Misused Google domain Over the past several months, numerous phishing emails have been observed linking directly to files hosted on storage.googleapis.com. Legitimate companies do not typically host public-facing data in this manner. Users are advised not to click links directing to storage.googleapis.com. The domain has been blocked.
InfoStealer distributed through Twitter ads Threat actors are conducting an information-stealing malware campaign that leverages Twitter ads to target both Mac and Windows users.
Several landing pages have been identified promoting fraudulent utility products aimed at developers and general end users.
Clicking the download option provides instructions to pipe obfuscated commands into Bash or PowerShell. These commands facilitate the download of a secondary payload. On macOS, the payload consists of obfuscated JavaScript piped directly into osascript.
In one observed sample, the campaign demonstrated a particular focus on users in Central Asia, including Turkmenistan and Uzbekistan, determined by reading the system input layout.
Advertised applications include "Nancy Clipboard," "PulseNotch," "Scoppr", and "CleanDev." The campaign has been active for some time, and as of today, the associated domains remain operational behind Cloudflare, with Twitter continuing to run the advertisements.
Software should only be installed directly from reputable sources or your platform's official app store. Piping obfuscated commands into macOS Terminal or Windows PowerShell is not a standard installation method. Users should exercise caution when encountering any website requesting such actions. The latest iAntiSpy blocking databases provide protection against all known variants. The methodology observed is similar to a campaign previously identified targeting our company, detailed
here.
Customers with an enhanced protection subscription are already protected. For all other users, the iAntiSpy v26.09 update will be released later this week.