>We strongly recommend that everyone <strong>get out of the habit of \u201cjust Google it\u201d to find legitimate sites.<\/strong> Such habits often include clicking on the first link without giving it much thought, under the assumption that Google won\u2019t lead them astray, and will give them the correct result right at the top. Malware makers know this, of course, and that\u2019s why they\u2019re paying Google for the number-one position.<\/p>\n<p>Until or unless Google does a much better job of vetting its ads, a better practice than \u201cGoogle it\u201d would be to <strong>bookmark trusted sites whenever possible<\/strong>, and to go back to those bookmarks in the future.<a name=\"staysafe\"\/><\/p>\n<h3>How can I keep my Mac safe from Cuckoo and other malware?<\/h3>\n<p>If you use Intego VirusBarrier, you\u2019re already protected from this malware.<\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"alignright size-medium wp-image-54214\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/06\/X9-Mac-Antivirus-Launch-300x150.png\" alt=\"Intego X9 software boxes\" width=\"200\" height=\"100\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/06\/X9-Mac-Antivirus-Launch-300x150.png 300w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/06\/X9-Mac-Antivirus-Launch-150x75.png 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/06\/X9-Mac-Antivirus-Launch.png 600w\" sizes=\"auto, (max-width: 200px) 100vw, 200px\"\/>Intego VirusBarrier X9, included with <strong><a href=\"https:\/\/offer.intego.com\/BlogMACAV_lbmxlkchf\">Intego\u2019s Mac Premium Bundle X9<\/a><\/strong>, is a powerful solution designed to protect against, detect, and eliminate Mac malware.<\/p>\n<p>If you believe your Mac may be infected, or to prevent future infections, it\u2019s best to use antivirus software from a trusted Mac developer. VirusBarrier is award-winning antivirus software, designed by Mac security experts, that includes <a href=\"https:\/\/www.intego.com\/mac-security-blog\/why-your-antivirus-needs-real-time-scanning\/\">real-time protection<\/a>. It runs natively on both Intel- and Apple silicon-based Macs, and it\u2019s compatible with Apple\u2019s current Mac operating system, macOS Sonoma.<\/p>\n<p>One of VirusBarrier\u2019s unique features is that it can <a href=\"https:\/\/support.intego.com\/hc\/en-us\/articles\/207114798-VirusBarrier-X9-How-to-Scan-iPhone-iPad-and-iPod-Touch\">scan for malicious files on an iPhone, iPad, or iPod touch<\/a> in user-accessible areas of the device. To get started, just attach your iOS or iPadOS device to your Mac via a USB cable and open VirusBarrier.<\/p>\n<p>If you use a Windows PC, <a href=\"https:\/\/www.intego.com\/lp\/route-podcast-intego\/?channel=Podcast_Intego&amp;lpx=buy\"><strong>Intego Antivirus for Windows<\/strong><\/a> can keep your computer protected from malware.<a name=\"iocs\"\/><a name=\"other-names\"\/><a name=\"learnmore\"\/><\/p>\n<h3>How can I learn more?<\/h3>\n<p>This article will be updated soon with additional indicators of compromise (IOCs) for the Mac malware samples and malicious domains used in this Cuckoo campaign. Check back here and refresh the page later for further technical details.<\/p>\n<p>To learn more about the previous Cuckoo variant, see <a href=\"https:\/\/www.intego.com\/mac-security-blog\/intego-discovers-new-cuckoo-mac-malware-mimicking-homebrew\/\">Intego\u2019s original report on OSX\/Cuckoo malware<\/a>.<\/p>\n<blockquote class=\"wp-embedded-content\" data-secret=\"Yw7NLw5Kqz\">\n<p><a href=\"https:\/\/www.intego.com\/mac-security-blog\/intego-discovers-new-cuckoo-mac-malware-mimicking-homebrew\/\">Intego discovers new \u201cCuckoo\u201d Mac malware mimicking Homebrew<\/a><\/p>\n<\/blockquote>\n<p><iframe loading=\"lazy\" class=\"wp-embedded-content\" sandbox=\"allow-scripts\" security=\"restricted\" style=\"position: absolute; clip: rect(1px, 1px, 1px, 1px);\" title=\"\u201cIntego discovers new \u201cCuckoo\u201d Mac malware mimicking Homebrew\u201d \u2014 The Mac Security Blog\" src=\"https:\/\/www.intego.com\/mac-security-blog\/intego-discovers-new-cuckoo-mac-malware-mimicking-homebrew\/embed\/#?secret=Yw7NLw5Kqz\" data-secret=\"Yw7NLw5Kqz\" width=\"500\" height=\"282\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\"><\/iframe><\/p>\n<p>Be sure to also check out our <a href=\"https:\/\/www.intego.com\/mac-security-blog\/the-mac-and-iphone-malware-of-2024-and-what-to-expect-in-2025\/#forecast\">2025 Apple malware forecast<\/a> and our previous <a href=\"https:\/\/www.intego.com\/mac-security-blog\/category\/malware\/\">Mac malware articles<\/a> from 2025 and earlier.<\/p>\n<p><a href=\"https:\/\/podcast.intego.com\/\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" class=\"alignleft\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2021\/04\/intego-podcast-artwork-400.jpg\" alt=\"\" width=\"80\"\/><\/a>Each week on the <a href=\"https:\/\/podcast.intego.com\/\" target=\"_blank\" rel=\"noopener\"><strong>Intego Mac Podcast<\/strong><\/a>, Intego\u2019s Mac security experts discuss the latest Apple news, including security and privacy stories, and offer practical advice on getting the most out of your Apple devices. Be sure to <a href=\"https:\/\/podcasts.apple.com\/us\/podcast\/intego-mac-podcast\/id1293834627\" rel=\"noopener\"><strong>follow the podcast<\/strong><\/a> to make sure you don\u2019t miss any episodes.<\/p>\n<p>You can also subscribe to our <a href=\"https:\/\/www.intego.com\/mac-security-blog\/mac-security-newsletter\/\"><strong>e-mail newsletter<\/strong><\/a> and keep an eye here on <a href=\"https:\/\/www.intego.com\/mac-security-blog\"><strong>The Mac Security Blog<\/strong><\/a> for the latest Apple security and privacy news. And don\u2019t forget to follow Intego on your favorite social media channels: <a href=\"https:\/\/x.com\/IntegoSecurity\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" style=\"border-width: 1px; border-style: solid; border-color: rgba(255, 255, 255, 0.2); border-radius: 8px;\" title=\"Follow Intego on \ud835\udd4f\/Twitter\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/03\/X-Twitter-logo-icon-225.gif\" alt=\"Follow Intego on X\/Twitter\" width=\"16\"\/><\/a>\u00a0<a href=\"https:\/\/www.facebook.com\/Intego\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" style=\"border-width: 1px; border-style: solid; border-color: rgba(255, 255, 255, 0.2); border-radius: 8px;\" title=\"Follow Intego on Facebook\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/03\/Facebook-logo-icon-225.gif\" alt=\"Follow Intego on Facebook\" width=\"16\"\/><\/a>\u00a0<a href=\"https:\/\/www.youtube.com\/user\/IntegoVideo?sub_confirmation=1\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" style=\"border-width: 1px; border-style: solid; border-color: rgba(0, 0, 0, 0.2); border-radius: 8px;\" title=\"Follow Intego on YouTube\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/03\/YouTube-logo-icon-225.png\" alt=\"Follow Intego on YouTube\" width=\"16\"\/><\/a>\u00a0<a href=\"https:\/\/www.pinterest.com\/intego\/\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" style=\"border-width: 1px; border-style: solid; border-color: rgba(0, 0, 0, 0.2); border-radius: 8px;\" title=\"Follow Intego on Pinterest\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/03\/Pinterest-logo-icon-225.png\" alt=\"Follow Intego on Pinterest\" width=\"16\"\/><\/a>\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/intego\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" style=\"border-width: 1px; border-style: solid; border-color: rgba(255, 255, 255, 0.2); border-radius: 8px;\" title=\"Follow Intego on LinkedIn\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/03\/LinkedIn-logo-icon-225.gif\" alt=\"Follow Intego on LinkedIn\" width=\"16\"\/><\/a>\u00a0<a href=\"https:\/\/www.instagram.com\/intego_security\/\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" style=\"border-width: 1px; border-style: solid; border-color: rgba(255, 255, 255, 0.2); border-radius: 8px;\" title=\"Follow Intego on Instagram\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/03\/Instagram-logo-icon-225.gif\" alt=\"Follow Intego on Instagram\" width=\"16\"\/><\/a>\u00a0<a href=\"https:\/\/podcasts.apple.com\/us\/podcast\/intego-mac-podcast\/id1293834627\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" style=\"border-width: 1px; border-style: solid; border-color: rgba(255, 255, 255, 0.2); border-radius: 8px;\" title=\"Follow the Intego Mac Podcast on Apple Podcasts\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/10\/ios9-podcasts-app-tile.png\" alt=\"Follow the Intego Mac Podcast on Apple Podcasts\" width=\"16\"\/><\/a><\/p>\n<p>\t\t\t\t\t\t\t<img decoding=\"async\" alt=\"\" src=\"https:\/\/secure.gravatar.com\/avatar\/5ad29f4111ce14911abaa98cbbcdea42?s=60&amp;d=mm&amp;r=g\" srcset=\"https:\/\/secure.gravatar.com\/avatar\/5ad29f4111ce14911abaa98cbbcdea42?s=120&amp;d=mm&amp;r=g 2x\" class=\"avatar avatar-60 photo\" height=\"60\" width=\"60\" loading=\"lazy\"\/>\t\t\t\t<\/p>\n<h3>About Joshua Long<\/h3>\n<p>\t\t\t\t<b>Joshua Long<\/b> (<a href=\"https:\/\/twitter.com\/theJoshMeister\">@theJoshMeister<\/a>), Intego&#8217;s Chief Security Analyst, is a renowned security researcher and writer, and an award-winning public speaker. Josh has a master&#8217;s degree in IT concentrating in Internet Security and has taken doctorate-level coursework in Information Security. Apple has publicly acknowledged Josh for discovering an Apple\u00a0ID authentication vulnerability. Josh has conducted cybersecurity research for more than 25 years, which is often featured by major news outlets worldwide. Look for more of Josh&#8217;s articles at <a href=\"https:\/\/security.thejoshmeister.com\">security.thejoshmeister.com<\/a> and follow him on <a href=\"https:\/\/x.com\/theJoshMeister\">X\/Twitter<\/a>, <a href=\"https:\/\/www.linkedin.com\/in\/theJoshMeister\">LinkedIn<\/a>, and <a href=\"https:\/\/infosec.exchange\/@theJoshMeister\">Mastodon<\/a>.\t\t\t\t\t<a href=\"https:\/\/www.intego.com\/mac-security-blog\/author\/joshlong\/\"><br \/>\n\t\t\t\t\t\tView all posts by Joshua Long \u2192\t\t\t\t\t<\/a><\/p>\n<footer>\n\t\t\t\tThis entry was posted in <a href=\"https:\/\/www.intego.com\/mac-security-blog\/category\/malware\/\" rel=\"category tag\">Malware<\/a> and tagged <a href=\"https:\/\/www.intego.com\/mac-security-blog\/topic\/atomic-stealer\/\" rel=\"tag\">Atomic Stealer<\/a>, <a href=\"https:\/\/www.intego.com\/mac-security-blog\/topic\/homebrew\/\" rel=\"tag\">Homebrew<\/a>, <a href=\"https:\/\/www.intego.com\/mac-security-blog\/topic\/malvertising\/\" rel=\"tag\">Malvertising<\/a>, <a href=\"https:\/\/www.intego.com\/mac-security-blog\/topic\/mac-malware\/\" rel=\"tag\">Malware<\/a>, <a href=\"https:\/\/www.intego.com\/mac-security-blog\/topic\/stealer-malware\/\" rel=\"tag\">Stealer Malware<\/a>. Bookmark the <a href=\"https:\/\/www.intego.com\/mac-security-blog\/cuckoo-returns-mac-malware-spreads-via-legit-looking-google-ads\/\" title=\"Permalink to Cuckoo returns; Mac malware spreads via legit-looking Google Ads\" rel=\"bookmark\">permalink<\/a>.\t\t\t\t\t\t\t<\/footer>\n<\/p><\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><script async src=\"\/\/www.instagram.com\/embed.js\"><\/script><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Malware Posted on January 31st, 2025 by Joshua Long Over the past couple years, we\u2019ve written a lot about stealer malware that infects Macs. One malware family that frequently resurfaces is Atomic Stealer, or AMOS (short for Atomic macOS Stealer). AMOS is designed to exfiltrate sensitive data from infected Macs; this typically includes things like [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":64924,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11768],"tags":[14239,35136,35139,1531,13448,35140,11553,35137,22198,10970,14304,35138],"dealstore":[],"offerexpiration":[],"class_list":["post-64923","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-apple-2","tag-ads","tag-atomic-stealer","tag-cuckoo","tag-google","tag-homebrew","tag-legitlooking","tag-mac","tag-malvertising","tag-malware","tag-returns","tag-spreads","tag-stealer-malware"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Cuckoo returns; Mac malware spreads via legit-looking Google Ads - Som2ny Network<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/fivemor.com\/?p=64923\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Cuckoo returns; Mac malware spreads via legit-looking Google Ads - Som2ny Network\" \/>\n<meta property=\"og:description\" content=\"Malware Posted on January 31st, 2025 by Joshua Long Over the past couple years, we\u2019ve written a lot about stealer malware that infects Macs. One malware family that frequently resurfaces is Atomic Stealer, or AMOS (short for Atomic macOS Stealer). AMOS is designed to exfiltrate sensitive data from infected Macs; this typically includes things like [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/fivemor.com\/?p=64923\" \/>\n<meta property=\"og:site_name\" content=\"Som2ny Network\" \/>\n<meta property=\"article:published_time\" content=\"2025-02-02T21:06:38+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/02\/OSX-Cuckoo-Mac-macOS-malware-logo-v4-400x260-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"400\" \/>\n\t<meta property=\"og:image:height\" content=\"260\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/fivemor.com\/?p=64923#article\",\"isPartOf\":{\"@id\":\"https:\/\/fivemor.com\/?p=64923\"},\"author\":{\"name\":\"admin\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371\"},\"headline\":\"Cuckoo returns; Mac malware spreads via legit-looking Google Ads\",\"datePublished\":\"2025-02-02T21:06:38+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/fivemor.com\/?p=64923\"},\"wordCount\":1172,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/fivemor.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/fivemor.com\/?p=64923#primaryimage\"},\"thumbnailUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/02\/OSX-Cuckoo-Mac-macOS-malware-logo-v4-400x260-1.jpg\",\"keywords\":[\"ads\",\"Atomic Stealer\",\"Cuckoo\",\"Google\",\"Homebrew\",\"legitlooking\",\"Mac\",\"Malvertising\",\"Malware\",\"Returns\",\"Spreads\",\"Stealer Malware\"],\"articleSection\":[\"Apple\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/fivemor.com\/?p=64923#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/fivemor.com\/?p=64923\",\"url\":\"https:\/\/fivemor.com\/?p=64923\",\"name\":\"Cuckoo returns; Mac malware spreads via legit-looking Google Ads - Som2ny Network\",\"isPartOf\":{\"@id\":\"https:\/\/fivemor.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/fivemor.com\/?p=64923#primaryimage\"},\"image\":{\"@id\":\"https:\/\/fivemor.com\/?p=64923#primaryimage\"},\"thumbnailUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/02\/OSX-Cuckoo-Mac-macOS-malware-logo-v4-400x260-1.jpg\",\"datePublished\":\"2025-02-02T21:06:38+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/fivemor.com\/?p=64923#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/fivemor.com\/?p=64923\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/fivemor.com\/?p=64923#primaryimage\",\"url\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/02\/OSX-Cuckoo-Mac-macOS-malware-logo-v4-400x260-1.jpg\",\"contentUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/02\/OSX-Cuckoo-Mac-macOS-malware-logo-v4-400x260-1.jpg\",\"width\":400,\"height\":260},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/fivemor.com\/?p=64923#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/fivemor.com\/?bp_activities=1\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cuckoo returns; Mac malware spreads via legit-looking Google Ads\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/fivemor.com\/#website\",\"url\":\"https:\/\/fivemor.com\/\",\"name\":\"Som2ny Network\",\"description\":\"Daily Deals\",\"publisher\":{\"@id\":\"https:\/\/fivemor.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/fivemor.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/fivemor.com\/#organization\",\"name\":\"Som2ny Network\",\"url\":\"https:\/\/fivemor.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png\",\"contentUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png\",\"width\":300,\"height\":86,\"caption\":\"Som2ny Network\"},\"image\":{\"@id\":\"https:\/\/fivemor.com\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png\",\"caption\":\"admin\"},\"sameAs\":[\"https:\/\/fivemor.com\"],\"url\":\"https:\/\/fivemor.com\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Cuckoo returns; Mac malware spreads via legit-looking Google Ads - Som2ny Network","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/fivemor.com\/?p=64923","og_locale":"en_US","og_type":"article","og_title":"Cuckoo returns; Mac malware spreads via legit-looking Google Ads - Som2ny Network","og_description":"Malware Posted on January 31st, 2025 by Joshua Long Over the past couple years, we\u2019ve written a lot about stealer malware that infects Macs. One malware family that frequently resurfaces is Atomic Stealer, or AMOS (short for Atomic macOS Stealer). AMOS is designed to exfiltrate sensitive data from infected Macs; this typically includes things like [&hellip;]","og_url":"https:\/\/fivemor.com\/?p=64923","og_site_name":"Som2ny Network","article_published_time":"2025-02-02T21:06:38+00:00","og_image":[{"width":400,"height":260,"url":"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/02\/OSX-Cuckoo-Mac-macOS-malware-logo-v4-400x260-1.jpg","type":"image\/jpeg"}],"author":"admin","twitter_card":"summary_large_image","twitter_misc":{"Written by":"admin","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/fivemor.com\/?p=64923#article","isPartOf":{"@id":"https:\/\/fivemor.com\/?p=64923"},"author":{"name":"admin","@id":"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371"},"headline":"Cuckoo returns; Mac malware spreads via legit-looking Google Ads","datePublished":"2025-02-02T21:06:38+00:00","mainEntityOfPage":{"@id":"https:\/\/fivemor.com\/?p=64923"},"wordCount":1172,"commentCount":0,"publisher":{"@id":"https:\/\/fivemor.com\/#organization"},"image":{"@id":"https:\/\/fivemor.com\/?p=64923#primaryimage"},"thumbnailUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/02\/OSX-Cuckoo-Mac-macOS-malware-logo-v4-400x260-1.jpg","keywords":["ads","Atomic Stealer","Cuckoo","Google","Homebrew","legitlooking","Mac","Malvertising","Malware","Returns","Spreads","Stealer Malware"],"articleSection":["Apple"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/fivemor.com\/?p=64923#respond"]}]},{"@type":"WebPage","@id":"https:\/\/fivemor.com\/?p=64923","url":"https:\/\/fivemor.com\/?p=64923","name":"Cuckoo returns; Mac malware spreads via legit-looking Google Ads - Som2ny Network","isPartOf":{"@id":"https:\/\/fivemor.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/fivemor.com\/?p=64923#primaryimage"},"image":{"@id":"https:\/\/fivemor.com\/?p=64923#primaryimage"},"thumbnailUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/02\/OSX-Cuckoo-Mac-macOS-malware-logo-v4-400x260-1.jpg","datePublished":"2025-02-02T21:06:38+00:00","breadcrumb":{"@id":"https:\/\/fivemor.com\/?p=64923#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/fivemor.com\/?p=64923"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fivemor.com\/?p=64923#primaryimage","url":"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/02\/OSX-Cuckoo-Mac-macOS-malware-logo-v4-400x260-1.jpg","contentUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/02\/OSX-Cuckoo-Mac-macOS-malware-logo-v4-400x260-1.jpg","width":400,"height":260},{"@type":"BreadcrumbList","@id":"https:\/\/fivemor.com\/?p=64923#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/fivemor.com\/?bp_activities=1"},{"@type":"ListItem","position":2,"name":"Cuckoo returns; Mac malware spreads via legit-looking Google Ads"}]},{"@type":"WebSite","@id":"https:\/\/fivemor.com\/#website","url":"https:\/\/fivemor.com\/","name":"Som2ny Network","description":"Daily Deals","publisher":{"@id":"https:\/\/fivemor.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/fivemor.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/fivemor.com\/#organization","name":"Som2ny Network","url":"https:\/\/fivemor.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fivemor.com\/#\/schema\/logo\/image\/","url":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png","contentUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png","width":300,"height":86,"caption":"Som2ny Network"},"image":{"@id":"https:\/\/fivemor.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371","name":"admin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fivemor.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png","caption":"admin"},"sameAs":["https:\/\/fivemor.com"],"url":"https:\/\/fivemor.com\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts\/64923","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=64923"}],"version-history":[{"count":0,"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts\/64923\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/media\/64924"}],"wp:attachment":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=64923"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=64923"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=64923"},{"taxonomy":"dealstore","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fdealstore&post=64923"},{"taxonomy":"offerexpiration","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fofferexpiration&post=64923"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}