X-sponsored malvertising promotes fake Mac app, delivers MacSync malware

TL;DR
Jamf Threat Labs warns of a ClickFix-style attack where a verified X account promoted a malicious domain impersonating DynamicLake, a Mac utility. Visitors were redirected to dynamicmacisland[.]com and instructed to paste Terminal commands to install malware (MacSync/Atomic Stealer; DigitStealer variants seen). The ad bypassed checks due to trust in a familiar account; X removed it after Jamf reported. The DynamicLake developer condemns fake copies and urges downloads only from DynamicLake.com. This highlights ongoing malvertising risks on social platforms.
Topics:technologytechnology-and-security#macos#malvertising#malware#social-engineering#technology-and-security#x-twitter
- Malware found spreading through sponsored ad on X 9to5Mac
- Fake “Claude Code” Google Ad Delivers MacSync Stealer, Hijacks Ledger Wallets on macOS cyberpress.org
- A Weaponized Google Ad Install Malicious Claude Code to Hijack Entire macOS CyberSecurityNews
- MacSync Stealer Hijacks macOS via Fake Claude Code Google Ads – Full Attack Chain Exposed gbhackers.com
Want the full story? Read the original reporting
Read on 9to5Mac